Entitlements Are Not Being Removed When a Business Role Is Auto Unassigned via an Assignment Rule

Hi All,

Issue: Birth Right Role is not working as expected via Assignment Rule.

When the condition for a birthright role matches via an assignment rule, the entitlement is correctly added to the user.

However, the entitlement is not being removed when the condition no longer matches the user.

This issue is occurring inconsistently for some users, for few users the entitlement is removed as expected, for other users, it is not removing entitlements even after the condition is no longer met.

Same functionally working fine in QA Environment.

We are using AD Groups to provision.

I have checked below points.

  1. Refresh task check “Refresh assigned, detected roles and promote additional entitlements and Provision assignments”.

  2. Unchecked "Refresh assigned and detected roles " in account aggregation task.

  3. Entitlement is not added manually

Hi @puppamReddy,

Can you provide us with more information about whether the AD provisioning of these memberships has been performed, if it has failed, or if it simply hasn’t been executed?

1 Like

Hi @puppamReddy,

Can you check the configuration in the Global Setting and see what the setting for below snapshot is.

image

Thanks

it’s not been executed.

I do not see any provisioning transaction for role removal.

Within the Administrator Console, there should be a provisioning process for the application and the account for which you attempted to revoke membership. It should have the following characteristics:

1 Like

Yes, I have checked, but I did not find any provisioning transactions related to the removal of this role.

Did you check the xmls for the identity which is not working compared to which is working ? most the role assignment / entitlement assignment .

Just now I checked below observations

Working user have

  1. Business role and It role
  2. Under roleAssignments tag business role souce=Rule
  3. RoleDetection tag I do see assignmentIds

Not working User
1.Only IT Role Under RoleDetection tag
2. RoleDetection tag I do not see assignmentIds

@puppamReddy

Besides all the above replies, can you also confirm that the group, whatever it is in the IT role, should not be requested manually by manager user access before, right?

If that is the case, I don’t think it will be removed because the manual request will come first priority and won’t remove the group from the user when the role is unassigned. The group will be removed only if you do remove requests from manage user access only.

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.