Unable to remove privileges for an RSA Via Governance and Lifecycle user
Originally Published: 2016-06-16
Article Number
Applies To
RSA Version/Condition: 7.0
Issue
After clicking the Remove action for a privilege, the button changes to Removed, but changes back to Remove when the Apply Changes button is pressed.
This behavior occurs when the following steps are taken:
- Select the Users selection on the Users tab.
- Select the Privileges tab.
- Under the Action column choose a privilege to remove by clicking on the Remove button next to the privilege name.
- The button changes to Removed.
- Click on the Apply Changes button to apply the changes.
Instead of the privilege being removed the button changes back to Remove, as in the screen shot below:
Cause
Resolution
There are two ways to determine if entitlements are eligible to be removed from the user Privileges tab.
Option 1
- Select the privilege under the Name column and press the information dialog represented by the yellow i icon. This will display how the user entitlement is defined. If the entitlement shows that it is Used By App Roles, then this entitlement is an indirect entitlement and must be removed by removing the parent App Role.
- Select the privilege under the Name column and press the information dialog represented by the yellow i icon. If the entitlement details screen shows None for the value of App.Roles, then this is the parent application role and may be removed (or added) as a user privilege. The indirect entitlements that are children of this App Role are listed under the Entitlements section.
Option 2
The second way to determine if entitlements are eligible to be removed from the user Privileges tab is to view the entitlements from the User Access list.- Select Users from the Users tab and then click the Access tab.
- Group the applications by Business Source Name and then select the Aveksa application.
- In the RSA Via Lifecycle and Governance 7.0 role model the user privileges for the Aveksa application are controlled by roles assigned under the Aveksa application.
- Under the Entitlement Type column entitlements that may be removed (or added) to a user are of type app-role and entitlements that are indirect entitlements owned by a parent application role that cannot be removed will be identified by the type ent.
Workaround
- Select the Admin menu and the System.
- Then under the Settings tab select Access Request Manager.
- Set the value to On.
Related Articles
How to remove all user data stored in the RSA Identity Governance and Lifecycle application database 747Number of Views A completed change request to remove Aveksa Application/Directory entitlements from a user does not remove the access from… 199Number of Views How to cancel/remove pending emails waiting in the queue in RSA Identity Governance & Lifecycle 214Number of Views How to search for users with RSA Mobile administration GUI 1Number of Views Unable to restart the RSA Authentication Manager services 150Number of Views
Trending Articles
RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA SecurID Software Token 5.0.3 for Microsoft Windows Release Notes RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide View Transfer Tokens to Cloud Jobs
Don't see what you're looking for?