Application Roles not removed on Provisioning Role removal - SCIM Connector
search cancel

Application Roles not removed on Provisioning Role removal - SCIM Connector

book

Article ID: 113532

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Suite

Issue/Introduction

This article addresses an issue where Application Roles, specifically those mapped to the eTDYN-str-multi-c-01 attribute, persist on an associated account even after a Provisioning Role has been removed from a global user in a SCIM Connector environment.

Environment

Identity Manager 14.x & 15

Cause

This behavior occurs by design when the last Provisioning Role linked to a template for a specific endpoint is removed. In this scenario, the system treats the action as an account deletion process rather than a synchronization update, which bypasses the synchronization algorithm that would typically handle the removal of individual capability account values.

Resolution

This is confirmed as expected behavior within the provisioning framework. The synchronization algorithm only applies when at least one Provisioning Role linked to a template for the same endpoint remains.

If multiple roles exist, removing one will trigger sync; however, removing the final role defaults to account deletion logic where specific attribute synchronization is not performed.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.