Groups Not Displaying in Manage My Access — Identity Portal
search cancel

Groups Not Displaying in Manage My Access — Identity Portal

book

Article ID: 130183

calendar_today

Updated On:

Products

CA Identity Portal CA Identity Suite

Issue/Introduction

This article addresses an issue where the middle area of the Manage My Access section remains empty and does not display groups for user selection. This typically occurs when entitlements are not correctly mapped to the endpoint attributes or when orphaned provisioning roles exist in the portal.

Environment

Identity Portal 14.5

Cause

  • The GroupMembership attribute is not correctly mapped in the Identity Portal Admin UI.
  • Entitlements for the specific endpoint (e.g., Active Directory) have not been added or associated with the correct tasks.
  • Orphaned Provisioning Roles exist in the Identity Portal that no longer exist in the Provisioning Server.
  • Stale cache entries in the Backend Entitlement or User Profiles.

Resolution

  1. Log in to the Identity Portal Admin UI.
  2. Navigate to Elements > Endpoints > Entitlements and select your endpoint (e.g., AD).
  3. Select the Account Scope tab and verify that the view option is selected.
  4. Navigate to the Entitlements tab and click Add entitlements.
  5. Create a "Modify Group" entitlement:
    • Set Entitlement type to ActiveDirectorygroup membership.
    • Set Add task to ModifyActiveDirectoryAccount.
    • Set Remove Task to ModifyActiveDirectoryAccount.
  6. Click Rules and add any necessary conditional logic.
  7. Navigate to Account Attributes in the Admin UI.
  8. Click Add attributes, provide a name, and map it to GroupMembership.
  9. If groups still do not display, clear the cache:
    • Navigate to Tools > Cleanup the cache.
    • Specifically clear Backend Entitlement and User Profiles entries.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.