Azure Administrative Units (AUs) are not revoked when access is removed in Identity Manager (IM)
search cancel

Azure Administrative Units (AUs) are not revoked when access is removed in Identity Manager (IM)

book

Article ID: 435426

calendar_today

Updated On:

Products

CA Identity Suite

Issue/Introduction

When a Provisioning Role mapped to an Azure Administrative Unit (AU) is removed from a user in Identity Manager, the AU membership is not revoked in Azure. The Azure Rest Connector fails to issue the necessary DELETE call to the Microsoft Graph for AU membership removal. This results in access governance inconsistency, compliance risk, and the need for manual cleanup in Azure.

Environment

Product: Identity Manager
Affected Version: 14.5.1 + CHF1
Component: Azure Rest Connector

Cause

This issue is caused by a product defect where the Azure connector did not correctly handle the DELETE operation for Administrative Units.

Resolution

Open a Suppot case an refer to Hotfix: HF_DE664431.zip, providing your versions and details.