We have a use case where we have AD entitlements which are dynamic in AD. We want to bring those dynamic entitlements into Saviynt.
What is the best way to do this? Our thought was to create roles which contain the dynamic AD entitlements and then use technical rules to assign the access.
Is there any other ways to set up dynamic entitlements?
Also, is there a way on the users identity page to determine is access was assigned as birthright role or access request? because if we go the technical rule route, this will be BR access and we want to be able to distinguish between BR entitlements and access requests.
You can create enterprise role and have naming conventions as Birthright- and when entitlement is assigned from birthright arstasks table store source as provrule