After removing a user from AD and performing an LDAP group refresh in CA PAM, the user is not deleted.
To remediate this issue, Broadcom-provided PAM_USR_SYNC was applied, but patch application results in the following error in Session Log, and the user is still not deleted:
"Unable to delete user <user CN> because it has custom report <CUSTOM-REPORT-NAME> assigned. Please delete the report and run the patch again."
PAM Session Log indicates that the user for which deletion is being attempted is associated with customized report(s) and therefore cannot be deleted from PAM.
1. Delete the custom reports associated with this user which are mentioned in the PAM Session Log by going to (Session==>Logs==>Reports===>Manage Reports)
2. Please apply PAM_USR_SYNC patch again and as a result user should be successfully removed showing the success message in the Session Log:
User <brokenuser@brokenuserdomain> was present in the access manager but not the credential manager. deleting.
To request the latest version of