3.1 Unable to Assign the Role with SoD Constraint to a User

Issue: In a normal scenario, when you request a role for users that conflicts with the user’s current role, the SoD policy applied to the conflicting role invokes an SoD approval flow. The SoD approvers, which may be selected approvers or default approvers set in the separation of duties settings, receive a corresponding task in their Tasks list. Once the task is approved, the requested role is assigned to the user. However, when you add a new user to the default approvers’ list in the separation of duties settings, the SoD policy fails to add a task in the newly-added user's task list. This results in an error message and the subsequent failure of the role assignment. (Defect 267078)

Workaround: To resolve this issue, restart the tomcat service in the identity applications server whenever you add a new user to the default approvers list in the separation of duties settings.