Click HERE to see how Saviynt Intelligence is transforming the industry. |
08/20/2024 01:06 AM
Hi all,
We have configured a logical endpoint for AD and the account name rule is currently set with the option for check unique account as 'All', same as the base AD.
But we see, the following error throws up when the user has an inactive account for logical AD app and is trying to raise a new account request for the same logical app. Please note the user has an active account in the Base AD and has an inactive account in the Logical AD app.
How can we resolve this error?
We also tried removing this config 'All' and left it empty, that actually solved the problem. But want to know what is the impact of removing this option? Is there anything else that will solve this problem?
Thanks & Regards,
Sinchana
Solved! Go to Solution.
08/20/2024 01:08 AM
Hi @SinchanaC is it inactive or suspended from import service.
Don't add 'All' use only inactive and manually suspended.
08/20/2024 01:21 AM
It is in inactive state, not suspended from Import service.
I tried adding the above mentioned condition. It works. Could you also please let me know what is the impact if we remove 'All' and keep it empty?
Thanks & Regards,
Sinchana
08/20/2024 05:04 AM
It tries to create new account , when it tries it validates what all status of existing accounts to be checked as user can have multiple accounts under endpoint
08/20/2024 01:29 AM
@SinchanaC , it just stops users to raise a new account request if new account already exist configured to NO.
i haven't seen any impact as such till now.