We have created an SAP Concur connector-type application in IIQ. However, during group aggregation, we are only receiving a subset of entitlements. For example, although there are 150 entitlements, we are only getting 45. We have not identified any differences between the entitlements that are visible and those that are missing.
Could anyone advise on how we can retrieve all entitlements during group aggregation. Your assistance would be greatly appreciated.
One thing to confirm first is that all of those entitlements actually exist in SAP Concur and that your service account has permissions to see the full set. I have had plenty of moments where I kept digging in SailPoint, but the issue and the fix were on the source side.
I think I also agree, if there are 150 entitlements at target applications, and you are able to pull only 35, then definitely it could be an issue with the permission of your service account. Just check with Sap team, if they have given all the necessary permission required for service account. just double check as well, there is no aggregations rule selected, where you are doing filtering of the accounts.
Hi @vinaygopal221, On top of what @nbhansali and @naveenkumar3 already said (permissions + no filtering rules), there are a couple of Concur-specific things worth checking…
What exactly are those missing numbers of groups “entitlements” on the Concur side? because actually (IIQ 8.4) only aggregates the pre-defined Concur roles, and groups that are associated to those roles via user-role assignments… so if they are not linked to role assignments or association model, they will simply never show up in group aggregation by design…
Are any of the missing ones “custom roles”? If you’re using custom Concur roles, SailPoint only aggregates them if you explicitly list them, please check this out
I hope these things could resolve it for you, or at least enlighten you with some ideas/thoughts
Our service account have all permissions but still not able to fetch all those entitlements to SailPoint IIQ, can anyone suggest how we can fetch all entitlements, and we don’t have any custom roles, aggregation rule selected.