Saviynt unveils its cutting-edge Intelligence Suite products to revolutionize Identity Security!
Click HERE to see how Saviynt Intelligence is transforming the industry.
Saviynt Copilot Icon

Orphaned Service Account Not Included in Service Account Campaign

NikitaPawar_
New Contributor III
New Contributor III

Hello Team,

We are trying to create a service account campaign for the XYZ endpoint, but we have encountered an issue where orphaned accounts with the service account type are not being captured. The campaign only includes service accounts mapped to users, and the orphaned service accounts are excluded by default.

Steps Taken:

  1. Ensured prerequisites are met: 
     -  Set Service Account Type = Service Account at the endpoint level.                                                         
    -   Each account owner is mapped with the Primary Certifier rank.
  2. Tested the following advanced queries, but orphaned accounts are still not included.
  • AccountType in ('Service Account')
  • AccountType in ('Service Account') and status in ('Manually Provisioned','1','Active')
  • name like '%IFTestUser%'    ........Specifying orphan account name as hardcoded
  • accountkey not in (select accountkey from user_accounts) and endpointkey=134

    Issue: Is there support for orphaned accounts with the "Service Account" type in service account campaigns? If so, could you provide guidance on capturing these accounts in the campaign?

    Expected Outcome:
    We would like orphaned service accounts to be included in the campaign along with user-mapped service accounts.

    Thank you for your assistance.

    Regards, 
    Nikita Pawar
    @SPAL @gauravchandok 
9 REPLIES 9

NM
Esteemed Contributor
Esteemed Contributor

@NikitaPawar_ 

Try this in advance query 

accounttype in ('Service Account','Service')


If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'

NikitaPawar_
New Contributor III
New Contributor III

Tried with this query :  accounttype in ('Service Account','Service')
Still not captured orphaned service account in campaign 

NM
Esteemed Contributor
Esteemed Contributor

@NikitaPawar_ can you share logs?


If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'

Does account have certifiers?


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

Yes @rushikeshvartak 
Account have owners with primary rank 

@NM Follow logs in attached file 
and can you just clear this doubt 
Is orphaned accounts with the "Service Account" type supported or captured  in service account campaigns or not ?

Because we also checked with this 
https://forums.saviynt.com/t5/identity-governance/orphan-account-not-not-showing-in-service-account-...

@NM 

Is orphaned accounts with the "Service Account" type supported or captured  in service account campaigns or not ? 
Its captured 


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

NM
Esteemed Contributor
Esteemed Contributor

@NikitaPawar_ yes it shows in the camapign


If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'

Ensured Prerequisites for Certification:

  • Set the Service Account Type to "Service Account" at the endpoint level.
  • Mapped account owner to the Primary Certifier rank for each account

Are there any additional configurations necessary from a certification perspective that I may have missed? 
With this config certification comes under in-progress status but not capturing orphaned service account

  • Please share campaign config and sample account config screenshot

Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.