Click HERE to see how Saviynt Intelligence is transforming the industry. |
08/27/2024 06:32 AM
We want to import account and entitlements from Workday. We are using OOTB Workday RAAS connector.
We have configured all the reports in workday as per document by Saviynt.
When we run account import job, we can reconcile account.
After running access import job, entitlement value is populated as combination of two fields from Workday: Security Group Name + (Tenant_Security_Group_ID)
And due to this, we are not able to import access import mapping because the entitlement name in saviynt doesnot match with the security group (entitlement in workday) from mapping report.
Sample entry from Workday security group report:
<wd:Security_Group wd:Descriptor="Report Writer">
<wd:ID wd:type="WID">ac85a54dce1e10e2bb07a532c85568d0</wd:ID>
<wd:ID wd:type="Tenant_Security_Group_ID">Report_Writer</wd:ID>
</wd:Security_Group>
Entitlement name in Saviynt: Report Writer (Report_Writer)
Sample entry from Account entitlement mapping report:
<wd:Workday_Account wd:Descriptor="kaustubh@xxxxx.com / Kaustubh">
<wd:ID wd:type="WID">ac85a54dce1e10e375511097852da8a7</wd:ID>
<wd:ID wd:type="System_User_ID">kaustubh@xxxxx.com</wd:ID>
<wd:ID wd:type="WorkdayUserName">kaustubh@xxxxx.com</wd:ID>
</wd:Workday_Account>
<wd:Security_Groups>
<wd:Reference_ID>Report_Writer</wd:Reference_ID>
</wd:Security_Groups>
According to Saviynt agent response on a ticket, entitlement value which is populated is expected behavior and it is configured in the connector. Hence cannot be changed.
Please suggest a way to import account entitlement mapping.
08/27/2024 06:44 AM
Please share connector configuration
08/27/2024 06:55 PM - last edited on 08/27/2024 11:40 PM by Sunil
Mapped fields below and attached json:
BASE_URL: https://xxxxxx.workday.com
API_VERSION: v42.1
TENANT_NAME: flyscoot
REPORT_OWNER: abc@xyz.com
USE_OAUTH: false
username: xxxx
password: xxxx
USER_IMPORT_MAPPING: {"ImportType":"RAAS"}
ACCESS_IMPORT_LIST: Security Group
[This message has been edited by moderator to disable url hyperlink]
08/27/2024 07:14 PM
08/27/2024 07:31 PM
I tried mapping display name to Descriptor field of workday like
"DISPLAYNAME": "wd:Security_Group.wd:Descriptor~#~char"
The display name is also displayed combination of
Security Group Name + (Tenant_Security_Group_ID)
08/27/2024 07:33 PM
Here
Please confirm understanding
08/27/2024 07:36 PM
Yes, your understanding is correct.
Agent response below:
08/27/2024 07:39 PM
In this case your mapping report should give entitlement as Security Group Name + (Tenant_Security_Group_ID)
08/28/2024 03:12 AM
Changed the mapping report. Sample below:
{
"Reference_ID": "selfTerminee_wkdyGroup",
"Group_Name": "Terminee As Self",
"Security_Group": "Terminee As Self (selfTerminee_wkdyGroup)"
}
],
"Workday_Account": "abc@xyz.com / AB BC"
Still facing issue.
Here, again, Workday_Account field is also combination of username and display name from workday.
Do we need to change this value in the report as well? In account report we are getting abc@xyz.com
08/28/2024 06:06 AM
Yes change in report