When I remove any entitlement for a webservice connector. It doesn’t reflects immediately on the user profile. We had configured getObject API.
Do we have aggregate the account every time to see the updated access in IDN. Doesn’t the get Object operation triggers automatically & does this job ?
If you remove an entitlement outside of IDN, natively that is, you need to aggregate that account for the source that is connected to it for the changes to be visible in IdentityNow.
If you remove an entitlement from IDN via for example a certification, it should show immediatly after the API request has been successful.
How does the entitlement structure look like and what operations are you using right now? Are you removing the actual entitlement itself or the entitlement from a user account conneted to the Webservice source?
Hi Tanay,
I am not understanding the issue. Are you revoking an entitlement directly or revoking access profile or role ? Is it getting removed in target?
Can you share step-by-step what it is you are doing inside IdentityNow?
Can you also share a screenshot of the operations in the Web Service Configuration, as well as a screenshot of the Remove Entitlement Operation configuration?
There are two access profiles AP1 & AP2. Both were assigned using Access Request.
I am removing AP2 via Certification. It does gets removed from Target but the changes doesn’t reflects in IDN until I aggregate the account.