We are raising an access request for the JDBC application. However, after running the Account Aggregation task and Refresh Identity Cube task, the account is not visible in the JDBC application, and the associated attributes are also not getting populated.
Additionally, in the Access Request tab interaction form, after updating the termination date for the identity and running the Process Event task, the leaver event is triggering successfully. However, during the leaver workflow process, an Interaction Form is appearing in the Access Request flow.
The form is neither allowing role selection nor enabling the “OK” button, due to which the leaver process is getting stuck and is not completing successfully.
We would like to remove/disable this Interaction Form so that the leaver workflow can complete successfully without manual intervention.
Hi @ManvithaNalabolu06 ,
Can you check if the form has any fields with review Required, if review required is checked, uncheck the review required in form.
And also check if there any required fields, whose value is not getting populated automatically. If the values are not populated in required fields, then the form may appear for the required field values.
If possible, can you share the screenshot of the form
Hi @ManvithaNalabolu06 , First question: You are submitting the access request, but the JDBC application accounts does not appear in IIQ. This would cause a global provisioning rule check to see whether the query’s insert/update is feeding the data properly. Then, verify if a single account query is configured properly or not. If not, you can configure the getObjectSQL query, it will appear when you are provisioning. for imediate apprear add the Provsioning Policy.
Second question: This will occur only when a user has two accounts in the same application. To prevent this, either you can write a Provisioning Target Account Selector Rule, or, if you want to generate a ticket or ignore select account in request, you can update the “Do Provisioning Forms” workflow.
Is your Provisioning is successful and you are able to see the changes in the Target system ? if no you need to fix the Provisioning rule to fix the issues.
Once running aggregation are you able to see the account update status in the TaskResult if no then then check the Acccount scan data and match it against your Downstream system.
Verify the co-relation rule for the correct account update
@ManvithaNalabolu06 , can you check if the account is present in the target JDBC application.
If ‘detect deleted accounts’ option is enabled in account aggregation, then if the account is not present in target application then IdentityIQ also deletes the link object in the IdentityIQ environment
Based on the reported behavior, there appear to be two separate issues:
1. JDBC Account Not Visible After Aggregation
Please verify the following:
Confirm that the JDBC account exists in the target database and that the aggregation query returns the account record.
Review the Account Aggregation task results and logs for any errors or skipped records.
Validate the Application Schema mapping and ensure that all required account attributes are correctly mapped.
Verify that the account correlation logic is configured correctly and that the account is being correlated to the expected identity.
Check whether the account is present as an uncorrelated account in the application.
After aggregation, run Identity Refresh with the options to refresh identity attributes, promote managed attributes, and correlate entitlements as applicable.
If the account is still not visible, please provide:
JDBC application configuration details
Aggregation task results
Correlation configuration
Relevant log entries from ccg.log/catalina.out
2. Interaction Form Appearing During Leaver Workflow
The behavior indicates that an approval step or provisioning policy form is being invoked during the leaver process.
Please review the following:
Check the Leaver Lifecycle Event configuration and identify the workflow being triggered.
Review the workflow XML and look for Approval, Form, or Interactive Work Item steps.
Verify whether any provisioning policy attached to the requested roles/applications contains mandatory form fields.
Check if an Access Request workflow is being called from the leaver workflow instead of directly executing deprovisioning actions.
Review any custom rules (Before Provisioning, After Provisioning, Workflow Rules, Lifecycle Event Rules) that may be generating an interaction form.
To allow the leaver process to complete automatically:
Remove the approval or interaction form step from the leaver workflow.
Configure the lifecycle event to use an automated deprovisioning workflow.
Ensure all required workflow variables are populated programmatically so that no user input is required.
If the form originates from a provisioning policy, mark the fields as non-interactive or provide default values through workflow variables/rules.
The disabled “OK” button typically indicates that one or more required form fields are not being populated, preventing form submission. Identifying the source of the form within the workflow or provisioning policy should resolve the issue.
Please share the workflow definition and lifecycle event configuration if further analysis is required.