Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

Assign Access to Primary account (AD) if user has multiple accounts in single endpoint

stalluri
Regular Contributor II
Regular Contributor II

Users will have multiple accounts as Saviynt supports it.

Users:

  1. User 1 :

    1. Have 4 AD accounts: sam(Primary), sam.s, sam.w, sam.ws

    2. Atlassian: sam(primary)

  2. User 2 ;

    1. Have has 2 accounts: vam(primary), vam.w

    2. Atlassian: vam(primary)

  3. User 3 :

    1. Have 3 AD accounts: ram(primary), ram.d, ram.s

    2. Atlassian: ram(primary)

  4. user 4 :

    1. Have 1 AD account: san(primary)

    2. Atlassian: san(primary)

 

Endpoint:

User is trying to request an entitlement from "Atlassian" endpoint, which have parent and other entitlements.

associated entitlements as below:

  • Entitlement: Change Management //endpoint is "Atlassian"

ARS Request:

User is trying to submit a request for the above endpoint and the task are getting created for both parent and child entitlements.

 

Parent entitlement is getting assigned to correct account.

 

where as other/linked entitlement of AD is picking a random account and assigning the access.

 

Accounts picked/linked after task complete: (current output)

  1. User 1 :

    1. sam.s //AD

    2. sam(primary) //Atlassian

  2. User 2 ;

    1. vam.w //AD

    2. vam(primary) //Atlassian

  3. User 3 :

    1. ram.d //AD

    2. ram(primary) //Atlassian

  4. user 4 :

    1. san(primary) //AD

    2. san(primary) //Atlassian


Actual/Expected Output: It has to assign to primary account

User 1 :

    1. sam(primary) //AD

    2. sam(primary) //Atlassian

  1. User 2 ;

    1. vam(primary) //AD

    2. vam(primary) //Atlassian

  2. User 3 :

    1. ram(primary) //AD

    2. ram(primary) //Atlassian

  3. user 4 :

    1. san(primary) //AD

    2. san(primary) //Atlassian

Summary/requirement:

We need to have a config where we can set up a logic, so that system can pick the primary account or system has to directly select the primary account.


Best Regards,
Sam Talluri
If you find this a helpful response, kindly consider selecting Accept As Solution and clicking on the kudos button.
2 REPLIES 2

rushikeshvartak
All-Star
All-Star

This is known issue. You should have 1-1 account with endpoint and domain


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

stalluri
Regular Contributor II
Regular Contributor II

Is there any enhancement for this?

I created one so.
https://ideas.saviynt.com/ideas/EIC-I-4975


Best Regards,
Sam Talluri
If you find this a helpful response, kindly consider selecting Accept As Solution and clicking on the kudos button.