Child roles removed but still linked to accounts

book

Article ID: 221906

calendar_today

Updated On:

Products

CA Identity Suite CA Identity Manager

Issue/Introduction

When removing a child role from a parent role, the accounts linked to the template of the child role are not removed

 

Cause

This is working as designed. 

Resolution

To work around this, go to Identity Manager  UI:

1)  Use the "Check Role Synchronization" task, you can see that the user has an extra assignment from Acct Template

2) Use the "Synchronize User with Roles" task and select add missing and remove extra account option.