In an Active Roles 8.2.1 environment configured with multiple Managed Domains (for example, Domain A, Domain B, and Domain C), attempting to delegate permissions to DomainB\Account Operators for objects in Domain B may result in the wrong trustee being applied.
When the permissions wizard is used to select DomainB\Account Operators, the wizard displays the correct group as selected. However, after the permissions are applied, the trustee recorded/applied is Account Operators from a different managed domain (for example, DomainA\Account Operators). The behavior consistently selects Account Operators from whichever managed domain is listed first in the Managed Domains configuration.
Removing the first managed domain from the Managed Domains list does not resolve the issue; instead, the trustee selection shifts to the next domain listed first, and the incorrect Account Operators group is applied again.
The following defect ID chas been created to address this issue, and it will be fixed in a feature release version. Please refer to this article for updates or contact support referencing the Product defect ID: 91777.
The following defect ID 91777 has been created to address this issue, and it will be fixed in a feature release version. Please refer to this article for updates or contact support referencing the Product defect ID: 91777.
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center