Is there way to turn of auto cancellation of access request in ISC

Hi Sailors,

Is there a way to turn of auto cancellation of access request for same identity same requestable entitlement but change in account name on 2nd req

The change in account name is happening via interactive forms of ISC

Thanks in advance
Avinash Mulpuru.

Hi @amulpuru ,

I don’t think there is direct way you can cancel this, system automatically validate existing access after we submit request, I assume its Active Directory User Accounts and Admin Accounts, if that is the case use different source and get get admin user with ldap search filter with this set up you can request same access to user accounts and admin accounts in same target system with different source names.

Thanks,

Mahesh

Hi @uppala ,thanks for the reply yes these AD Service account requests happening via interactive forms in ISC which is equivalent of IIQ SA req quick Link

With two different sources i was able to submit 2nd access request but what if a source required dev,qa,test,uat,product account of same non Huma identity with different names probably SA_dev,SA_QA… Etc that will break right

Im looking for something where I can build plan with same entitlement but diff SA name that should not stop access request auto cancellation process in ISC

@amulpuru - in that case

1.create environment specific Access Profiles and assign them to different accounts. or

2. multiple account correlation via custom attribute here ensure provision logic uses environments, i personally prefer first approach.

Thanks,

Mahesh

I what to create multiple accounts to same identity via ISC with change in Account name that happening via interactive forms as I mentioned I created multiple access profile as you suggested this time with diff acc name aceess request is getting submitted Access profile but access profile is end up being detected no new account getting created @uppala

But this not the case in IIQ ,in IIQ I was able to submit multiple access request with change in name and they are getting created (multiple AD accounts with same AD group and Same ou) and same entitlement is being visible multiple times tied to different accounts of single identity cube

I just looking for replication of this use case in ISC

I think ISC is still considering different accounts on same source as single account, here is other community discussions Provisioning multiple accounts on same source through ISC - Identity Security Cloud (ISC) / ISC Discussion and Questions - SailPoint Developer Community

Provisioning fails for users with multiple accounts from a same source - Identity Security Cloud (ISC) / ISC Discussion and Questions - SailPoint Developer Community