Saviynt unveils its cutting-edge Intelligence Suite products to revolutionize Identity Security!
Click HERE to see how Saviynt Intelligence is transforming the industry.
Saviynt Copilot Icon

create remove access task for all entitlements when there is remove account/disable account task

sudheera
New Contributor
New Contributor

Hi,

We need to remove all entitlements in the account whenever there is a removeaccount task /disable account task is created for REST application, as all the ent are not getting removed from accounts from app end when there is remove/disable account.

as of now we are following these procedures

1)for leaver, we are creating user update rule to perform the deprovision access

2)from ARS if end user request for remove/disable account request we are creating analytics report and from that it is creating deprovision access for all entitlements.

Do we have any other approach to get remove all entitlements from accounts whenever there is remove/disable account task is created for the accounts?

19 REPLIES 19

NM
Esteemed Contributor
Esteemed Contributor

@sudheera you can set a configuration on endpoint 

"Create dependent remove access task"

So when a remove account task gets created it will automatically create remove access task.


If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'

sudheera
New Contributor
New Contributor

HI,

I have updated the config changes, but it is not creating remove access tasks automatically.

Do i need to change any other settings?

NM
Esteemed Contributor
Esteemed Contributor

@sudheera did you try to raise a remove account request? 

Is it approved?

Does the user have access assigned?


If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'

sudheera
New Contributor
New Contributor

Yes, remove account request is created. we are using automatic approval for remove.

user have 3 entitlements.

NM
Esteemed Contributor
Esteemed Contributor

@sudheera by any chance are the  task in pending state for the access?  

And I hope you are trying to remove account for the endpoint for which access are present.

Share task screenshot as well.


If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'

sudheera
New Contributor
New Contributor

by any chance are the  task in pending state for the access?  -No

sudheera_0-1729154587060.png
sudheera_1-1729154660509.pngsudheera_2-1729154709807.png

@sudheera - We have edited this message to mask sensitive information from an attached image. Please refer private message we have sent you on same]

NM
Esteemed Contributor
Esteemed Contributor

@sudheera can you share the remove account task too which was created via request.


If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'

sudheera
New Contributor
New Contributor

HI,

sudheera_0-1729155135227.png

sudheera_1-1729155213002.pngsudheera_2-1729155239301.png

 

NM
Esteemed Contributor
Esteemed Contributor

@sudheera is it a disconnected application?

And what is the request option set for entitlement type?


If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'

sudheera
New Contributor
New Contributor

Request option is Table.

sudheera_0-1729155846344.png

It is Oracle EBS DB connector application

NM
Esteemed Contributor
Esteemed Contributor

@sudheera we have the same configuration in 24.5 and it works fine for us.


If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'

sudheera
New Contributor
New Contributor

I tried the above solution for REST connector in 24.4 version. It is working fine.

Are there any limitations with DB connector?

  • Can you try with new request or user. it works well irrespective of version

Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

Hi,

Yes, it is working irrespective of version.

It is working for REST connector application, but it is not working DB connecter application.

Are there any limitations on connector type?

There is no limitation its working in 24.9 also


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

rushikeshvartak
All-Star
All-Star

There are 2 configs 

  • Endpoint Level  - Create Dependent Entitlement Task for Remove Access
    rushikeshvartak_0-1729097450700.png

     

  • Entitlement Type Level - Create task Action
  • rushikeshvartak_1-1729097471939.png

     


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

HI,

i have changed the configurations, but it is not creating remove access tasks. do i need to change any other configs?

ShantanuKumar
Regular Contributor
Regular Contributor

Team, Could you please help us with why it is not working even after setting the correct configuration? Or do you need us to open a ticket?

Please open support ticket


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.