When the built-in CN=ActiveRoles certificate for the Entra connection expires and the Azure connection is reconfigured through the Active Roles Configuration Center, Active Roles recreates its internal Entra tenant object and assigns it a new ARS GUID, even if the same App Registration and AppID are preserved. As a result, any Access Templates linked directly to the Tenant become invalid and are removed, while links to Managed Units remain intact. Tenant-level Access Template links must be manually rebuilt afterwards.
The following defect ID 651661 has been created to address this issue, and it will be fixed in a feature release version. Please refer to this article for updates or contact support referencing the Product defect ID: 651661.
The following defect ID 651661 has been created to address this issue, and it will be fixed in a feature release version. Please refer to this article for updates or contact support referencing the Product defect ID: 651661.
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center