Hi all,
We are seeing unexpected behaviour during user access review certifications.
Our design is:
-
A role provides birthright access.
-
That role assigns an Entra security group.
-
The security group grants access to an application.
During a user access review, SailPoint correctly identifies the security group as birthright and does not require it to be reviewed.
However, SailPoint still requires the reviewer to make an approve or revoke decision on the application assignment itself.
It appears that SailPoint understands the group is birthright but does not understand that the application access is downstream of that group and fully dictated by the role.
From a reviewer’s point of view, this is confusing. The app access cannot be meaningfully revoked without breaking the role-based birthright model.
Is this expected behaviour?
If not, is there a way to configure certifications so that application access inherited solely via a birthright role and security group is also excluded from review?
Cheers,
Sean

