and more in a single search tool across platforms. Read the announcement here. |
04/18/2023 11:59 AM
We have a use case to add an User to an AD Group before he gets inactivated. The User Import sets User Status based on the User Source system (HR). Is there a way to apply the AD group action before the User Import inactivates the User? We have AD application set up as another Security System/Endpoint.
We added a policy trigger on the User status change which created a pending task for adding group access. But that pending taskk fails with "User is not Active" message.
04/18/2023 12:24 PM
Hi @igaravi
Can you enable below config and try? This will be available in Global Configuration.
Thanks
04/20/2023 08:52 AM
Hi there,
That Global Config makes User Update Rules act on inactive users and accounts. The problem is, you can't add access from a User Update Rule. You have to have the User Update Rule re-run a Technical Rule that adds access. Since this global config is limited to user update rules, the technical rule run still generates the same error.
04/18/2023 08:25 PM
You can create user update rule and create task based on user status changed to inactive
04/20/2023 08:55 AM
That's what we've tried, but Saviynt refuses to add access to inactive users. Since the user being inactive is the trigger to disable the account, we can't add access. Really the "access" in this case is a group that denies a member account access to anything in AD, even if the account is still logged in when the group is added.