Resolution for Accounts Remaining Linked After Child Role Removal in CA Identity Manager
search cancel

Resolution for Accounts Remaining Linked After Child Role Removal in CA Identity Manager

book

Article ID: 221906

calendar_today

Updated On:

Products

CA Identity Suite CA Identity Manager

Issue/Introduction

This article explains the expected behavior when removing child roles from parent roles within Identity Manager and provides the steps to resolve orphaned account links that may remain after the removal process.


                            

Environment

Identity Manager 14.x & 15

Cause

The behavior where accounts remain linked after a child role removal is Working as Designed. CA Identity Manager does not automatically trigger the removal of associated account templates when a role is revoked. This design ensures that accounts are not unintentionally de-provisioned or orphaned, allowing administrators to manually verify the state of the account before removal.

Resolution

To clean up account links after a child role removal, use the following synchronization procedure:

  1. Log in to the Identity Manager User Console.
  2. Navigate to the Role Management task menu.
  3. Select the Check Role Synchronization task and locate the user. You will observe that the user retains an "extra assignment" from the account template associated with the removed child role.
  4. Navigate to the Synchronize User with Roles task.
  5. Select the user and choose the option to Add Missing and Remove Extra account assignments.
  6. Submit the task to perform the synchronization. This will remove the orphaned account link associated with the removed child role.

Additional Information

For detailed information on role and account synchronization policies, refer to the Account Synchronization - 14.5 or Account Synchronization - v15