Group Aggregation clearing out entitlements after running

Currently we have Radiant Logic connected to IIQ using the LDAP connector. We have both an Application account and group aggregations setup. Both the Account and Group aggregations worked when when setup the app. Now only the account aggregation is working. We run the account aggregation and it pulls in users and entitlements. When we run the group aggregation it is clearing out all the entitlements the account aggregation pulled in.
We do need to have both aggregations work as we will have some entitlements that will not be associate to a user that we need to make sure get pulled in using the group aggregation.

Looking to see if anyone has ran into this before. We have had a ticket open with sailpoint now for a couple of weeks and no one has been able to point us to what might be causing this.

Hi @langn,

Just a couple questions to get clarity on your issue.
Are you promoting the entitlements to managed attribute during account aggregation?
Is the group aggregation providing you with all the entitlements in the application, including the one which was pulled in via account aggregation.?

Are you promoting the entitlements to managed attribute during account aggregation? Yes, we are
Is the group aggregation providing you with all the entitlements in the application, including the one which was pulled in via account aggregation.? It is

Have you defined the entitlements as type of Group, like:

In the Group Aggregation task, do you have Detect deleted account groups enabled ?

Is the SearchDN configured correctly? Do you have configured a Iterate Search Filter?

From the Schema, did you test using the ‘Preview’ button below the group schema?

Does the command connectorDebug in the IIQ Console provide any results?

– Remold

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.