This article explains the expected behavior when removing child roles from parent roles within Identity Manager and provides the steps to resolve orphaned account links that may remain after the removal process.
Identity Manager 14.x & 15
The behavior where accounts remain linked after a child role removal is Working as Designed. CA Identity Manager does not automatically trigger the removal of associated account templates when a role is revoked. This design ensures that accounts are not unintentionally de-provisioned or orphaned, allowing administrators to manually verify the state of the account before removal.
To clean up account links after a child role removal, use the following synchronization procedure:
For detailed information on role and account synchronization policies, refer to the Account Synchronization - 14.5 or Account Synchronization - v15