There is a Business Role with Dynamic Role and an Account Definition assigned. The Account Definition has the flag “Retain account definition if permanently disabled” unchecked.
If a permanently disabled Employee matches the dynamic role criteria and is assigned to this Business Role a new Account (ADSAccount or UNSBAccount, depending on the type of account definition) is created although the account definition is not effectively assigned, because the “Retain account definition if permanently disabled” flag is not set.
If the Employee is removed from the Business Role, the account definition is removed from the user, but the newly create account still exists (marked as disabled).
This is a product defect (26941).
WORKAROUND
Exclude permanently disabled Employees from any dynamic roles.
STATUS
This will be fixed on a future release of the product. If you require this immediately corrected, please contact Support for a hotfix referencing the defect ID 26941.
© 2024 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center