Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

Thycotic connection correlating accounts during import without correlation rule in place.

Alex_Terry
Regular Contributor
Regular Contributor

Hello, hope you can help.

We have set up a connection with our Delinea instance. When we import accounts we are seeing that some accounts from Delinea are correlating to our users however we don't have an account correlation rule in place.  

I've investigated the global configuration and the settings and it appears that there's nothing that would indicate this behaviour should occur. Similarly there is nothing in the documentation that would indicate this should occur without an account correlation rule in place.

Please could you advise?

9 REPLIES 9

Saathvik
All-Star
All-Star

@Alex_Terry : Would you be able to share the logs during the import timeframe also ImportAccountEntJSON?


Regards,
Saathvik
If this reply answered your question, please Accept As Solution and give Kudos to help others facing similar issue.

rushikeshvartak
All-Star
All-Star

Share correlation config 


Regards,
Rushikesh Vartak
If you find this response useful, kindly consider selecting 'Accept As Solution' and clicking on the 'Kudos' button.

AliW
New Contributor
New Contributor

Hi @rushikeshvartak@Saathvik. Subbing in for Alex whilst he is away.

I've attached the ImportAccountEntJSON and the logs near the end of job import (if there's more needed or if there's something specific you're looking for, please let us know).

There is no User Account Correlation rule set on the endpoint. We are seeing the mapping occur automatically in the import and we can also see this in the logs: [quartzScheduler_Worker-3] DEBUG rest.RestProvisioningService - Mapping Users to accounts."

Best regards

@AliW : Looks like in latest version it is by default it is correlating the accounts by matching with username when there is no correlation rule on respective endpoint. We also noticed the similar behaviour in latest version. For me it looks like a bug because nowhere in documentation it is mentioned that by default it correlates the accounts based on username. I would suggest to open a ticket with Saviynt Support to confirm if this is the expected behaviour or a bug


Regards,
Saathvik
If this reply answered your question, please Accept As Solution and give Kudos to help others facing similar issue.

sudeshjaiswal
Saviynt Employee
Saviynt Employee

Hello @Saathvik @Alex_Terry @AliW,

This is how the system design and it is expected behavior.
By default it will correlating the accounts by matching with username when there is no correlation rule on respective endpoint.

Thanks.

If you find the above response useful, Kindly Mark it as "Accept As Solution".

Alex_Terry
Regular Contributor
Regular Contributor

Hey @sudeshjaiswal, thanks for the reply. Just one quick follow up:

Can this behaviour be disabled in Saviynt?

sudeshjaiswal
Saviynt Employee
Saviynt Employee

Hello @Alex_Terry,

No, You wont be able to disable as thats the default behaviour.
If you do not to use the default co-relation rule, you can define your co-relation rule in the endpoint.

Thanks.


If you find the above response useful, Kindly Mark it as "Accept As Solution".

@sudeshjaiswal : Is this new behaviour in latest version? Because we haven't seen this behaviour in older version


Regards,
Saathvik
If this reply answered your question, please Accept As Solution and give Kudos to help others facing similar issue.

Alex_Terry
Regular Contributor
Regular Contributor

Awesome, cheers for clearing that up. Thanks for all the help.