There is a requirement for users not to be removed from specific Dynamic Groups when the user is deprovisioned.
This is by design, the Active Roles policies do not accept Dynamic Groups to be included, as a workaround the Dynamic Group will need to be converted to Basic Group, then add it to the exclusion rule and then convert it back to a Dynamic Group.
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Conditions d’utilisation Confidentialité Cookie Preference Center