Click HERE to see how Saviynt Intelligence is transforming the industry. |
08/31/2024 07:56 AM
Hi Team,
We could see that the parent AD endpoint got disabled due to the child AD endpoint got disabled. In the user update rule, we have kept disable Account task action child endpoint and we have not kept the parent endpoint name. Can anyone help on this how is this possible?
08/31/2024 08:44 AM - edited 08/31/2024 08:46 AM
@nitishdas , you can not disable or enable child endpoint account as that is a logical entry.
Child endpoint account just confirms whether account is in group or not. To make any changes to child account , it is actually removing / adding group membership.
Remove the disable child account action from user update rule. Instead you can have deprovision access.
08/31/2024 09:20 AM
Action : Keep deprovision access in rule for child endpoint