Impact area
Security
Severity
High
Affected element
User Groups
Rule ID #
SN-0437
Impact #
This rule checks for child groups which do not have all the roles of their parent groups. Roles may have been removed from a child group through different voluntary or involuntary actions, but the expectation is that child groups should have all the roles of their parents. Missing roles in groups can lead to lack of functionality and unexpected errors for users in the affected group.
Remediation
Removing the parent from this group, saving, and then adding the parent back should resolve this issue.
Time to fix
20 min