Certification Campaign on IdentityNow Source

We have done a certification campaign on the IdentityNow source, which includes the permission of ORG_Admin, Report_Admin, etc.

When the entitlement is revoked as part of a campaign, the respective role is removed from the source level. (IdentityNow source). But still, at the identity level, that identity holds permission/role. Does anyone notice this behavior?

Hi @Manju22 ,

Yes, I noticed the same behavior until I refresh the identity once again or perform a single source aggregation for the account. It seems to be the behavior here.

Regards,
Uday

No. I have refreshed the identity manually. But still, at the identity level, that identity holds permission/role.

Hi Manju,
How have you setup your source. Could you please elaborate ? I have configured the source and it works fine. The only issue is related to single account aggregation which needs to be done to reflect the removal of role from IdentityNow source

Thanks
Rakesh Bhati

Hi @Manju22 ,
Is it a requestable role or a birthright role,If its a requitable role then it will be removed but if its a birthright then it will again get provisioned.

Thanks,
Naveen