Roles and Entitlement dependencies

Hello Community,

In ISC, we have defined two roles:

  • Role R001: Includes entitlements E01, E02, and E03.
  • Role R002: Includes entitlements E01, E04, and E05.

Note: Entitlement E01 is common to both roles.

When an Identity is granted Role R001:

  1. Can I individually view the entitlements associated with the Identity? Or will only the Role be visible?
  2. Can entitlements be removed from an Identity independently of the Role?
  3. If Entitlement E01 is removed, will the Identity lose Role R001, or will it retain the other entitlements (E02 and E03)?

When an Identity is granted both Role R001 and Role R002 but then the R002 is removed from the Identity:

  1. Will the Identity retain Entitlement E01 (which is also associated with Role R001)?
  2. In case the Entitlement E01 is removed (as a consequence of R0002 removal), will Role R001 also be removed from the Identity?

Hi Marco,

  1. Can I individually view the entitlements associated with the Identity? Or will only the Role be visible?
    You can individually view both the roles & entitlements in the identity cube by navigating to Access > Entitlements

  2. Can entitlements be removed from an Identity independently of the Role?
    No, it is not possible to remove from SailPoint. Though if it is removed externally, it will get assigned to identity again since it is part of the role.

  3. If Entitlement E01 is removed, will the Identity lose Role R001, or will it retain the other entitlements (E02 and E03)?
    Add to my comment for #2, role cannot be removed due to entitlement change unless you revoke it manually or it will auto revoked based on role membership criteria

  4. Will the Identity retain Entitlement E01 (which is also associated with Role R001)?
    Yes, it retains E01 because it is part of R001.

  5. In case the Entitlement E01 is removed (as a consequence of R0002 removal), will Role R001 also be removed from the Identity?
    No, R001 will not be removed. Instead it adds E01 to an identity again as part of R001.

Hope this helps.

2 Likes

Hello Suresh,

thank you for your response!

So, combining your answers 2 and 3, I believe that even by removing (externally) all the Entitlements (E01, E02, and E03), the Role would still be kept in ISC and its Entitlement would get reassigned back to the account.
Is this correct?

Extending my doubts to Certification Campaings:

  1. An account with Role R001 gets revised. Can the account lose individual Entitlements or only the Role entirely?
  2. In case only one single Entitlements (E01) does not get certificated, would the user lose the Role and retain the other entitlements (E02 and E03)?

Your understanding is correct.

  1. It will lost all the entitlements attached to the role
  2. The priority is in the following order from high to low, Roles, Access Profiles and Entitlements. So the role will always retained with attached entitlements.
1 Like

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.