A managed domain added in ARS is not giving any permissions to accounts which are supposed to get it via access templates. Other managed domains are fine, but not for this one. ARS Admins are also impacted:
Active Roles built-in policy "Built-in Policy - Exclude from Managed Scope" is applied. Creating an object via the ARS Shell will show below error:
Remove/block "Built-in Policy - Exclude from Managed Scope" from the affected managed domain:
© 2025 One Identity LLC. ALL RIGHTS RESERVED. 使用条款 隐私 Cookie Preference Center