Unable to remove entitlement from an LDAP application once assigned

Which IIQ version are you inquiring about?

8.4

Please share any images or screenshots, if relevant.

Admin entitlement from the LDAP application.

Screen shot of members tab in the entitlement

Remove access page from the Manage user access quicklink

Share all details about your problem, including any error messages you may have received.

I have assigned an entitlement to an user using the quicklink Manage user access named Admin, now when i am trying the remove the same access using “Manage user access” quicklink, i am unable to find the entitlement in the “remove access” page. I have confirmed the entitlement has been assigned to use in the target application. I have also tried following method : -

  1. Performed the identity refresh task with “Refresh entitlements for all links” option checked.

Please help me resolve this issue, Thank you.

Hi @Prash373

Check after running the following tasks.

  1. LDAP_Application group aggregation task.
  2. System tasks: Perform Identity Request Maintenance

Perform Identity Request Maintenance– prunes old identity request objects and scans unverified access requests to check for provisioning completeness.

Hi @Prash373

Try to run Account Aggregation task for the application and ensure that the entitlements are being pulled correctly and are linked to the user. If this did not work then check the option “Refresh Identity Entitlements for all links” in the “Refresh Identity Cube” task.

Hi @iiq-isc ,
I have performed the Perform Identity Request Maintenance and group aggregation tasks for the application still facing the same issue.

Can you run “Full Text Index Refresh” task and see entitlement if populating or not in remove access tab?

1 Like

Hi @Prash373, this is the correct answer by @vedeepak it will work 100%.
Have a nice and great one!

Regards,
Mustafa

Hi @MohamedSaad ,
As mentioned above, i have refreshed identity using the Identity refresh task with the Refresh Identity Entitlement for all links option selected and the results were same. But when i performed the Account Aggregation task i am getting the caution symbol in front of the entitlement as shown below

Hi @vedeepak ,
I have performed the Full Text Index Refresh task and still the entitlements are not getting populated in the Remove access tab.

I see the warning symbol on that entitlement. Can you refresh identity cube with “Provision assignments” option enabled? Also check the logs after the refresh identity task ran, if there are any errors.

Hi @Prash373 ,

as per this screenshot , it seems disconnected entitlement . it happens when iiq is not able to validate this from source . Can you verify in source , that it is actually provisioned or not . if it is then run the aggregation task again , if not check the identity from debug , and see if there is any entry for this in attribute assignment . if it is , then only refresh task will work with provision assignment check .
also from the debug , check the entitlement group for this application and verify the native identity . if the native identity is not correct then also it will not be visible in remove tab .
if the native identity is not correct , then just for testing purpose fix the native identity from backend and see if its working . if it works , then you can further validate why native identity did not get setup properly .
Thanks.

1 Like

Hi @harsh_gupta4 ,

I have resolved the issue of entitlements, now i am getting proper entitlements instead of sticky entitlements, yet in the in Manager user access quick link, in the Remove access tab, i am unable to find the assigned entitlements, even though the values are populated in the target application and identity cube

Hi @Prash373 , Open the Identity XML and check if those group exists in “EntitlementGroup” .
Is this entitlement got assigned as part of Birthright Roles ?

Hi @Prash373, maybe it’s part of a Role, check that and let us know because Full Text Index Refresh task builds and refreshes the index files used for full text searches on defined fields on the access request pages of the Lifecycle Manager.
The index files are rebuilt each time this task is run.

That means if the issue is not related to something else, like Roles (Assignment, BR, etc…), this task will fix it for you, anyways, can you just request an access/entitlement “for the testing purposes” for this user or another user with an entitlement that not related or part from any Role “stand alone” and check again then let us know.

Have a nice and great one!

Regards,
Mustafa

If possible share that identity xml object

3 Likes

1 . make sure that the entitlement is not part of any role .
2. Run the Refresh identity will all checkboxes checked . :stuck_out_tongue:

Thank you all, the issue have been resolved. Performed the “Full Text Index Refresh task”, made sure entitlement is not part of any role and also the “Identity refresh” with Refresh assigned, detected roles and promote additional entitlements option, and now i can see the entitlement in the remove access tab.

1 Like

Glad to hear that it’s resolved, have a nice and great one!