Hi,
My understanding is that updates made to access profiles that are tied to roles do flow downstream to the target systems if the change is a net new addition of an entitlement. Please correct me if I’m wrong.
We’re seeing a client observe a behavior in production where upon updating an existing access profile to add a new entitlement, there was temporary revocation of existing access followed by re-provisioning of the existing access with the added entitlement. This access profile is tied to a role.
There was no change to the role membership criteria made, and there were no removal of entitlements from the access profile either. Also I believe removing entitlements from an access profile does not affect existing users with the entitlements assigned via the access profile (i.e. they do not get their entitlement revoked.) but please let me know if that’s incorrect.
Is there ever a scenario where changing an access profile tied to a role causes deprovisioning followed by re-provisioning of access?