Saviynt unveils its cutting-edge Intelligence Suite products to revolutionize Identity Security!
Click HERE to see how Saviynt Intelligence is transforming the industry.
Saviynt Copilot Icon

Request access for others - Multi users tile not triggering a pending request

Akilan
New Contributor
New Contributor

Hi Team,

We select multiple users and single endpoint and some entitlement. After submitted the request. Pending request is not generating in Request history.

Regards,

Akilan.

21 REPLIES 21

rushikeshvartak
All-Star
All-Star
  • Did you checked logs ?
  • Share input file 

Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

Akilan
New Contributor
New Contributor

Hi @rushikeshvartak ,

1) This happened on 8th-Aug. We can able to get logs for last one week. There is no option to select 8-Aug.
2)We are not using any file to request. we are using UI(tile) to request for bulk users.

Hi @Akilan ,

Make sure to add workflow Workflow for requests for multiple users under Global configurations --> Request --> Bulk section. if not added already and check.

pmahalle_0-1723808642361.png

 


Pandharinath Mahalle(Paddy)
If this reply helps your question, please consider selecting Accept As Solution and hit Kudos 🙂

  • Please submit another request and collect logs.
  • Also validate under Global config - Request below configuration is set 

rushikeshvartak_0-1723815435053.png

  • Auto Approve Workflow for Multiuser request upload
  • Bulk Approval Email Template 

Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

NM
Honored Contributor II
Honored Contributor II

Hi @Akilan , any issue with workflow added under global configuration? do you see an error message when you try to replicate it?

Akilan
New Contributor
New Contributor

Hi Experts,

I have added workflow in global configuration. Now i can see the request is pending with manager.

Issue: If i request for 5 users using multiple access other tile. The first user getting pending request but for other 4 users there is no request created. Please help me in this issue.

  • This can be data issue.
  • Attach email template in global configuration to identify issue also validate logs

Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

Akilan
New Contributor
New Contributor

Hi @pmahalle , @rushikeshvartak , @NM ,

We have added workflow in SS level. The bulk user tile creating request for add access(user already have account, now we are requesting only for access) but not for new account(User previously doesn't have Account). In email attachment validation column I'm getting comments.

1) User:123 does not have account in the Endpoint: ABC

2) User:123 does not have active Account : 123 in Endpoint ABC 

But User is Active and AD account also active.

 

 

 

  • Share input file and logs

Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

Akilan
New Contributor
New Contributor

Hi @rushikeshvartak ,

We couldn't found any error in log and i copied the data after submitting the request.

NOTE: All users mentioned in data  previously doesn't have account in endpoint which we request.

 

usernameendpointaccountnameactionentitlementtypeentitlementstartdateenddatecommentValidationRequest ID
Users1A_EndpointUsers1Dynamic AttributeAccessTypeAll  __GLOBALCOMMENTS__TestUser:Users1 does not have account in the Endpoint: A_Endpoint 
Users1A_EndpointUsers1Add AccessmemberOfEnt1  __GLOBALCOMMENTS__TestUser:Users1 does not have active Account: Users1 in Endpoint:A_Endpoint . 
Users1A_EndpointUsers1Add AccessmemberOfEnt2  __GLOBALCOMMENTS__TestUser:Users1 does not have active Account: Users1 in Endpoint:A_Endpoint . 
Users1A_EndpointUsers1Add AccessmemberOfEnt3  __GLOBALCOMMENTS__TestUser:Users1 does not have active Account: Users1 in Endpoint:A_Endpoint . 
Users2A_EndpointUsers2Dynamic AttributeAccessTypeAll  __GLOBALCOMMENTS__TestUser:Users2 does not have account in the Endpoint: A_Endpoint 
Users2A_EndpointUsers2Add AccessmemberOfEnt1  __GLOBALCOMMENTS__TestUser:Users2 does not have active Account: Users2 in Endpoint:A_Endpoint . 
Users2A_EndpointUsers2Add AccessmemberOfEnt2  __GLOBALCOMMENTS__TestUser:Users2 does not have active Account: Users2 in Endpoint:A_Endpoint . 
Users2A_EndpointUsers2Add AccessmemberOfEnt3  __GLOBALCOMMENTS__TestUser:Users2 does not have active Account: Users2 in Endpoint:A_Endpoint . 
Users3A_EndpointUsers3Dynamic AttributeAccessTypeAll  __GLOBALCOMMENTS__TestUser:Users3 does not have account in the Endpoint: A_Endpoint 
Users3A_EndpointUsers3Add AccessmemberOfEnt1  __GLOBALCOMMENTS__TestUser:Users3 does not have active Account: Users3 in Endpoint:A_Endpoint . 
Users3A_EndpointUsers3Add AccessmemberOfEnt2  __GLOBALCOMMENTS__TestUser:Users3 does not have active Account: Users3 in Endpoint:A_Endpoint . 
Users3A_EndpointUsers3Add AccessmemberOfEnt3  __GLOBALCOMMENTS__TestUser:Users3 does not have active Account: Users3 in Endpoint:A_Endpoint . 

Does endpointname is correct ? and its not Endpoint display name ?


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

Akilan
New Contributor
New Contributor

Hi @rushikeshvartak ,

Yes, endpoint name is correct not Endpoint display name.

What is account name rule for app ?

Please share logs


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

Akilan
New Contributor
New Contributor

This is AD based child application. There is no separate account name rule configuration in endpoint level. we have configured in AD connection level in Account name rule json. 

CN=${user.username.toLowerCase()},${if(user.customproperty4.equals('A') && user.employeeType.equals('B')){'OU=C_Users,OU=Test Users,DC=test,DC=com'} else {'OU=test Users,DC=test,DC=com'}}

Account name rule in endpoint parent and child is same?


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

Akilan
New Contributor
New Contributor

yes same

Share logs in file


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

Akilan
New Contributor
New Contributor

Hi @rushikeshvartak ,

PFA the Log details.

 

ENTTYPEREQUIRED:[Groups]

  • Validate Entitlement Type name 
  • Validate entitlement name is correct.
  • validate if this is wokring for non ad application  

Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

Akilan
New Contributor
New Contributor

Hi @rushikeshvartak ,

We have tested with Non-AD Application its not working and Entitlement type name  & Entitlement name is correct. 
We are using dynamic attribute this will impact multi users request??

If query are dynamic and it may cause issue. Validate from multi user UI


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.