Saviynt unveils its cutting-edge Intelligence Suite products to revolutionize Identity Security!
Click HERE to see how Saviynt Intelligence is transforming the industry.
Saviynt Copilot Icon

Multi-Account deployment - E.g. AD or Entra ID

Murmur
Regular Contributor III
Regular Contributor III

Hi everyone, 

I'm wondering how you tackle Users with multiple Accounts in the same Endpoint (e.g. User Account, Admin Account).

Do you have a separate Endpoint for each Account Type? Do you have them in the same Endpoint? 

Both approaches come with their own drawbacks and benefits, such as limitations in the ARS, if you have 2 ccounts in the same endpoint.

Any insight is greatly appreciated 🙂

  

3 REPLIES 3

rushikeshvartak
All-Star
All-Star

You can use same endpoint. Can you elaborate your concern ?


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

Murmur
Regular Contributor III
Regular Contributor III

My concerns are, that 

  • Technical Rules only target the primary account. It seems impossible to target the secondary account. 
  • Unsure if same applies to User Update Rules
  • The ARS issue seems to be fixed in NEO Experience - in the old experience you could not select for which account you request the access
  • Managing of accounts in separate endpoints might be easier and more convenient than setting up actionable Analytics for every edge-case (e.g. this one: Solved: Enable only Primary AD account of a user when user... - Saviynt Forums - 78272)

I'll try it with one endpoint for now, but if annyone has any hints / issues with either of the configurations, feel free to share!

We are using different endpoints to keep configuration keep and easy for maintance


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.