Click HERE to see how Saviynt Intelligence is transforming the industry. |
09/04/2023 12:34 AM
Hi all,
How can I deprovision certain access only for user update rule?
Appreciate any input, thank you
09/04/2023 12:53 AM
Can you please elaborate on the requirement? Do you want to deprovision certain access using the user update rule upon user metadata changes?
09/04/2023 01:11 AM
Hi @naveenss ,
Thanks for the prompt response. Yes, we only want to deprovision certain access using user update rule upon user attribute change.
For example, user account in AD is a member of Account Receivable (AR) and Account Payable (AP).
Upon change of user's department attribute, I want to deprovision the AP access but keep the AR
09/15/2023 04:53 AM
@println-titan - user update rules have a specific action 'Revoke selected access' you can use that action to specify the endpoint and entitlement to be revoked for the particular endpoint
09/17/2023 09:20 PM
Use below option https://docs.saviyntcloud.com/bundle/EIC-Admin-v23x/page/Content/Chapter05-Policies/Updating-User-Up...
Revoke Selected Access | Remove Access Task | From Release v5.5.0SP2 onwards, Revoke Selected Access action is introduced using which you can trigger remove access tasks for selected entitlements and endpoints without deactivating the account. Selecting Revoke Access allows you to select the Endpoint (All or specific endpoint) and specify the Entitlements under the endpoint for which you want to create remove access task. Based on the condition mapped, the revoke access action is triggered and remove access tasks are created for the respective endpoint. |