There are a couple similar questions but no solution seems to have been identified so far. E.g.,
BACKGROUND:
- A user has 2 accounts on Active Directory (1 active, 1 disabled)
- A user has 2 accounts on a BusinessApplication (1 active, 1 disabled)
- BusinessApplication has an access profile, enabled for request, and assignment criteria is set up to automatically assign access to the active account.
- A role is configured, with the following settings:
- Role has 1 access profile, called ‘AD SSO Access Profile for Business Application’
- ‘AD SSO… Application’ access profile is configured to assign an entitlement, with the multiple account options configured to select the active Active Directory account
- Assignment criteria is configured so that the role is assigned if…
- AD account is active
- Business Application account is active
- Identity is active
ISSUE
- The role is not being assigned to the identity, even though with the active accounts, all requirements for the assignment criteria have been met.
My assumption is that ISC is taking information from the inactive AD record or Business App record and not assigning the role, even though there is both an Active AD account and active Business App account.
Any thoughts?
Thanks,
Margo
