When attempting to prevent certain users from deprovisioning objects by applying an access template that denies the Deprovision permission on objects, an access template is scoped to a security group and assigned to the target groups, the restriction is not enforced.
Members of the scoped security group are still able to deprovision the protected groups, including newly created test groups, regardless of how the access template is scoped.
The following defect ID 651117 has been created to address this issue, and it will be fixed in a feature release version. Please refer to this article for updates or contact support referencing the Product defect ID: 651117.
The following defect ID 651117 has been created to address this issue, and it will be fixed in a feature release version. Please refer to this article for updates or contact support referencing the Product defect ID: 651117.
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center