and more in a single search tool across platforms. Read the announcement here. |
02/14/2024 09:51 PM
Hi Team,
we have a use case, where we want to assign "ABC group" as primary while disabling and moving the account to Disable OU. we are using DisableJSON and I couldn't anything where I can add logic for removing domain users(513) groups and adding "ABC group" as primary. Hence I created the technical rule with the below condition but the task is not being generated. i am assuming might be that the add task will not be generated once the account is disabled
we are using DisableJSON with the below query which is working user is being disabled, the account moves to disable OU, and all groups are removed only unable to add other group as primary
{
"moveUsertoOU": "OU=DisabledUsers,DC=itlab,DC=com",
"deleteAllGroups": "Yes",
"userAccountControl": "514"
}
technical rule
02/14/2024 10:01 PM
if account status is inactive then task will not be created
02/16/2024 09:02 AM
Hi @rushikeshvartak is there any way where we can add a group and mark primary before disabling?
also, can you let us know what exactly this option does inDISABLEACCOUNTJSON in AD?
deleteAllGroups
02/19/2024 07:30 AM - edited 02/19/2024 07:30 AM
Hi @navneetv ,
One way could be (not that nice though) ,
1)In your rule where you disabling user, take two action 1)add account to primary group 2)disable user account
2)Have different wsretry jobs based on task type. Run the add access first and then disable account. You can merge all in one trigger and have them sequential
3)But if you use deleteALLGroups, it will remove all groups that are added to user in AD so no point of doing 1 and 2. So don't select this option
4)Use analytics to remove all groups from Ad except your primary one
Thanks,
Amit
02/19/2024 10:31 AM
deleteAllGroups - It removes all groups assigned to account.
02/29/2024 06:30 AM
Hi @rushikeshvartak @AmitM I tried to make another group as primary in the active saviynt profile but it is giving an error . can you suggest how to add a group and make it primary to active profile ?
error
Error while ADD operation for account-gab.geronimo to Group-1181 in AD - [LDAP: error code 21 - 00000057: LdapErr: DSID-0C091284, comment: Error in attribute conversion operation, data 0, v4563]Error while ADD operation for account-gab.geronimo to Group-1181 in AD - [LDAP: error code 21 - 00000057: LdapErr: DSID-0C091284, comment: Error in attribute conversion operation, data 0, v4563]