and more in a single search tool across platforms. Read the announcement here. |
01/31/2023 02:42 PM
Is it possible to baseline a birthright role for users we have detected match the entitlement list through recon? For example, we have birthright roles for salaried versus hourly employees, and when you move between statuses we successfully remove and add one role or the other using birthright. This doesn't work for users who gained access to the role entitlements before Saviynt was in place. It would be ideal if we could baseline the role somehow so that would work for even "legacy" employees.
I know this is possible for applications and out-of-band access so thought it could be possible for this use case as well.
Solved! Go to Solution.
01/31/2023 02:47 PM
Use baseline feature under endpoint
02/01/2023 05:44 AM
I was aware of this, but it will also baseline birthright role or enterprise/application role? How does it do this?
02/01/2023 08:05 PM
Only Entitlement (actual access) will be baselined. you can use source column of role_user_account to baseline as custom solution
02/03/2023 06:13 AM
It seems like writing an analytic that periodically looks for that or the birthright condition and removes access will be the solution.
02/03/2023 06:46 AM
I did have one more thought. Wouldn't this also be resolved for us by making the birthright technical rule detective and running the detective rule job periodically? What are the downsides to that? What is the future of this capability given that job type is deprecated?