Saviynt unveils its cutting-edge Intelligence Suite products to revolutionize Identity Security!
Click HERE to see how Saviynt Intelligence is transforming the industry.
Saviynt Copilot Icon

Parent AD endpoint disabled due to child AD endpoint has been disabled

nitishdas
New Contributor
New Contributor

Hi Team,

We could see that the parent AD endpoint got disabled due to the child AD endpoint got disabled. In the user update rule, we have kept disable Account task action child endpoint and we have not kept the parent endpoint name. Can anyone help on this how is this possible?

2 REPLIES 2

Amit_Malik
Valued Contributor II
Valued Contributor II

@nitishdas , you can not disable or enable child endpoint account as that is a logical entry. 

Child endpoint account just confirms whether account is in group or not. To make any changes to child account , it is actually removing / adding group membership.

Remove the disable child account action from user update rule. Instead you can have deprovision access.

 

Kind Regards,
Amit Malik
If this helped you move forward, please click on the "Kudos" button.
If this answers your query, please select "Accept As Solution".

rushikeshvartak
All-Star
All-Star
  • How endpoint filter works ?
    • Parent application is actual data for account & entitlement
    • Child entitlement is referenced data for account & entitlement
  • You should only call deprovision access  from child endpoint 
  • If you call any account related action such as enable/disable/remove account it will also impact parent endpoint.

Action : Keep deprovision access in rule for child endpoint


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.