Saviynt unveils its cutting-edge Intelligence Suite products to revolutionize Identity Security!
Click HERE to see how Saviynt Intelligence is transforming the industry.
Saviynt Copilot Icon

Deprovision certain access only for user update rule

println-titan
New Contributor III
New Contributor III

Hi all,

How can I deprovision certain access only for user update rule?
Appreciate any input, thank you

4 REPLIES 4

naveenss
All-Star
All-Star

Hi @println-titan 

Can you please elaborate on the requirement? Do you want to deprovision certain access using the user update rule upon user metadata changes?

 

Regards,
Naveen Sakleshpur
If this reply answered your question, please click the Accept As Solution button to help future users who may have a similar problem.

Hi @naveenss ,

Thanks for the prompt response. Yes, we only want to deprovision certain access using user update rule upon user attribute change.

For example, user account in AD is a member of Account Receivable (AR) and Account Payable (AP).
Upon change of user's department attribute, I want to deprovision the AP access but keep the AR

shivmano
Regular Contributor III
Regular Contributor III

@println-titan  - user update rules have a specific action 'Revoke selected access' you can use that action to specify the endpoint and entitlement to be revoked for the particular endpoint

rushikeshvartak
All-Star
All-Star

Use below option https://docs.saviyntcloud.com/bundle/EIC-Admin-v23x/page/Content/Chapter05-Policies/Updating-User-Up... 

rushikeshvartak_0-1695010759482.png

Revoke Selected Access

Remove Access Task

From Release v5.5.0SP2 onwards, Revoke Selected Access action is introduced using which you can trigger remove access tasks for selected entitlements and endpoints without deactivating the account. Selecting Revoke Access allows you to select the Endpoint (All or specific endpoint) and specify the Entitlements under the endpoint for which you want to create remove access task. Based on the condition mapped, the revoke access action is triggered and remove access tasks are created for the respective endpoint.


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.