Good morning/afternoon,
I am currently trying to integrate part of my workflow to check with managers on the current status of their vendors (whether they are current, have been discontinued, new vendors to add, etc.). Currently we are having to email the managers of our departments and are working manually out of a spreadsheet. However, we have the vendors in AD and Azure AD, and we have AD and Azure AD synced with SailPoint. Our goal is to move this process into SailPoint so that managers can simply respond via SailPoint to revoke or retain access for vendors.
While great in theory, we are having some issues. If I query for a/some normal user(s) (such as myself) and select an entitlement that applies to the identities queried, their manager is appropriately listed as a reviewer for the campaign, but if I query for and select an entitlement to which our Vendors get, the campaign reviewer is set to me or one of my colleagues, depending on which one of us is generating the campaign.
To walk you through what it is that we are trying is as follows:
Selecting Certification Campaigns in the Search Tab
Querying with the following: @accounts(source.name:āVendor Accountsā AND disabled:false)
Selecting Certify These Identities
Selecting Refine Access Items
Selecting an entitlement that is applied to all of our vendorsā accounts and adding it to the campaign
Naming the campaign and giving it a description and turning on Email Notifications
Manager is selected as the Reviewer
Leaving Maintain access to undecided items on
Requiring Comments for decisions marked as revoked
Generating the campaign now and having a due date for 2 weeks after the campaign starts
When viewing the campaign, rather than the manager, who is appropriately set in both AD and Azure AD, the reviewer is the person generating the campaign. If you have any insight or recommendations for me to look at, please feel free to share.
Thanks!

