New Capability: Entitlement Rename and Move is now GA

Description

The feature addresses an issue with aggregating entitlements that are renamed in Active Directory and Azure Sources. Prior to this release, when an entitlement Distinguished Name (DN) was changed in an Active Directory or Azure source, ISC was not able to correlate the renamed entitlement to its associated entitlement in ISC. This resulted in invalid entitlement references within roles and access profiles and the loss of entitlement owner, display name, and access request information.

With this release, when an entitlement Distinguished Name (DN) is changed in an Active Directory or Azure source, ISC is now able to correctly correlate the modified entitlement to its associated entitlement in ISC.

New Capabilities

ISC is now able to seamlessly handle entitlements that have been renamed or moved within MS Active Directory or Azure sources.

Problem

Prior to this release, when an entitlement was renamed or moved within a MS Active Directory or Azure source, the corresponding ISC entitlement was removed and a new entitlement was created in it’s place however references to the entitlement were not updated.

Solution

ISC is now able to correlate entitlements that have been renamed within MS AD or Azure with the corresponding entitlements in ISC instead of removing and replacing them.

Who is affected?

This feature affects all customers.

Action Required

No action is required by customers.

Important Dates

:warning: Update: This feature is now Generally Available for all customers.

7 Likes

That’s fantastic news!

1 Like

Does this affect accounts that have their DN changed as well?

1 Like

Hi @PGookin,

Thank you for this announcement. This addresses a significant pain point with AD and Entra entitlement management.

I have a few questions about the technical implementation:

1. Correlation Mechanics:

How does ISC correlate the renamed/moved entitlement to the existing entitlement in ISC? Is it using the GUID / ObjectID as the primary correlation attribute, or are there other identifiers involved? Does this correlation happen during account and entitlement aggregation, or is there a separate reconciliation mechanism?

2. Configuration:

Is this capability automatically enabled for all AD and Entra ID sources, or does it require any connector/source configuration changes?

3. Edge Cases:

Are there any limitations or known scenarios where correlation might not work as expected?

Understanding these mechanics would help us better support this feature.

Thank you :slight_smile:

3 Likes