RSA Identity Governance and Lifecyle users who do not belong to role can not be identified
Originally Published: 2016-12-29
Last Modified: 2023-10-06
Article Number
Applies To
RSA Product/Service Type: Access Certification Manager
RSA Version/Condition: 6.9.1 P18
Issue
In 6.9.1 P18, we display a message that x users do not belong to the role, but they are not listed with a Revoke button, although they are directly entitled, and also entitled indirectly through a role or group.
This is different behavior from versions prior to P18, where those users are listed in the Directly Entitled tab with a Remove action button.
In P18, you would see this behavior:
Resolution
- If user is added to a role directly, then the users will be displayed as members in the Directly Entitled category.
- If user is associated to a group or a role and that group/role is added as entitlements to the role, then the user will not be displayed as member in the Directly Entitled category. The user is considered as indirect and will be displayed in All category without any action (that is, without the Remove button) only.
- If user is added to a role directly and also added via group to the role, then the user will not be displayed as member in the Directly Entitled category. The user is considered as indirect and will be displayed in All category without any action (that is, without the Remove button) only.
- The action button will not be available for direct members in the All category if they match in the above use case conditions.
Related Articles
Error message "Can not convert logon name: lab\\tstuser1 to UPN error: 0" during IWA authentication in RSA Access Manager 39Number of Views Users can not open The SDTID file in some mail applications 122Number of Views Where in enVision can we see which row was the last to be retrieved by the DB? 8Number of Views Root Cause Identified for the SecurID 3.0 App Token Import Issue 2Number of Views How to identify the original StealthAudit Console Machine in RSA Identity Governance & Lifecycle 24Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Unable to login to RSA Authentication Manager Security Console as super admin Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x
Don't see what you're looking for?