Saviynt unveils its cutting-edge Intelligence Suite products to revolutionize Identity Security!
Click HERE to see how Saviynt Intelligence is transforming the industry.
Saviynt Copilot Icon

SOD evaluation issue

shivmano
Regular Contributor III
Regular Contributor III

Hi Team - 

For preventative SOD check, we have below 2 rulesets 

1) ZALL - Evaluate SODs in Access Request as 'Yes'

2) BIOBRK-Finance-SOD-SetOne - Evaluate SODs in Access Request as 'Yes'

ZALL is for SAP with type SAP and BIOBRK-Finance-SOD-SetOne is for a different endpoint with type Non-SAP. 

The issue is while requesting access to SAP for a user, we are seeing the SOD violations flagged from under BIOBRK-Finance-SOD-SetOne which is not having any functions or entitlements part of SAP. Why does this happen? Can we avoid this from happening? 

 

Thank you 

6 REPLIES 6

NM
Honored Contributor II
Honored Contributor II

Hi @shivmano in the function of BIObsk did you any conflicting entitlement?

Can you share ruleset and function details

rushikeshvartak
All-Star
All-Star
  • Can you provide screenshot of issue along with ruleset

Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

shivmano
Regular Contributor III
Regular Contributor III

@NM @rushikeshvartak  - Here is the screenshot the BIOBRK-Finance-SOD-SetOne  violation showing on the request page for SAP endpoint. Also none of the entitlements in the BIOBRK-Finance-SOD-SetOne  functions are from SAP endpoint. 

shivmano_0-1725007537101.png

Ruleset (BIOBRK-Finance-SOD-SetOne)

shivmano_1-1725007614439.pngshivmano_2-1725007627052.pngshivmano_3-1725007659697.pngshivmano_4-1725007672956.png

shivmano_10-1725007966155.png

 

Ruleset (SAP) - ZALL

shivmano_5-1725007727903.pngshivmano_6-1725007751882.pngshivmano_7-1725007775382.pngshivmano_8-1725007794169.pngshivmano_9-1725007876154.png

 

[This message has been edited by moderator to disable url hyperlink]

NM
Honored Contributor II
Honored Contributor II

@shivmano what is the function type for (BIOBRK-Finance-SOD-SetOne) function

shivmano
Regular Contributor III
Regular Contributor III

@NM it is Non-SAP

This is expected behavior; please refer https://forums.saviynt.com/t5/identity-governance/sod-owner-approval-generated-in-case-of-no-violati...

 existing SOD will be visible 

below is configuration to disable [Global config - SOD ]

rushikeshvartak_0-1725030502390.png

 

 


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.