Click HERE to see how Saviynt Intelligence is transforming the industry. |
02/05/2024 02:23 AM
Hi All,
We encountered an issue when reconciliating the AD account status on Saviynt. Due to some reason, few AD accounts were deleted manually on Windows ActiveDirectory and after running the AD account import job on Saviynt, accounts status remain 'Inactive' instead of changing to 'Suspended from Import Service'.
AD accounts that were deleted through Saviynt tasks are showing correct status ('Suspended from Import Service'), only those that were deleted manually on Windows ActiveDirectory are having the status issue, verified that they have been completely removed on Windows ActiveDirectory.
We have checked the log file and those AD accounts that were deleted manually on Microsoft ActiveDirectory does not exist during account import. Based on Saviynt document, account status should change to 'Suspended from Import Service'. Searching for Accounts (saviyntcloud.com)
Any advice on the matter is greatly appreciated.
Thanks,
Suet Yie
02/05/2024 06:29 AM
Hi @SuetYie ,
May i know the your AD connector STATUS_THRESHOLD_CONFIG- ? everything okay means ? go with CQ query after manually suspended or inactive - add condition update the status 'suspended from import'
already account info deleted in target system (Ad) we can update manually update status.
Thanks,
Raghu
If this reply answered your question, please Accept As Solution and give Kudos to help others who may have a similar problem.
02/05/2024 06:31 PM
Hi Raghu,
Please find below the STATUS_THRESHOLD_CONFIG, based on our understanding on the config it seems to be correct, other accounts status are showing expected result.
{
"statusAndThresholdConfig": {
"statusColumn":"customproperty30",
"activeStatus":["512","544","66048"],
"deleteLinks":true,
"accountThresholdValue": 20000,
"correlateInactiveAccounts": true,
"inactivateAccountsNotInFile": false
}
}
May I know what could possibly be the cause of preventing account status changing to 'suspended from import service' even tho the account has been deleted on AD and does not exist during the account import? We would like find the root cause instead of changing the accounts status manually.
Thanks,
Suet Yie
02/05/2024 06:49 PM
02/06/2024 12:17 AM
Hi @rushikeshvartak ,
Please find my comments as below,
Thanks,
Suet Yie
02/06/2024 08:51 PM
If you have changed account status manually in past then it cause data issue.
02/05/2024 04:04 PM
I have the exact same issue with one particular account. The account was deleted in AD and I expect it to switch to Suspended from Import and it is stuck at Manually Suspended
02/06/2024 11:06 PM
@SuetYie - we are facing same issue our system, but Saviynt team not given any solution eod .alternative approach we can do manually ,anyway target system in data deleted.
if still checking with same account exiting person not able send new request also bez it is manually suspended.
Thanks,
Raghu
If this reply answered your question, please Accept As Solution and give Kudos to help others who may have a similar problem.