cancel
Showing results for 
Search instead for 
Did you mean: 

Unable to remove privilege from IDM UI and dynamic groups

Sankar_Aravind
Participant
0 Kudos

Hi Team,

1) We are currently performing some cleanup activity. When we checked some Withdrawn users, some of the privileges were still assigned to the users and when i clicked the privilege status, we observed the status as "Inherited, master privilege" and some are "inherited" , but no ROLE is assigned currently (only privs assigned). and the privileges are not getting removed when we tried even through job. In IDM UI, the delete button is disabled when I try to delete.

The EXECSTATE, LINKSTATE, ORPHAN (=0) all are showing either 0 or 1.

We tried deleting with direct Reference through job, but still the roles are not deleting and there are no Dynamic groups also assigned.

2) We are unable to remove dynamic groups. If i delete and refresh, the group is adding immediately.

but no roles/privileges are adding because of this dynamic group addition (even after the dynamic group job runs). Just the dynamic group adding back each time.

Please advise.

Accepted Solutions (0)

Answers (1)

Answers (1)

simona_lincheva4
Participant
0 Kudos

Hi Aravind,

This you check for mcOrphan assignments, those are usually coming from business roles, so there were indirect assignments to users and for some reason not correctly removed with the reconcile process.

BR,

Simona