Domain account deprovisioning on Windows source

Hi,

I think currently Sailpoint Identitynow is not supporting the deprovisioning on domain account on windows local connector. So we are trying to find an alternate option to handle this. Is there an option like before / after provisioning which calls the powershell script to remove the domain accounts from the windows local group.

Hi Chandra!

We have previously had success with the Windows Connector managing the access that local accounts have. Adding and Removing access is noted in the Windows Local connector features. Have you tried revoking an entitlement from an account and received an error? Please share the error message from the failed event.

Thank you,

  • Zach

Hi @zachm117

I’m able to remove access for Local accounts, but can’t do for Domain accounts. We are trying to remove local admin group membership for domain accounts.

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.