Salesforce permissionset certification is missing one identity

Which IIQ version are you inquiring about?

8.2p6

Share all details about your problem, including any error messages you may have received.

I have an identity with a salesforce account that has a permissionset called Full_Access.

When I create a targeted owner certification for Salesforce application and the entitlement “Full_Access” it does not show the identity.
The certification does show another identity that has the same permissionset though.
What could be the cause?

Thanks.
Pasha

Hi Pasha,

what type of certification did you launched? Targeted or Application owner certification.
If it is targeted certification, check the filter/population/rule logic in Who do you want to certify section.

Regards,
Arun

Hi @Arun-Kumar
It is a targeted entitlement owner certification. I have tried with explicitly filtered for my identity’s user name and it comes back as “nothing to certify”.

Can you try running the refresh this particular identity before generating review .

1 Like

Please try the following steps:

  1. In the Refresh Identity Cube task, enable the two checkboxes.

  2. For Faster testing, use the filter option to include only the specific identity you are working with.

  3. After the task is completed, verify the entitlements under the Identity Warehouse. Check if the “Full_Access” entitlement is still present.

  4. If the entitlement is present, it should also appear in the target certification.

  5. If you cannot find the entitlement, try to schedule the certification using Advanced Analytics to see if it appears there.

Hope this helps.

1 Like

Thank you guys. I did the refresh individually for this identity and the certification is picking it up. The question now is why my regular nightly refreshes were not doing the trick.

I would say check the provisioning transaction for this user and this Full_Access permissionSet and see changes done and try to match with your refresh task.

1 Like
  1. I have seen same issue and I observe that some of the entitlements are being deleted and added through batch requests due to which entitlements are not able to picking up on certification.
  2. I have scheduled one more IR task after the batch request (Only enabled two check boxes which I mentioned) and it helps me to promote entitlements.
  3. Check last refresh date on the link, this could helps you to find out any provisioning transection happened on that entitlement.
1 Like

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.