Understanding Access Review Violation Types in Identity Governance
search cancel

Understanding Access Review Violation Types in Identity Governance

book

Article ID: 101628

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Governance CA Identity Portal

Issue/Introduction

During an Access Review campaign, clicking the violation icon displayed next to a user's access entry may reveal various violation types, such as User ViolationRole Violation, or Link Violation. This article clarifies what these categories represent and how the system determines them.

Environment

  • Product: CA Identity Governance
  • 14.x, 15.x

Cause

Violation types in Identity Governance are driven by the configuration of Business Policy Rules (BPRs) and Audit Cards. When configuring a campaign, you can choose to hide violations or display them based on these policies.

The specific category of violation (User, Role, or Link) is determined by the scope of the policy or audit card triggered:

  • Role Violation: Triggered by policies governing role assignments, such as Segregation of Duties (SoD) rules (e.g., "User A cannot possess both Role X and Role Y").
  • User Violation: Triggered by policies related to user attributes, ensuring that a user's profile data meets specific compliance requirements.
  • Link Violation: Triggered by policies regarding specific connections, such as unauthorized user-to-resource or user-to-role assignments.

Resolution

The violation type is explicitly defined by the administrator during the creation of the Business Policy or Audit Card.

  1. When you create or modify a policy in the system, you assign the criteria that determine a violation.
  2. When the campaign engine processes the access data, it compares the current access state against these BPRs and Audit Cards.
  3. The violation icon labels the identified conflict based on the specific policy definition that was breached.

To manage these definitions, ensure that your BPRs and Audit Cards are accurately classified during the creation process to ensure that the campaign reporting reflects the correct violation category.


 

Additional Information

For detailed instructions on configuring these policies, refer to the  documentation.

15.x documentation:

Creating a business policy