MSSQL source campaign user access removal

Hi Team, We are trying to remove user permission from MSSQL source user access review campaign and after the source owner/reviewer revoke any permission and sign off user access/permission is getting removed as we have elevated the service account permission to remove the user access/permission from the MSSQL database server instance. But before the source owner tried to revoke the user access/permission and sign off the campaign due to some reason user access/permission got removed from the MSSQL database server instance. After this source owner tried to revoke the user access/permission and sign off the campaign we are getting error “Unable to provision remove database role- db_datareader@ENT_DSS_DW Reason: Database user does not exist for role provisioning.” In provisioning activity tab but when we tried to check campaign status and campaign remediation report this is not captured. Could you please suggest why this error notification is not captured in campaign status and campaign remediation report?

My expectation is when the access/entitlement gets deleted not due to the campaign but when the same access/entitlement is going to be deleted which is included in the campaign as part of user access removal process through campaign the system should capture the failure of revoke of the access/entitlement in the campaign status and campaign remediation reports. The system is throwing “Unable to provision remove database role- db_datareader@ENT_DSS_DW Reason: Database user does not exist for role provisioning.” Which is shown in “Activities” tab but not captured in campaign status and campaign remediation report.

Thanks
Kalyan

Hi Kalyana,

I don’t think Campaign Status Report captures the exact reason of the revocation failures. It just captures whether revocation is successful or not and populate the Revoked Column as True or False respectively.

Hi Mahesh,

Thank you for your reply.

I have seen for AD based user access revocation capturing like “The account was deleted or changed before the campaign was completed.” under “Comments” column in campaign report for the access items which were removed at the end system not through campaign revoke process during user access revoke again trying to revoke in campaign.

Thanks
Kalyan

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.