Click HERE to see how Saviynt Intelligence is transforming the industry. |
07/04/2024 10:10 AM
We are using AD group management module to create and manage groups in AD.
We also have few other groups as well which the user gets assigned to via rules and these groups are not managed by AD group management module so in order to allow users access to request only groups that we are managing via AD group management module we are planning to use custom property1 as a flag and based on that we can filter groups that we allow via ARS.
Issue: The issue here is when we put some value in custom property1 we can see that same value being updated in Saviynt role but that value is not coming up in the AD entitlement's custom property1 in Saviynt. We want to keep this value only in Saviynt to use as a flag. Is there any way we can update the entitlement's custom property as well (only in Saviynt) while creating a group via AD group management?
Solved! Go to Solution.
07/04/2024 04:31 PM
Use Enhanced Query to update roles cutomproperty from role type as entitlement = 6 and endpoint as AD to entitlement values table
07/09/2024 12:25 PM
Using enhanced query worked.
Thank you for the help!
07/05/2024 09:21 AM - edited 07/05/2024 09:22 AM
Provision that value in one of the field of Active Directory while creating group from Saviynt.(any extension attribute)
And when you perform group recon of AD , map that extension attribute to the custom property of the entitlement and then you can leverage that entitlement custom property to filter the group during ARS request.
Thanks,
Devang Gandhi
If this reply answered your question, please Accept As Solution and give Kudos to help others who may have a similar problem.
07/09/2024 12:25 PM
We wanted to handle this via Saviynt itself and not make use of any extension attribute from AD.