Project

General

Profile

Actions

Defect #3397

closed

Groups assigned to accounts aren't removed from end systems after removal of the role

Added by Alena Peterová 11 months ago. Updated 7 months ago.

Status:
Closed
Priority:
High
Assignee:
Peter Štrunc
Category:
Account managment
Target version:
Start date:
06/19/2023
Due date:
% Done:

100%

Estimated time:
Affected versions:
Owner:

Description

My use-case - I have an AD group which has the flag "automatically create accounts". When I assign the role directly to the account, account gets the groups. However, when I remove the role, account isn't removed from the group.

Steps to reproduce - detail:
  • have a user who has an account on end system (here AD, the role creating this account is AD-test1)
  • create a role which assigns the system, has the flag "Automatically create accounts" and fills some value to the multi-valued attribute. Here "AD new test role" filling the value "test new role".
  • assign this role to the main personal account
  • it creates an empty link to account (i.e. a link without "assigned by role") - this is probably the cause of the problem later
  • the value is provisioned correctly
  • remove the role
  • the value from the role is not removed from the values on the system. Also, the link to the account stays there.

Files

00_role_automatically_create_account.png (90.3 KB) 00_role_automatically_create_account.png Alena Peterová, 06/19/2023 05:57 PM
04_provisioning.png (14.2 KB) 04_provisioning.png Alena Peterová, 06/19/2023 05:57 PM
03_links_to_accounts.png (45.5 KB) 03_links_to_accounts.png Alena Peterová, 06/19/2023 05:57 PM
02_assign_role_to_account.png (74.1 KB) 02_assign_role_to_account.png Alena Peterová, 06/19/2023 05:57 PM
01_start_roles.png (30.7 KB) 01_start_roles.png Alena Peterová, 06/19/2023 05:57 PM
05_roles_are_still_there.png (4.17 KB) 05_roles_are_still_there.png Alena Peterová, 06/19/2023 06:05 PM
Actions

Also available in: Atom PDF