Hello All,
I am posting to crowdsource a solution to a problem that I am having. A little background on me, I was thrown into engineering solutions for ISC with little experience on the platform. I am still trying to learn everything I can in the hour or two of free time I have outside of my normal duties. My experience lies in performing administrative functions on the platform and creating a few basic workflows.
Problem:
We use Entra ID as our directory, and in within the directory we have an extension attribute that I will refer to as “extension_attribute_1” (ea1). This specific attribute is not available in the authoritative or secondary sources. The person that would review ea1 should be the end users manager as well.
SailPoint has still yet to be fully implemented as our IGA, and currently we rely on the requestor to inform the IAM team the value of ea1. If we were to ingest this through a secondary source of some sort, this would still be a manual process where IAM and the end user work together and IAM maintains a flat file that is aggregated whenever a change is made (which is multiple times an hour).
As far as the environment, we have entitlements that have the following naming structure (for a different purpose): “Extension Attribute 1 - Name A”.
Thought:
Is there a way that ea1 and the manager attribute could be updated via a transform based on if a user has been granted access to “Extension Attribute 1 - Name A”?
I am also looking to see if there is something I can do upstream, but business requirements may not be able to allow me to do this.
I was also thinking MAYBE there could be a rule created, but I have no Idea of the scope of this.