Non-Employee Risk Management - System User Roles are removed on Initial user login

…Additional data point if you need to figure out what’s happening. In the back, there’s the user → role mappings (on NERM side), there’s a ‘source’ associated to each mapping.

What could be reason for source: “null” ? From the nerm apis while provisioning the roles, we get “source”: “manual”

No, it’s because for us IIQ is the system for access request and identity governance. ISC is not used to manage identity and account lifecycle management operations.

This, I get. Though there are various approaches (e.g. Singlular Idm, vs hierarchical [distributed] IdMs)…that’s another discussion entirely.

Interesting…so you have ISC…just to use NERM?

Yes, ISC just for NERM now :slight_smile:

  1. Do you know on how to disable Just In Time provisioning during authentication to NERM?

As per documentation: Authentication and Timeouts - SailPoint Non-Employee Risk Management Admin Help If a user doesn’t have an account within Non-Employee the first time they try to authenticate, one will be created for them automatically through Just-In-Time provisioning.

So, if we create their accounts in NERM via APIs and they already have their identity in ISC, then does the role removal happens due to JIT provisioning?