# JDBCConnector delete/cleanup orphan entitlements (role- and identity-assignments)

**URL:** <https://developer.sailpoint.com/discuss/t/jdbcconnector-delete-cleanup-orphan-entitlements-role-and-identity-assignments/30230>\
**Category:** IIQ Discussion and Questions\
**Tags:** identityiq, jdbc-connector\
**Created:** [February 13, 2024, 1:50pm UTC](https://developer.sailpoint.com/discuss/t/jdbcconnector-delete-cleanup-orphan-entitlements-role-and-identity-assignments/30230 "2024-02-13T13:50:07Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![chriskk](https://avatars.discourse-cdn.com/v4/letter/c/eb8c5e/32.png) [@chriskk](https://developer.sailpoint.com/discuss/u/chriskk)\
**Post date:** [February 13, 2024, 1:50pm UTC](https://developer.sailpoint.com/discuss/t/jdbcconnector-delete-cleanup-orphan-entitlements-role-and-identity-assignments/30230/1 "2024-02-13T13:50:07Z")

</div>

### IIQ version: 8.3

I hope i have a simple question 😃

Currently I do some testings on whats happen, if an entitlement is no longer available.

The jdbc connector builds with a GroupAggregation-Task the entitlement catalog - okay.  
And if the group is no longer available, the entitlements gets deleted by IIQ from catalog.  
(Option ‘Detect deleted account groups’ must acticated in GroupAggregation-Task.)

But the orphan entilements are still included in IIQ roles and assigned to the identities.

How does IIQ sync there role/entitlement- and identity/entitlement-assignments?

thx

---

<div class="post-metadata">

**Author:** ![chriskk](https://avatars.discourse-cdn.com/v4/letter/c/eb8c5e/32.png) [@chriskk](https://developer.sailpoint.com/discuss/u/chriskk)\
**Post date:** [February 15, 2024, 6:35am UTC](https://developer.sailpoint.com/discuss/t/jdbcconnector-delete-cleanup-orphan-entitlements-role-and-identity-assignments/30230/2 "2024-02-15T06:35:57Z")

</div>

Any tips would be welcome.

---

<div class="post-metadata">

**Author:** ![pmandal](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/pmandal/32/7049_2.png) [@pmandal](https://developer.sailpoint.com/discuss/u/pmandal)\
**Post date:** [February 15, 2024, 8:53am UTC](https://developer.sailpoint.com/discuss/t/jdbcconnector-delete-cleanup-orphan-entitlements-role-and-identity-assignments/30230/3 "2024-02-15T08:53:42Z")

</div>

Hi [chris kk](https://developer.sailpoint.com/discuss/u/chriskk),

Here is the hyperlink to the SailPoint IdentityIQ documentation to manage uncorrelated accounts:  
[Manage Uncorrelated Accounts - SailPoint IdentityIQ Documentation](https://community.sailpoint.com/t5/IdentityIQ-Wiki/Managing-uncorrelated-accounts/ta-p/71826)  
Please refer to this document for comprehensive guidance on effectively managing uncorrelated accounts within the SailPoint IdentityIQ platform.

Regards  
Priyam

---

<div class="post-metadata">

**Author:** ![Jarin\_James](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jarin_james/32/3372_2.png) [@Jarin\_James](https://developer.sailpoint.com/discuss/u/Jarin_James)\
**Post date:** [February 15, 2024, 12:20pm UTC](https://developer.sailpoint.com/discuss/t/jdbcconnector-delete-cleanup-orphan-entitlements-role-and-identity-assignments/30230/4 "2024-02-15T12:20:07Z")

</div>

Hi @chriskk ,

If you are referring to updating the role model as well, you will have to run Propagate Role Changes task. You can refer the Propagating Role Changes section in this document.  
[8.3 IdentityIQ Role Group and Population Management Guide - Compass (sailpoint.com)](https://community.sailpoint.com/t5/IdentityIQ-Product-Guides/8-3-IdentityIQ-Role-Group-and-Population-Management-Guide/ta-p/214159)

---

<div class="post-metadata">

**Author:** ![BalajiChandrasekaran](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/balajichandrasekaran/32/8386_2.png) [@BalajiChandrasekaran](https://developer.sailpoint.com/discuss/u/BalajiChandrasekaran)\
**Post date:** [February 15, 2024, 12:52pm UTC](https://developer.sailpoint.com/discuss/t/jdbcconnector-delete-cleanup-orphan-entitlements-role-and-identity-assignments/30230/5 "2024-02-15T12:52:32Z")

</div>

Hi @Chriskk & @Jarin_James ,

Propagate role changes task will help in removing the roles from the identity cube if the role/entitlement has been deleted from the role. But in this scenario explained by @chriskk, the role composition is not modified. The entitlement that was present in the role has now become invalid as it is now not present in the entitlement catalogue. We have to delete the entitlement manually from the IT role and then go forward with the role propagation task.

---

<div class="post-metadata">

**Author:** ![chriskk](https://avatars.discourse-cdn.com/v4/letter/c/eb8c5e/32.png) [@chriskk](https://developer.sailpoint.com/discuss/u/chriskk)\
**Post date:** [February 15, 2024, 1:26pm UTC](https://developer.sailpoint.com/discuss/t/jdbcconnector-delete-cleanup-orphan-entitlements-role-and-identity-assignments/30230/6 "2024-02-15T13:26:12Z")

</div>

Thanks you for your clarification.

In my opinion, IIQ should help to automate this behavior 😉

If I really need to watch these changes manually:  
How can IIQ help me to collect this information (e.g. a list of deleted entitlements) and send this to some people so they can react?

Currently is there only an option/flag in GroupAggregation.

thx

---

<div class="post-metadata">

**Author:** ![BalajiChandrasekaran](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/balajichandrasekaran/32/8386_2.png) [@BalajiChandrasekaran](https://developer.sailpoint.com/discuss/u/BalajiChandrasekaran)\
**Post date:** [February 15, 2024, 3:08pm UTC](https://developer.sailpoint.com/discuss/t/jdbcconnector-delete-cleanup-orphan-entitlements-role-and-identity-assignments/30230/7 "2024-02-15T15:08:16Z")

</div>

Yes, Role object is static one, whereas the Identity object is dynamic where it gets updated/modified by different task.

If the role object is also dynamic, it would eliminate a lot of stale data.

---

<div class="post-metadata">

**Author:** ![frerkmeyer](https://avatars.discourse-cdn.com/v4/letter/f/c67d28/32.png) [@frerkmeyer](https://developer.sailpoint.com/discuss/u/frerkmeyer)\
**Post date:** [February 20, 2024, 2:47pm UTC](https://developer.sailpoint.com/discuss/t/jdbcconnector-delete-cleanup-orphan-entitlements-role-and-identity-assignments/30230/8 "2024-02-20T14:47:10Z")

</div>

We have the exact same problem.  
I consider this a bug of IIQ (v8.3).  
Support said this is an “idea” for improvement.  
So I wrote a bug report as an idea:  
[https://ideas.sailpoint.com/ideas/IIQ-I-1169](https://ideas.sailpoint.com/ideas/IIQ-I-1169)  
Please vote and comment on this.

I try to rephrase the bug/problem as clear as possible:

- business role b contains it role i
- it role i contains entitlement e.
- entitlement e gets deleted in app, so it is no longer valid
- group aggregation with delete option on deletes entitlement e from the entilement catalog, but:
- it role i references entitlement e nevertheless.
- If we assign business roles to identities, they get assigned it roles, which leed to assignment of entitlements, which generates errors and stacktraces and stop the provisioning as soon as it reaches the first invalid entitlement.

There is no job to automatically detect invalid entitlements and delete them from it roles.  
It is expected to manually discover invalid entitlements and manually delete invalid entitlements from it roles.

I’m currently writing a tool to clean it roles, which I would expect to be included in the IIQ product.  
Currently I am able to detect all invalid entitlements in it roles and log that (as of today).  
I have problems finding the correct way to delete those entitlements from it roles.  
Pointers to code for that are welcome.

THX

---

<div class="post-metadata">

**Author:** ![frerkmeyer](https://avatars.discourse-cdn.com/v4/letter/f/c67d28/32.png) [@frerkmeyer](https://developer.sailpoint.com/discuss/u/frerkmeyer)\
**Post date:** [March 1, 2024, 2:01pm UTC](https://developer.sailpoint.com/discuss/t/jdbcconnector-delete-cleanup-orphan-entitlements-role-and-identity-assignments/30230/9 "2024-03-01T14:01:57Z")

</div>

Thanks to

> **[@vishal\_kejriwal1](https://developer.sailpoint.com/discuss/u/vishal_kejriwal1/summary)**
>
> 15 years of experience in Identity Governance , I am an expert in designing implementing secure identity governance solutions , defining process that will enable organizations to meet secure control and also to meet Audit and regu…

I was able to write a cleanup task:

> [@How to delete entitlement reference in it role profile? Save does not save](https://developer.sailpoint.com/discuss/t/how-to-delete-entitlement-reference-in-it-role-profile-save-does-not-save/31552):
>
> Which IIQ version are you inquiring about? Version 8.3 Share all details related to your problem, including any error messages you may have received. Some entitlements in an external application (Keycloak) got deleted. Group aggregation with the delete option activated removed them from the entitlement catalog. Now there are invalid references to those in the profiles of some it roles, which Sailpoint IIQ does not delete. (I consider this a bug, I try to repair the product). So I wrote a gen…

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [April 30, 2024, 2:02pm UTC](https://developer.sailpoint.com/discuss/t/jdbcconnector-delete-cleanup-orphan-entitlements-role-and-identity-assignments/30230/10 "2024-04-30T14:02:03Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
