Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

AD group assigned to incorrect account using Entitlements With New Accounts

ZA
New Contributor III
New Contributor III

Hi All,

I have a REST based app but we require an AD group to be assigned to the user when an account is created so I added the AD group in "Entitlements with New Accounts" in the endpoint. Normally this works perfectly fine but we have a group of users that have multiple AD accounts (privileged account and their normal employee account). Saviynt is assigning the AD group to their privileged account rather than their normal account. I'm not sure how Saviynt determines which of the 2 accounts to grant the access, maybe alphabetical order, not sure.

What can we do so that these users get the AD group to the correct account (or even both AD accounts should be fine)?

4 REPLIES 4

armaanzahir
Valued Contributor
Valued Contributor

Hi @ZA ,

We had encountered a similar issue in our instance where the entitlement configured as "Entitlements with new account" (which belonged to another AD application) got assigned to the application for which we configured the "Entitlements with new account".

There is an open ticket on this, and engineering work is in progress. 

For now, what you can do is create an actionable analytic which would detect that, if an account has been newly provisioned in app1(detection from the arstasks table), trigger an add access task for app2 and run this analytic on a scheduled frequency.

Configuring Allowed Actions (saviyntcloud.com)

Thanks,

Armaan

Regards,
Md Armaan Zahir

ZA
New Contributor III
New Contributor III

Hi @armaanzahir ,

I see. So those users also had multiple AD accounts and the entitlement was assigned to the wrong account?

Saviynt does not able to classify or does not have configuration now that based on account type assigned entitlement on new account, hence you can resolve this using Actionable analytics. https://docs.saviyntcloud.com/bundle/EIC-Admin-v23x/page/Content/Chapter17-EIC-Analytics/Managing-An... 

Please submit idea ticket for enhancement   https://ideas.saviynt.com/ideas


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

armaanzahir
Valued Contributor
Valued Contributor

Yep 🙂

Regards,
Md Armaan Zahir