# How to auto-select a particular/main account for provisioning while requesting access to a multi-forest Active Directory source in Request Center?

**URL:** <https://developer.sailpoint.com/discuss/t/how-to-auto-select-a-particular-main-account-for-provisioning-while-requesting-access-to-a-multi-forest-active-directory-source-in-request-center/71403>\
**Category:** SHF Discussion and Questions\
**Tags:** provisioning, virtual-appliance, identity-security-cloud\
**Created:** [July 8, 2024, 4:10pm UTC](https://developer.sailpoint.com/discuss/t/how-to-auto-select-a-particular-main-account-for-provisioning-while-requesting-access-to-a-multi-forest-active-directory-source-in-request-center/71403 "2024-07-08T16:10:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![TheOneAMSheriff](https://avatars.discourse-cdn.com/v4/letter/t/ee59a6/32.png) [@TheOneAMSheriff](https://developer.sailpoint.com/discuss/u/TheOneAMSheriff)\
**Post date:** [July 8, 2024, 4:10pm UTC](https://developer.sailpoint.com/discuss/t/how-to-auto-select-a-particular-main-account-for-provisioning-while-requesting-access-to-a-multi-forest-active-directory-source-in-request-center/71403/1 "2024-07-08T16:10:02Z")

</div>

Lets say a multi-forest Active Directory connector has 2 forests for accounts and 1 forest for groups. When requesting entitlements(Not Access Profiles or Roles) from “Request Center” to the subjected source how can I tell ISC/SailPoint to provision to the main account, which could be in either of the 2 forests with accounts depending on an identity attribute?

---

<div class="post-metadata">

**Author:** ![zachm117](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/zachm117/32/3883_2.png) [@zachm117](https://developer.sailpoint.com/discuss/u/zachm117)\
**Post date:** [July 8, 2024, 4:35pm UTC](https://developer.sailpoint.com/discuss/t/how-to-auto-select-a-particular-main-account-for-provisioning-while-requesting-access-to-a-multi-forest-active-directory-source-in-request-center/71403/2 "2024-07-08T16:35:05Z")

</div>

Hey Amar!

I don’t believe there is an easy way to do this currently. Entitlement requests have gotten a lot of changes recently, but unfortunately the do not currently have the multiple account options like Access Profiles.

IDN in general isn’t great at handling identities that have multiple accounts in one source.

The two options I can think of to help with this would be to either switch to using Access Profiles for access requests, or create a second AD source to filter on each account.

Switching to Access Profiles for these types of requests will let you use the [Multiple Account Options](https://documentation.sailpoint.com/saas/help/access/access-profiles.html#:~:text=Requests%20for%20details.-,Multiple%20Account%20Options,-When%20an%20identity) to help determine which account to provision the access to.

Creating a second source would essentially split the accounts that the users have into 2 seperate sources. For example, if users have a domainA and a domainB account, one connector will just look for the domainA accounts and the other would look for the domainB accounts so users only have one account on each source. This would duplicate the entitlements in the entitlement catalog, but it would allow you to just make the domainA groups provisioned to the domainA accounts. It is fairly common to have multiple sources to support users having multiple accounts, we have 3 ourselves, in order to only have one account from a source linked to an identity, but it can get a bit messy.

Here are some other topics regarding having multiple AD sources that may be helpful.

> [@2 Active Directory Source connectors?](https://developer.sailpoint.com/discuss/t/2-active-directory-source-connectors/10112):
>
> Hello All - I have a use case where our admins have 2 AD accounts, one named and one for admin access. Admin AD account creation will be manual, however we want both accounts to be disabled upon termination and we do not want attributes synced to the admin accounts. It’s my understanding that attribute sync will apply to all correlated AD accounts. My idea is to setup a secondary Active Directory source, which will include the OU for the admin accounts, and exclude the OU on the primary Active…

> [@Request Center : request role for user that have more than 2 accounts](https://developer.sailpoint.com/discuss/t/request-center-request-role-for-user-that-have-more-than-2-accounts/23697):
>
> My identity have more than one account in one my source. And i have another role that use an access profile base in this source. In Request center if i ask the role, it’s failed with error : "Your request failed beacause you have more than one account on the source mySOurceName. Any idea ?

Please let me know if this helps!

- Zach

---

<div class="post-metadata">

**Author:** ![TheOneAMSheriff](https://avatars.discourse-cdn.com/v4/letter/t/ee59a6/32.png) [@TheOneAMSheriff](https://developer.sailpoint.com/discuss/u/TheOneAMSheriff)\
**Post date:** [July 8, 2024, 5:12pm UTC](https://developer.sailpoint.com/discuss/t/how-to-auto-select-a-particular-main-account-for-provisioning-while-requesting-access-to-a-multi-forest-active-directory-source-in-request-center/71403/3 "2024-07-08T17:12:15Z")

</div>

Hi Zach,

Appreciate your detailed insight. What you described is the exact issue, duplicating of entitlements when using two different sources. Since account selector in access profiles only work in case of automated provisioning, not “Request Center” I had to drop that.

The attempt to use segments to split the users visibility in Request Center hit a limitation as segments in ISC only filter access items for requester, but not for recipients like the Quicklink populations in IIQ. Perhaps going with the limitation of segment is my best bet. Thank you

---

<div class="post-metadata">

**Author:** ![TheOneAMSheriff](https://avatars.discourse-cdn.com/v4/letter/t/ee59a6/32.png) [@TheOneAMSheriff](https://developer.sailpoint.com/discuss/u/TheOneAMSheriff)\
**Post date:** [July 10, 2024, 3:04pm UTC](https://developer.sailpoint.com/discuss/t/how-to-auto-select-a-particular-main-account-for-provisioning-while-requesting-access-to-a-multi-forest-active-directory-source-in-request-center/71403/4 "2024-07-10T15:04:34Z")

</div>

The solution finalized was to have two different sources with entitlements duplicated as @zachm117 mentioned about. Event Triggers can be used to auto deny/approve an approval request in case the account was selected incorrectly due to the duplication in entitlements. Segments was used to limit the visibility of entitlements but segments only apply to requesters, not recipients: [Access Segmentation for Beneficiary | SailPoint Ideas Portal](https://ideas.sailpoint.com/ideas/GOV-I-1957)

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [September 8, 2024, 3:05pm UTC](https://developer.sailpoint.com/discuss/t/how-to-auto-select-a-particular-main-account-for-provisioning-while-requesting-access-to-a-multi-forest-active-directory-source-in-request-center/71403/5 "2024-09-08T15:05:06Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
