We are delighted to share our new EIC Delivery Methodology for efficiently managing Saviynt Implementations and delivering quick time to value. CLICK HERE.

Forum Posts

Facing issue in creating username generate rule

Hello,We are facing an issue while creating the username using the username generation rule. Below is the advanced configuration we are usingCONCAT(LOWER(LEFT(users.firstname, 1)),LOWER(LEFT(users.middlename, 1)),LOWER(LEFT(users.lastname, 1)),LPAD(F...

Deepu_0-1699967981361.png
Deepu by New Contributor II
  • 298 Views
  • 1 replies
  • 0 kudos

Custom Property Attributes

I have utilised all the User Custom Property attributes (until CP65) for various integrations. I would like to extend it more since we have a lot of transformed values coming up for various provisioning. What's the process to do it?How should we defi...

SowmithriV by Regular Contributor
  • 611 Views
  • 3 replies
  • 0 kudos

Resolved! Create generation email rule via dataset

I am creating generation emal rule.I put all the old addresses and usernames in the dataset(follow picture), and prepend 'old' to emailaddress if the user's username is in attribute2 (username) of the dataset.Otherwise, just username@domain. For exam...

JPMac_0-1699854885366.png
JPMac by Regular Contributor
  • 813 Views
  • 5 replies
  • 0 kudos

Resolved! Create Email generation rule

I want to create an emailgeneration rule along the following requirements.1. Connect user.lastname and user.firstname with concat.concat(user.lastname, user.localname, @domain)2. If looking at dataset (name=oldemail), set displayname if there is a du...

JPMac by Regular Contributor
  • 407 Views
  • 2 replies
  • 0 kudos

Saviynt Azure AD Monitoring

I am looking for capability in Saviynt that can monitor Azure AD users and flag ones that were not created by Saviynt. Does anyone know if Saviynt has the capability and if so where it exists. 

Hindrance by New Contributor II
  • 497 Views
  • 6 replies
  • 0 kudos

Account-Group and Account-Role Membership Associations are missing in Saviynt for ServiceNow

Hello Team,We have integrated ServiceNow with Saviynt as a managed application, Configured the ImportAccountEntJSON to import roles, groups, and accounts; however, Saviynt failed to import few Account-Groups and  Account-Role Associations.Please see ...

Dynamic attributes

I need one help related to a dynamic attribute created under endpoint level. The data type is selected as SQL ENUM but when the user is trying to raise the access request through ARS his account name "e_tnitime" is not populating in the dynamic attri...

nitishdas by New Contributor
  • 1099 Views
  • 19 replies
  • 0 kudos

REST connector issue-connectionJSON token issue

Hi We are having an issue with access token in connection JSON, when we have hardcoded the token values the importaccountentJSON works fine. However we are not able to get the token in connection JSON.1. the API doesn't have any authentication type m...

trivi by New Contributor II
  • 567 Views
  • 3 replies
  • 0 kudos

GSP to Modify Role Users Page

Hi,We have a requirement to customize the Role Users page where we only need to show the list of users part of the role and hide the "Add User" button. This is required in our project so that role owners are not allowed to add users to roles directly...

aksharkay_0-1698905337748.png
aksharkay by New Contributor III
  • 305 Views
  • 2 replies
  • 0 kudos

Resolved! Can we use Enhanced Query Execution to flag large number of accounts as Suspended

Hello,we are decommissioning (removing) many of our SAP endpoints. They have 1000's of accounts. Before we disable the endpoints, security systems and connectors we need to remove all active accounts.The usual method of running a V2 Analytic to Depro...

Enddate for Service Accounts

Hi, We have a requirement that when a service account reaches it's 90 days period of inactiveness (after being disabled), A remove Account task should trigger and this will delete the service account from the Disabled Users OU in AD.To trigger the re...

AshishDas by Regular Contributor II
  • 814 Views
  • 4 replies
  • 0 kudos

Cleanup of account Risks

We have a requirement to do cleanup of accounts. Could you please help with the ways how saviynt performs cleanup of accounts from Backend. Is it done via query of file upload? Also, can the risks involved with cleanup be mentioned?

Kaushik1 by New Contributor
  • 468 Views
  • 4 replies
  • 0 kudos

Resolved! SSO Login Failure with Saviynt Message

We are configuring our environments for SSO using the Single Sign - On option in the UI as we were instructed by our TAM.Everything is configured in Azure as the IdP along with the federated certificate XML being downloaded and added to Saviynt for t...

thumbnail_image004.png Ryne_G_0-1697735963225.png Ryne_G_1-1697736035194.png
Ryne_G by New Contributor III
  • 814 Views
  • 4 replies
  • 0 kudos

Bulk removal of entitlements using file import for service now application (Ticketing based)

Hi, We are using SNOW based ticketing system. Below is the flow and requirement:1. User request required access and account in ARS Tab, Once request approved SNOW create a ticket to the target application team.2. Application team act on the ticket an...

nitishdas by New Contributor
  • 262 Views
  • 3 replies
  • 0 kudos

Changing attribute label and format

Dear community,Our project is not going to use the property "Comment" located in User Details tab. This is a built-in field with string format.We would like to release this property to be reused in a new requirement. Is there any way to change its LA...

FranciscoS by New Contributor III
  • 605 Views
  • 5 replies
  • 0 kudos

Not able to change password from API

Dear community, We have created an user in Saviynt with the aim to be used with API to change user passwords. This user has been set the password by an admin account through API and we have set the localauthenabled and passwordexpired properties with...

FranciscoS_0-1698093913740.png FranciscoS_1-1698093969970.png FranciscoS_2-1698094086145.png
FranciscoS by New Contributor III
  • 457 Views
  • 2 replies
  • 0 kudos

Update User Request

We are trying to use Update User Request to do name changes on users. Currently only Email, System Username, and Secondary Email are able to be changed. When we try to use it to change just the Username field, it doesn't do anything. We raised a supp...

aidanryan by New Contributor III
  • 364 Views
  • 3 replies
  • 0 kudos

Resolved! Saviynt table to store Task Creation / Completion Emails that were sent

Hi Team, Task creation / completion emails gets sent instantly and doesn't require emailhistoryjob to be run. So, the email sent is not stored in EMAILHISTORY_ARCHIVE or EMAILHISTORY table. We would like to review certain task creation / completion e...

Resolved! Password policy for AD service Account

Hello All,Currently, in our AD, the password policy is set to reject when three consecutive numbers are entered. like 123, 234, 456.We also have a blacklist added to saviynt for certain words or common PWs but I am not sure how to implement this. Can...

Joon by Regular Contributor II
  • 475 Views
  • 3 replies
  • 0 kudos

Security System Threshold Limit

Hello,I need some clarifications on the functions of the  NEWACCOUNT Provisioning limit task type. In the documentation it mentions that NewAccount Allows you to specify the provisioning limit for New Account task. The New Account task is generated f...

GOE by Regular Contributor
  • 608 Views
  • 5 replies
  • 0 kudos

Resolved! Roles Request Query is not working

Hi,We are trying to populate the enterprise roles if the roles metadata match the identity metadata. For eg. we want to show the roles If roles.customproperty10 matches with users. orgunitid. We are using the below query, but it is not working for us...

Bharadwaj by Regular Contributor
  • 499 Views
  • 3 replies
  • 0 kudos

Resolved! Deleting Sav user identities

I'm sure this is a common thing but I couldn't find much in the community about it. In our Dev environment, it's easy to make a mistake when we're being exploratory with integrations. We have accidentally imported additional users into our Dev enviro...

Rule for 'Update Account' isn't triggering when user status and other attributes changed.

Hello Saviynt Experts,Problem statement: In Saviynt we have a user update rule which is supposed to trigger whenever any update happens to identity through either API/UI/Import but upon identity update through api, the rule has triggered but there we...

Resolved! SQL query to get Entitlements Hierarchy

Dear community,We are trying to fetch Profile and Role to create an Analytics report.This can be found in every Account > Entitlement Hierarchy tab.However, we are not able to fetch this value from DataAnalyzer through SQL query. We do not find these...

FranciscoS_0-1697455949735.png
FranciscoS by New Contributor III
  • 657 Views
  • 2 replies
  • 0 kudos

endpoint access query not working as expected

Hi All,   I am facing a strange issue while fulfilling following requirement. I wanted to dispany endpoints to only specific sav role members, so accordingly i have created following queries and placed under endpoint access query parameter in endpoin...

sampath18 by Regular Contributor II
  • 638 Views
  • 7 replies
  • 0 kudos

Extend API rate limit of Saviynt

Hi Team,We have an application called Humanica, it is the source for Saviynt to push the user information from Humanica to Saviynt. On October 1st they tried to push some updates for the users from Humanica to Saviynt using Saviynt API. Till Septembe...

Resolved! Entity attribute

Dear community,We are about to use Entity built-in attribute to populate information of interest for every user. (ex. data feed of the employee profile whose source triggered the creation).We want to know if this attribute is used by some OOTB featur...

FranciscoS by New Contributor III
  • 820 Views
  • 7 replies
  • 0 kudos

Preprocessor unable to populate the secondary manager based on the previous manager

Hello Team,Under ModifyUserJSON, we have written pre processor code. For third-party users, we are using CSV to import user data.Using Case:Whenever a user's manager changed, the value of the previous manager has to be saved in the secondary manager ...

Entitlement EndDate in Enterprise role

HiUserCase: User requests an Enterprise role from ARS along with StartDate and EndDate in the request.All the entertainment in the role gets the same StartDate and EndDate in the Target SAP system.Later when a new entitlement is added to the role, th...

HarishG by Regular Contributor
  • 661 Views
  • 8 replies
  • 0 kudos

Resolved! Dataset usage in User Import Preprocessor

Hi Team,We are trying to call pre-processor query to update location, description and 2 more attributes, using  Dataset in Saviynt.We have used below query in User Pre-processor Config JSON while importing user via CSV file. We are fetching the locat...

Activedirecory - Manager DN

Hi ,There is a requirement to fetch user's manager attribute value while creating the AD account and populate it with  AD manager attribute(DN) at the time of account creation.I have tried by specifying as follows in create account json as :"manager"...

Accounts are Suspended randomly

HiWe are facing an issue, that some of the accounts are randomly suspended during the AD import, Even if there are present in the target(AD)During the next run, the account is imported into Saviynt. Any idea why the account are suspended randomly and...

HarishG_0-1696776982504.png
HarishG by Regular Contributor
  • 635 Views
  • 4 replies
  • 0 kudos

Primary Account Type for AD

Where do we set the options for primary account type? Our AD Endpoint has no values to select from. Also, how do we set this in the import to set primary account type for specific accounts that we can identify either by naming convention or by the OU...

sherbert_0-1696535306187.png
sherbert by New Contributor
  • 439 Views
  • 4 replies
  • 0 kudos

Service now -Staus and sub status

Hi Team,We developed a REST connector to integrate a custom ticketing system for the ARS request management of customer applications. With help of ticket status json we can able to get the RITM status into saviynt, but we had requirement to capture t...

Mervinr by New Contributor
  • 475 Views
  • 4 replies
  • 0 kudos

Resolved! Couldn't use inner queries and Database function in preprocessor during import of users

Hi All,We have a use-case to generate unique username and copy username to systemusername in Saviynt. Data is imported from connected HR SAP source. Currently we are using MODIFYUSERDATAJSON to run preprocessor queries.  Use-case should cover:1. user...