Saviynt unveils its cutting-edge Intelligence Suite products to revolutionize Identity Security!
Click HERE to see how Saviynt Intelligence is transforming the industry.
Saviynt Copilot Icon

Update Entitlement CustomProperty as part of Group creation via AD group management module.

gtaunk
New Contributor
New Contributor

We are using AD group management module to create and manage groups in AD.

We also have few other groups as well which the user gets assigned to via rules and these groups are not managed by AD group management module so in order to allow users access to request only groups that we are managing via AD group management module we are planning to use custom property1 as a flag and based on that we can filter groups that we allow via ARS.

Issue: The issue here is when we put some value in custom property1 we can see that same value being updated in Saviynt role but that value is not coming up in the AD entitlement's custom property1 in Saviynt. We want to keep this value only in Saviynt to use as a flag. Is there any way we can update the entitlement's custom property as well (only in Saviynt) while creating a group via AD group management?

4 REPLIES 4

rushikeshvartak
All-Star
All-Star

Use Enhanced Query to update roles cutomproperty from role type as entitlement = 6 and endpoint as AD to entitlement values table


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

Using enhanced query worked.

Thank you for the help!

dgandhi
All-Star
All-Star

Provision that value in one of the field of Active Directory while creating group from Saviynt.(any extension attribute)

And when you perform group recon of AD , map that extension attribute to the custom property of the entitlement and then you can leverage that entitlement custom property to filter the group during ARS request.

 

Thanks,
Devang Gandhi
If this reply answered your question, please Accept As Solution and give Kudos to help others who may have a similar problem.

gtaunk
New Contributor
New Contributor

We wanted to handle this via Saviynt itself and not make use of any extension attribute from AD.