sbhagat
(swapnil bhagat)
September 3, 2024, 6:41pm
1
In Manager Certification,
If any Business roles are having 3 IT Detected Role and 1 IT Assigned Role .
When we create certification then we are seeing that separate access item got created for Business role and also for Assigned Role.
What is the expected behavior?[wrap=“hidden”]
[/wrap]
sbhagat
(swapnil bhagat)
September 6, 2024, 1:53pm
3
Issue it Manager Certification is taking only Assigned Roles but not the detected Roles.
Hello,
Is the detected role(which did not appear in cert) a part of Business role?
1 Like
sbhagat
(swapnil bhagat)
September 9, 2024, 8:33am
5
YES, It is the part of Business roles.
I believe the IIQ behavior is it displays the business role(parent role) in the certification and not the child role if it is detected IT roles.
But it displays the Assigned IT roles even though it is a part of a business role.
You can certify the business role but cannot certify individual IT Roles(Detected) which are present inside them
You can use exclusion rule to handle the assigned business role
Refer this link:
Explanation of the Certification Exclusion Rule Code
Introduction
The provided XML code defines a certification exclusion rule in the SailPoint system, which is used for identity and access management. This rule aims to remove specific certifiable items from the certification process if the identity being certified is marked as inactive.
Code Structure
Rule Element
Rule language=“beanshell” name=“Rule-Exclusion” type=“CertificationExclusion”
The language attribute specifies the scripting la…
2 Likes
system
(system)
Closed
November 8, 2024, 9:59am
8
This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.