Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

Pop-Up error in AD Group Management

ShyamSrisailam
Regular Contributor
Regular Contributor

Hi All,

We have tested on AD Group creation and it's working fine with ROLE_ADMIN access but when I test only with ROLE_ENDUSER access it's giving a pop-up error at Child Group and Parent Group page - 

ARS > Create AD Group > Fill all the AD Group required details > Assign Group Owner > Child Group (Here, we are getting {"error": "access denied"}, we don't need to add any Child Group while create AD Group.) > The same error we are getting in Parent Group page also.

Below are the Screenshots of the Pop-Up ERROR in both Child Group and Parent Group.

Child Group:

ShyamSrisailam_0-1688732298469.png

Parent Group:

ShyamSrisailam_1-1688732686541.png

NOTE: Let us know is there any option to Hide/Disable Child and Parent Group pages while requesting AD Group.

 

Regards
SrisailamShyamSundarGoud
16 REPLIES 16

rushikeshvartak
All-Star
All-Star

Please add  request map

/entitlement_values/**

 


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

Hi @rushikeshvartak 

Thank You, after adding ADMIN - SUBMENU.ADMIN.entitlement_values_list in ENDUSER_SAVROLE the access denied pop-up ERROR is not occurring. 

 

Regards
SrisailamShyamSundarGoud

Hi @rushikeshvartak ,

After adding ADMIN - SUBMENU.ADMIN.entitlement_values_list in ENDUSER_SAVROLE the access denied pop-up ERROR is not occurring.  

However with the access SUBMENU.ADMIN.users_list, we see that ADMIN tab is visible for users having "ROLE_SAV_ENDUSER ". and we are able to select/add owner in AD group management. Please find the below screen shot with SAVE option

Swetha_1-1689332240386.png

Incase if we remove this SUBMENU.ADMIN.users_list from access then we don't see ADMIN tab but we face issue while adding the owner to the group we get the access denied popup error.

Swetha_0-1689330313892.png

Also let us know if the AD Group Management will work in V5.5 3.18 with ENDUSER SAV ROLE access.

Regards,

Swetha

 

Whats the url in browser 


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

Add related requestmal


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

We tried adding below access , still same error we are getting .

SUBMENU.ARS.create_userrequest
 Request Map

please let us know if any specific access to be added.

Regards,

swetha

Darshanjain
Saviynt Employee
Saviynt Employee

Hi @ShyamSrisailam 

 

Please use the below savrole export , you should be able to create new AD group with admin tab and add all users are shown in the owners tab.

 

Thanks

Darshan

Hi @Darshanjain,

There is nothing inside the zip file you posted.

FYI, we need to create new AD group without showing admin tab and add all users are shown in the owners tab.

Thanks,

Shyam

Regards
SrisailamShyamSundarGoud

Please use the below zip file, You should be able to see the files now.

 

Thanks

Darshan

ShyamSrisailam
Regular Contributor
Regular Contributor

Thank You @Darshanjain ,

The above provided SAV file is working fine but additionally just need to another access i.e., 

ADMIN -    SUBMENU.ADMIN.users_userlistjson

Regards
SrisailamShyamSundarGoud

Hello,

Am trying similar use case and get access denied error when trying to remove group owner and while trying to entitlement(child), parent entitlement addition works fine.

After adding all recommended access list to the sav role, I still see empty user list table.. any idea on this please?

Hi,

Which SAVROLE you are using? and can you send me the access list.

Version ?

 

Regards
SrisailamShyamSundarGoud

Hi,

Thanks for your response, sav role created in 5.5 version.

Attached access list export for your reference (added few additional access list to check whether it helps, still no luck).

Regards,

Brijit.

Hi @Brijit 

Add the below access in SAVROLE and try to check it

ADMIN - SUBMENU.ADMIN.roleslist

ARS - SUBMENU.ARS.create_role

ADMIN - SUBMENU.ADMIN.users_userlistjson

 

Regards
SrisailamShyamSundarGoud

Hi @ShyamSrisailam 

None of them are found in 5.5 version, have added other 3 already instead but still get "Access denied" or "Not authorized" error.

ADMIN - SUBMENU.ADMIN.roleslist

ARS - SUBMENU.ARS.create_role

ADMIN - SUBMENU.ADMIN.users_userlistjson

Added access:

SUBMENU.ADMIN.roles_list

SUBMENU.ADMIN.users_list

SUBMENU.ADMIN.userlistjson

Regards,

Brijit