Logical Application Not Updating

Which IIQ version are you inquiring about?

8.3p4

Hi all

I am working on AD/LDAP groups based logical applications. We have an account rule that returns the list of composite links (logical app) as we want the groups/memberOf to be visible in the logical application. The issue is if a group is added or removed to/from a logical application but it is not the first group to be added/removed, then the updates are not reflected in the logical application link in Identity Warehouse. But if we go to Entitlement Catalog and view the logical application entitlement, then the user shows up in member tab. Additionally, if we view the user in View Identity, then the logical application groups are visible in user’s access.

Has someone faced a similar issue? Any help is appreciated.

Thanks,
Mahima

Try running a full aggregation instead of an incremental one and see if the issue persists.

I tried running refresh logical accounts task for the logical application but it did not fix the issue. On saving the logical application link and committing transaction in account rule, the groups are reflected correctly in Identity Warehouse but is this a good way? if this could result in lock issues?

If an identity is being updated by another job (e.g., aggregation, certification, or sync tasks), it could cause deadlocks or inconsistent data. and performance issue will cause

Do you know of a better way to handle this issue?

Hi Mahima,

If you are still doing or evaluating this connector in lower environment then I would recommend you to review LogiPlex connector once. Its advanced version of logical connector,

Thanks,
Pallavi

We have implemented this in prod already.