Saviynt unveils its cutting-edge Intelligence Suite products to revolutionize Identity Security!
Click HERE to see how Saviynt Intelligence is transforming the industry.
Saviynt Copilot Icon

Correct Behavior of Remove Ent Task in Entitlement Map

tuhink
Regular Contributor
Regular Contributor

I am trying to create a use case where if a user requests removal of one entitlements it should automatically remove other entitlements specified.

For this I tried using the "Remove Ent Task" from Entitlement Map.

tuhink_0-1717082312610.png

For this, in one entitlement (ent1) map I have added another entitlement(d_ent2) & selected "Remove Ent Task".

The behavior I found is, if ent1 & d_ent2 belongs to same endpoint, then on remove entitlement of ent1, remove entitlement task for d_ent2 gets created.

But if ent1 & d_ent2 belongs to different endpoint, then on remove entitlement of ent1, no revoke task is getting created for d_ent2.

Is this expected behavior or I may be missing something?

16 REPLIES 16

rushikeshvartak
All-Star
All-Star

Remove task should be created irrespective of endpoint in entitlement map


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

tuhink
Regular Contributor
Regular Contributor

Hi @rushikeshvartak thank you for your prompt response. But when I am using entitlement from same endpoint, and modifying the account to remove the entitlement(ent1), the dependent one(d_ent2) is automatically getting added with that removal request. But if its from different endpoints, only removal task of that for that entitlement(ent1) is getting created. No other task is getting created. 

NOTE: I am only using the Remove Ent Task. I do not want the dependent task option. (you can refer to the screenshot for exact config

@tuhink  try below:

request filter - true, add depednent task-true, remove task -true, exclude task- false


Thanks,
Raghu
If this reply answered your question, Please Accept As Solution and hit Kudos.

tuhink
Regular Contributor
Regular Contributor

@Raghu if I select add dependent, then the 2nd entitlement will also get added when I add 1st entitlement. My use case is only with removal of 2nd entitlement; I do not want the 2nd one to get added automatically during add access

Conditional addition is not supported 


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

sorry didnt get what do you mean by Conditional addition

Providing one of the entitlement access from many.


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

What is request option for second endpoints under entitlement type


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

tuhink
Regular Contributor
Regular Contributor

@rushikeshvartak  I tried for 2 type of entitlements for second endpoints. One was drop-down(single) and another was selected as none

NM
Honored Contributor II
Honored Contributor II

Hi @tuhink , Instead of none select "none(Create task) from down

tuhink
Regular Contributor
Regular Contributor

Hi @NM for my 2nd endpoint I want the user to have any one of the entitlement.

so I initially tested with drop-down(single). But as it was not working, so I thought of changing the request option & tested with none.

NM
Honored Contributor II
Honored Contributor II

@tuhink Did you try with None(create task)

tuhink
Regular Contributor
Regular Contributor

Just tried, but didnt work

tuhink
Regular Contributor
Regular Contributor

I tested multiple scenarios.

What it seems like if I select only Remove Task, it only works within Same Endpoint.

But if I select both Dependent Task & Remove Task, then it works within same Endpoint & different Endpoint as well.

NM
Honored Contributor II
Honored Contributor II

Did you also try by keeping request option same for both the endpoints??

tuhink
Regular Contributor
Regular Contributor

Yes I tried but didn't work. I used both as Table.