Saviynt unveils its cutting-edge Intelligence Suite products to revolutionize Identity Security!
Click HERE to see how Saviynt Intelligence is transforming the industry.
Saviynt Copilot Icon

Some Entra DirectoryRole Entitlements Not Displaying

Ches
New Contributor III
New Contributor III

Hi,

I am looking to pull a complete list of all 'DirectoryRole' entitlements relating to EntraID(AzureAD).

Currently, Microsoft has just over 100 of these built in directory roles, found here: https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference#all...

However, in my Saviynt instance, I am only able to see 30~ or so.  Where are the other 60+ entitlements?

I had thought that perhaps if someone is not assigned the role in EntraID, then the entitlement would not import, however, there are some entitlements showing as no accounts within.

Ches_0-1720437213049.png

Thanks,

 

13 REPLIES 13

Raghu
All-Star
All-Star

@Ches  check any Entitlement and child entitlement 

Endpoint->Entilement->open active one -> check again child ent tab -->few ent's

Refrenc :

Raghu_0-1720438048855.png

 

 


Thanks,
Raghu
If this reply answered your question, Please Accept As Solution and hit Kudos.

Ches
New Contributor III
New Contributor III

Thanks for your reply, but this does not answer my question?

If I use the Global Reader DirectoryRole entitlement and look at the child entitlements, for example.. what does that have to do with what I'm looking for?

Ches_0-1720438426775.png

I am looking to understand why there are over 100 Microsoft built in DirectoryRoles, yet my Saviynt instances only display approx 30~.

  • Did you added any filters on connection level or Job control panel
  • Please validate Entitlement Filter query on connection level.

Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

Ches
New Contributor III
New Contributor III

Hi,

Any import jobs are complete imports and I see nothing to exclude any DirectoryRole etc.

The ENTITLEMENT_ATTRIBUTE on the connection looks standard. And the ENTITLEMENT_FILTER_JSON is blank (as expected).

  • You mean specific DirectoryRoles can't be excluded ?

Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

Ches
New Contributor III
New Contributor III

I meant that I see nothing to indicate my instance is excluding any Directory Role entitlements.

Lovelace
New Contributor
New Contributor

We're also experiencing this issue and trying to figure it out ourselves.

Please validate in 24.x latest version


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

My bad. We are v24.5

Ches
New Contributor III
New Contributor III

Hi @slovelace

After doing some further tests, I have came to the conclusion that the DirectoryRoles will NOT populate in Saviynt, unless the role gets assigned to someone/PIM in EntraID. Only then will it populate.

It would be great if you're able to test this on your side, to confirm the behaviour.

Lovelace
New Contributor
New Contributor

That is what we were suspecting. We also noticed that if the role is "eligible" but not active, it does not populate on the user. Perhaps this is also why some of them show up but are blank? This just failed QA tests yesterday so purely speculation on our part at the moment.

Will keep poking around and trying new things.

Ches
New Contributor III
New Contributor III

"We also noticed that if the role is "eligible" but not active, it does not populate on the user."

 

This behaviour was also noted. Unless it's active at the point of the EntraID sync, it'll show as not assigned to anyone.

Lovelace
New Contributor
New Contributor

Seems a bit odd. Means it's just a matter of luck if we know appropriate PIM roles then, and they can disappear just as fast on the next sync. Hmmmmmm.