Unable to remove privileges for an RSA Via Governance and Lifecycle user
Originally Published: 2016-06-16
Article Number
Applies To
RSA Version/Condition: 7.0
Issue
After clicking the Remove action for a privilege, the button changes to Removed, but changes back to Remove when the Apply Changes button is pressed.
This behavior occurs when the following steps are taken:
- Select the Users selection on the Users tab.
- Select the Privileges tab.
- Under the Action column choose a privilege to remove by clicking on the Remove button next to the privilege name.
- The button changes to Removed.
- Click on the Apply Changes button to apply the changes.
Instead of the privilege being removed the button changes back to Remove, as in the screen shot below:
Cause
Resolution
There are two ways to determine if entitlements are eligible to be removed from the user Privileges tab.
Option 1
- Select the privilege under the Name column and press the information dialog represented by the yellow i icon. This will display how the user entitlement is defined. If the entitlement shows that it is Used By App Roles, then this entitlement is an indirect entitlement and must be removed by removing the parent App Role.
- Select the privilege under the Name column and press the information dialog represented by the yellow i icon. If the entitlement details screen shows None for the value of App.Roles, then this is the parent application role and may be removed (or added) as a user privilege. The indirect entitlements that are children of this App Role are listed under the Entitlements section.
Option 2
The second way to determine if entitlements are eligible to be removed from the user Privileges tab is to view the entitlements from the User Access list.- Select Users from the Users tab and then click the Access tab.
- Group the applications by Business Source Name and then select the Aveksa application.
- In the RSA Via Lifecycle and Governance 7.0 role model the user privileges for the Aveksa application are controlled by roles assigned under the Aveksa application.
- Under the Entitlement Type column entitlements that may be removed (or added) to a user are of type app-role and entitlements that are indirect entitlements owned by a parent application role that cannot be removed will be identified by the type ent.
Workaround
- Select the Admin menu and the System.
- Then under the Settings tab select Access Request Manager.
- Set the value to On.
Related Articles
How to remove entitlements of a decommissioned application from user access in RSA Via Lifecycle and Governance 73Number of Views Unable to remove account from group through a review in RSA Identity Governance & Lifecycle 61Number of Views Unable to remove a Role Membership Rule from a Role in RSA Identity Governance & Lifecycle 28Number of Views Unable to remove deleted groups from role in RSA Governance & Lifecycle 20Number of Views How to cancel/remove pending emails waiting in the queue in RSA Identity Governance & Lifecycle 212Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide How to install the jTDS JDBC driver on WildFly for use with Data Collections in RSA Identity Governance & Lifecycle RSA Authentication Manager 8.8 Setup and Configuration Guide Artifacts to gather in RSA Identity Governance & Lifecycle
Don't see what you're looking for?