Usecase forDeprovisioning in SailPoint ISC

Hi Folks,

Just want to know some thoughts on one Use case:

Suppose for a user there are three source accounts, now when the terminated lifecycle get assigned automatically, the disable account will happen but for some reason only two accounts got disabled and one account is left due to some error. So, will the Sailpoint will retry automatically or there is any way to retrigger the event for that particular account.

Also 2nd thing is suppose we have LCS terminated plus 7 which only removes the entitlements so for this also how sailpoint will behave and is there any way to trigger event for particular account

Hi @Amsingh1

SailPoint will not retry automatically - you can configure “retryableErrors” in the source, which will kick off the attempt again as long as you specify the exact error that’s occurring. Only when the LCS is changed will events get kicked off again.

If you have another LCS state that gets triggered 7 days after termination, that can retrigger the disable again for the accounts if you specify it there. You can also specify “Remove All Access”, which will handle the entitlement removals.

Let me know if you need any further details!

Hello @Amsingh1 ,

In the Terminated LCS states, whichever sources you have configured for Disable Account Operations, for all of them, Disablement request will be sent to respective Target Sources. But, In case You want to retry, the ISC will not automatically retry any failed exceptions but you have explicitly mention it in retriable errors for respective source. Refer the below details.

Also, 2nd LCS state of “Terminated +7“, I Agree with @trettkowski you have to again mention list of sources for whom accounts or entitlements are impacted but if you don’t specify, then, only select Remove All Access Radio button so that it only remove entitlements.