Required Permissions

A user is required with the following scopes to perform necessary operations:

© SailPoint Technologies, Inc. All Rights Reserved.


This is the companion discussion topic for the documentation at https://documentation.sailpoint.com/connectors/saas/identity_security_cloud_gov/help/saas_connectivity/identity_security_cloud_governance/required_permissions.html

@DocsTeam, Under “Enable/Disable” operation, the scope mentioned is idn:accounts-provisioning:manage

But looks like no such scope exists on ISC :

Hi Arshad! Thank you for your input. We’ve created a Jira issue to track the effort and we’ll update the comment thread when it’s been addressed: CONDOCS-4073

1 Like

Hi @Arshad, you can use the scope as idn:account-provisioning:manage. There is a typo in this document page which will be corrected soon as mentioned in the above comment. Thanks!

Thank you @dinesh_mishra. Was able to find this :

image

Hope the typo in the document is updated soon.

1 Like

Hello @Arshad!
Thanks for bringing this to our attention. The typo in the Required Permissions topic has been corrected.
-Josh

2 Likes

Is this list still correct - we are able to aggregate entitlements, but receive this error when aggregating accounts.

[ConnectorError] 403 [Possible Suggestion] Ensure that configuration parameters is correct and service account is having required permissions. ERR_BAD_REQUEST, Request failed with status code 403, {“detailCode”:“403 Forbidden”,“trackingId”:“2cdfd5fed8904284ba63034942c527e1”,“messages”:[{“locale”:“und”,“localeOrigin”:“REQUEST”,“text”:“The server understood the request but refuses to authorize it.”},{“locale”:“en-US”,“localeOrigin”:“DEFAULT”,“text”:“The server understood the request but refuses to authorize it.”}],“causes”:} (requestId: da6c02a201744ffdb5c87cee513b6461)