PX Policy is not displaying all Provisioning Roles
search cancel

PX Policy is not displaying all Provisioning Roles

book

Article ID: 99911

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Governance CA Identity Portal

Issue/Introduction

This article addresses configuration behavior where specific Provisioning Roles are unavailable for selection within a Provisioning Manager (PX) Policy Action Rule. This typically occurs due to role scoping and administrative permission requirements within the Identity Manager environment.

Environment

  • Product: CA Identity Manager
  • Component: IDMGR
  • Release: 14.x

Cause

The issue is a result of a scoping limitation regarding the Provisioning Role configuration. In CA Identity Manager, owners of Provisioning Roles manage the role object itself, but administrators are required to control the membership of that role. When a Provisioning Role lacks an assigned administrator, the system restricts the ability to modify membership, preventing the role from appearing as a selectable option within a PX Policy Action.

Resolution

To resolve this issue and make the Provisioning Roles available for selection, ensure that the appropriate users are assigned as administrators to those roles:

  1. Identify the specific Provisioning Roles that are missing from the PX Policy list.
  2. Navigate to the Provisioning Role definitions within the Identity Manager console.
  3. Assign users who are members of the System Manager group as administrators to these Provisioning Roles.
  4. Once administrators are assigned, verify that the roles now appear in the PX Policy selection list under the following configuration:
    • Category: Roles
    • Type: Set Provisioning Role
    • Function: Add

Additional Information

  • To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.