Click HERE to see how Saviynt Intelligence is transforming the industry. |
11/30/2023 05:08 AM
Hi Team,
We have integrated Saviynt with a LDAP application, Once the account import full job runs, it deletes the Account Entitlement mapping. But during the access import, it properly corelates the account entitlement.
Please let me know, is there any configuration needs to perform?
Regards,
Balaji Epari
11/30/2023 09:27 AM - edited 11/30/2023 09:18 PM
Hi @BalajiEpari ,
Can you add below config in CONNECTION CONFIGURATION field of your Endpoint and check once.
{"conf":[{"ADDMEMBERTOENT":"TRUE"},{"ADDUSERTOENT":"TRUE"}]}
11/30/2023 09:10 PM
Since you are on 23.8
{"conf":[{"ADDMEMBERTOENT":"TRUE"},{"ADDUSERTOENT":"TRUE"}]}
12/01/2023 06:27 AM
Hi @rushikeshvartak / @pmahalle
We already added connection config as you mentioned. Still same issue.
There is one difference between our LDAP system and AD/other LDAP systems are member/memberOf attribute will be there in Groups entries instead of Accounts.
PFB Group entry Screenshot.
Regards,
Balaji Epari
12/01/2023 06:38 AM
Hi @BalajiEpari ,
What's your ENTITLEMENT_ATTRIBUTE value in your connection. Can you add member as a value and check once.
12/01/2023 07:09 AM
Hi @pmahalle
Yes, I have added member for ENTITLEMENT_ATTRIBUTE , so during Access import it properly corelates accounts with entitlement. But once we run the Account import it deletes the existing account-entitlement mappings in Saviynt.
Regards,
Balaji Epari
12/02/2023 08:23 PM
what is config for status threshold
12/01/2023 08:18 AM - edited 12/01/2023 08:20 AM
@BalajiEpari Could you please refer the trouble shooting guide
Troubleshooting (saviyntcloud.com)
Map the ACCOUNTID attribute with distinguishedName of the account in the ACCOUNT_ATTRIBUTE parameter.
If this reply answered your question, please Accept it As Solution to help others who may have a similar problem.
12/01/2023 08:29 AM - edited 12/01/2023 08:34 AM
Hi @SumathiSomala
We already mapped ACCOUNTID with dn in ACCOUNT_ATTRIBUTE. Checking outer Troubleshootings but didn't find any.
Above document is for corelation issue during Access import. which is working fine us.
But during our account import it deletes all existing account-entitlement mappings.
Regards,
Balaji Epari
12/02/2023 01:52 AM
@BalajiEpari please check the reconciliation field for account and access import.