Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

Disble account when transferred to another entities.

ejeong
Valued Contributor
Valued Contributor

Hi

We are provioning to mutiple AD domains based on company name.

When companyname is updated, we can see remove access tasks are created related to old company but no disable account is created.

If we have to control it with user update rule,,

We need to create a lot of user update rules to disable account

If companayname is updated and companyname is not equal to "A" then create disable account task for "B" "C" domain..Or we need to control it with analytics reports

Is these two options are only feature available in this use case?

 

1 REPLY 1

avinashchhetri
Saviynt Employee
Saviynt Employee

Hello @ejeong,

You can configure the endpoints and connectionJSON to just create 1 task to disable the account and not create each tasks per entitlement.

  • In the endpoint set the "Create Dependent Entitlement Task for Remove Access" to Off
  • In the AD connector, under REMOVEACCOUNTACTION parameter, set the JSON  value for deleteAllGroups to Yes e.g. "deleteAllGroups": "Yes"

 

In the user update rules, the endpoints is a dropdown and you cannot select more than one but you can add actions and add them as shown below.

avinashchhetri_0-1657228912262.png

 

 

 

 

 

 

If I have completely mis-understood your question, please feel free to elaborate.

 

Regards,

Avinash Chhetri

Regards,
Avinash Chhetri