Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

Can we prevent users from removing their birthright roles from Manage My Access

Sampo
New Contributor III
New Contributor III

Hi,

we're assigning roles to users using technical rules as birthrights.

When an enduser clicks Manage My Access link, there is an option to manage Roles and the user can choose to delete the roles that were granted as birthright roles. Is it possible to prevent the users from doing that or hide the 'Roles' section completely from Manage My Access?

best regards,

Sampo

 

4 REPLIES 4

dgandhi
All-Star
All-Star

Below post has the solution:

https://forums.saviynt.com/t5/identity-governance/requestable-role-query/m-p/36868#M20876

Is there any identification at the Role level which states whether a role is birthright role or not? If there is identification then based on that identification you can write your role query.

In our case , all the birthright roles had one role CP value as "BirthRightRole" and in Role query, we showed all the roles whose CP value was not like 'BirthRightRole' this way the birthright roles were not available for request.

Please check below config:

dgandhi_0-1686229265931.png

 

 

Thanks,
Devang Gandhi
If this reply answered your question, please Accept As Solution and give Kudos to help others who may have a similar problem.

Sampo
New Contributor III
New Contributor III

Hi Devang,

the Request Role Query seems to hide the roles from ARS but the roles are still visible in 'Manage My Access' page and the user has the option to try to delete it, even though the deletion will fail with "Role.Not.Requestable" error message. Ideally we'd like to hide the roles from the 'Manage My Access' page or hide the delete button that is visible for each role.

 

best regards,

Sampo

KasperT
New Contributor III
New Contributor III

Hi Devang,

Any comments on Sampo's question? We tried to open FD ticket for this but they wanted us to make forum post instead. No need for new post as there is this one.

Hi @KasperT  and @Sampo ,

For Enterprise Role, there is no such config to remove the delete button or even remove the 'Roles' part from the Manage my Access tile since it showing all the available accesses that you have.

This would be an enhancement request that you can submit on Ideas Portal - https://ideas.saviynt.com/ideas/

Thanks.