and more in a single search tool across platforms. Read the announcement here. |
10/30/2023 01:37 PM
Hi,
Does Saviynt's Azure connector (ootb) support advanced queries (ConsistencyLevel:eventual), what looks to be required (MS Graph) to e.g. filter out groups synchronized from onPremise AD to Azure?
If yes (or if there is a way without this to achieve the same), since what SAV version?
10/30/2023 09:22 PM
which graph API you trying to call ? and from which connector
10/31/2023 11:27 AM
Standard connector:
Configuring the Integration for Account and Group Import (saviyntcloud.com)
Filtering already security groups only:
"group_filter": "securityEnabled eq true"
so we would like to extend this to also cloud only...
10/31/2023 02:34 PM
Refer this post: https://forums.saviynt.com/t5/identity-governance/excluding-azuread-groups-of-membership-type-is-dyn...
10/31/2023 04:15 PM
You are presuming there that all groups follow any naming convention, like start with Az in case of Azure or so but that's not the case.
Group object has onPremisesSyncEnabled attribute, but to reach it required are advanced queries. Filter
> "group_filter":"securityEnabled eq true and onPremisesSyncEnabled ne true"
seems doesn't work in Sav (works in general if advanced queries supported).
Or anyone has a different experience or another way not groups name based?
10/31/2023 09:48 PM
only standard filters works.
You can additionally use entitlement filter
11/01/2023 09:39 AM
> You can additionally use entitlement filter
You mean e.g. name based or so... If so, this is not a way.
Is possible to connect to Azure (MS Graph) using any other generic connector (REST?) to be able achieve what is needed?
11/01/2023 09:40 PM
You can use generic REST connector with MS Graph API