# Detect/Prevent Second Account Creation in IdentityNow

**URL:** <https://developer.sailpoint.com/discuss/t/detect-prevent-second-account-creation-in-identitynow/10690>\
**Category:** SHF Discussion and Questions\
**Tags:** provisioning, identity-security-cloud\
**Created:** [May 1, 2023, 6:35pm UTC](https://developer.sailpoint.com/discuss/t/detect-prevent-second-account-creation-in-identitynow/10690 "2023-05-01T18:35:30Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![ajmerasunny1](https://avatars.discourse-cdn.com/v4/letter/a/3be4f8/32.png) [@ajmerasunny1](https://developer.sailpoint.com/discuss/u/ajmerasunny1)\
**Post date:** [May 1, 2023, 8:32pm UTC](https://developer.sailpoint.com/discuss/t/detect-prevent-second-account-creation-in-identitynow/10690/2 "2023-05-01T20:32:28Z")

</div>

For detecting users with 2+ accounts, you can use below query:

```
"query": {
    "query": "source.id:<<SOURCEID>>"
},
"indices": [
    "identities"
],
"aggregationsDsl": {
    "accounts": {
        "nested": {
            "path": "accounts"
        },
        "aggs": {
            "source_id": {
                "terms": {
                    "field": "accounts.source.id",
                    "min_doc_count": 2,
                    "size": 1000
                },
                "aggs": {
                    "identities": {
                        "terms": {
                            "field": "_id",
                            "min_doc_count": 2
                        },
                        "aggs": {
                            "accounts": {
                                "top_hits": {}
                            }
                        }
                    }
                }
            }
        }
    }
}

```

}

You can refer this too

> [@Get Users With More Than One Account in the Same Source](https://developer.sailpoint.com/discuss/t/get-users-with-more-than-one-account-in-the-same-source/338/7):
>
> UPDATE: The previous query may no longer work as the data model of identity search results has changed. It appears the \_uid field is no longer available, having been replaced by \_id. If you are experiencing issues using the above query, then try this query instead: { "query": { "query": "\*" }, "indices": ["identities"], "aggregationsDsl": { "accounts": { "nested": { "path": "accounts" }, "aggs":…

---

_[View the full topic](https://developer.sailpoint.com/discuss/t/detect-prevent-second-account-creation-in-identitynow/10690)._
