RSA Identity Governance and Lifecycle users do not match the membership rule once removed from the role
Originally Published: 2017-03-13
Article Number
Applies To
RSA Version/Condition: 6.8.1+
Issue
For example:
- Create a role with some membership rule. In this example we are using "users."Is Terminated"=0 or users.Department='Finance'" as the membership rule.
- Add users to the role matching the membership rule and apply the changes.
- Remove a user from the role and commit the changes.
- Try to add the same user back to the role by filtering with matching items and that user is not seen in the list. If we try to search manually with a filter set to All Members, we will be able to see that the user does not match the membership rule. The membership rule condition shows as false rather than true.
Resolution
- V6.8.1 P25,
- V6.9.1 P18,
- V7.0.0 P05,
- V7.0.1 P01,
- V7.0.2
Related Articles
Existing Role memberships later granted through Parent Roles are not revoked when the Role memberships are removed from th… 38Number of Views Terminated Users not correctly removed from Roles in RSA Identity Governance & Lifecycle 115Number of Views Administrative Task "Logging" showing in Administrative Role summary and cannot be removed from RSA Authentication Manager… 25Number of Views RSA PAM Authentication Agent cannot challenge users in Active Directory groups 275Number of Views Account entitlements not removed from user when account is un-mapped from the user in RSA Identity Governance & Lifecycle … 13Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows RSA Authentication Manager 8.9 Patches and Hotfixes Readme Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?