How to configure to request for entitlement only in the access request page in IIQ?

Which IIQ version are you inquiring about?

Version 8.X

Please share any other relevant files that may be required (for example, logs).

Share all details related to your problem, including any error messages you may have received.

Hi there,

Quick Question: I am looking for a configuration to only allow entitlements to be available in the access request page to request by default. I do not want any roles to be available in the access request page. Is this requirement achievable through any sailpoint configurations or do we have to implement any rules or make change in the form associated to Manage User Access Quicklink and the associated workflow?

Regards,
Rabin

@rabshrestha You can try with below steps.

Go in Global Settings → Quicklink Populations → Everyone → Right Side you will see QuickLinks → You will see “Request Access” → Click Configure on the right side → Unselect Request Roles checkbox.

You will see other option here also.

1 Like

check for entry uiAccessItemsColumnsEntitlement in UI config .
you can remove the one which you don’t need to be visisble.

If you want role to be not visible you can modify this from quicklink setting and unselect request roles .

2 Likes

Currently, for the population Everyone, no box is selected.

image

check for quicklink population were Access request quicklink is enabled.

1 Like

@rabshrestha Also Check if you are not login with sysAdmin. you have to test with normal identity who doesnot have sysadmin.

1 Like

I agree with my predecessors that you can achieve limitation in QuicklinkPopulation - the problem with this is that

  1. Roles are still visible in the search - you just cannot request them
  2. Sysadmins are bypassing this rules so will see and be able to select everything

I have sligtly different idea how you can do but it’s not that simple - you can turn on scoping and make roles which you don’t want to be visible to users assigned to the scope with no users assigned. This is more complex solution but actually it will make roles to dissapear from the search for end users (sysadmins will still see them).

1 Like

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.