Click HERE to see how Saviynt Intelligence is transforming the industry. |
04/12/2022 01:19 PM
Let us says I have an Active directory 100K+ groups, 100K+ active accounts in that AD. There are many applications in the company that uses AD group membership to control access to applications. In an initial setup, I have reconciled/imported all groups and accounts in to Saviynt so users can request for group membership.
Let us assume there are 200 - 300 applications each uses set of AD groups (says 2 to 20). For end users this is a cumbersome process to search for groups and request for access/membership.
So I want to start using the Endpoint filter facility/option provided by Saviynt so that set of groups can be represented as logical application/endpoint filter based applications/endpoint.
Do Saviynt see any limitations or performance issue in using endpoint filter beyond certain number of logical endpoints? if yes what is maximum number of logical applications/endpoint supported.
Solved! Go to Solution.
04/12/2022 02:58 PM
Hi,
No such documentation available which mentions the limitations if we have more number of endpoint filters configuration. However in your case count seems to be high. It would be good to go ahead with entitlement requests Instead of onboarding 200-300 applications to represent AD groups. You can suggest customer to add user friendly display names for entitlements in AD so when you import those will be available in Saviynt. User can search based on the display names.
Thanks,
Pallavi
04/12/2022 02:58 PM
Hi Vijaya,
There is no such limitation with respect to creating no. of endpoints in endpoint filter, confirmed with the concerned team as well. You can go ahead creating the same using endpoint filter.
Thanks
Nikita