Role IdentityRequestItems Incorrectly Flagged as Complete

Which IIQ version are you inquiring about?

8.3p3

Hello everyone,

I’m currently investigating a issue where IdentityRequestItems containing role items are incorrectly being flagged as Complete by IIQ. The issue can be consistently reproduced:

  1. When an user submits an access request that includes a role, everything is created as expected.

  2. After the Perform Identity Request Maintenance task is executed, the provisioning status of the item will be flagged as Finished by IIQ, even when the item has not been approved, yet alone provisioned:

    This does not have an effect on the approval or provisioning process of the request, everything is working as expected in this regard. Nothing is written to the identity cube or provisioned to the target application, until the approval process is finished.

  3. However, the status of the identity request will forever remain in pending, even after the approval and provisioning is finished. Again, this has no effect on provisioning, but is overall confusing to the end users.

After some investigation, this appears to be caused by the “approvalSplitPoint” attribute on the LCM Provisioning workflow. Changing the split point corresponds to the approval phase during which this issue will happen. I am using a customized LCM provisioning workflow, but this issue can be reproduced even with the OOB one. My current approval flow is manager → owner. I have the split point set to manager, which makes the identity request “vulnerable” to this issue right from its creation. If the user manages to complete the approval flow before the Identity Request Maintenance task is executed, then this issue will not happen, and the status of the identity request will be correctly updated. Setting the split point to null fixes this issue, but this introduces unwanted behavior to my LCM workflow.

This issue does not happen for any other access request type, e.g. entitlement request, account creation, etc.

Is there a way to prevent this issue from happening without significantly altering how my LCM workflow works? What is the reason for this behavior?

1 Like

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.