uppala
(Mahesh Babu Uppala)
February 20, 2025, 3:09pm
1
Hello Experts,
We Integrated Workday Accounts with IDN and observed few Access Profiles are getting removed with first Aggregation after they get provisioned.
Most of the Access profiles removed by system are User based Security Groups, any solution to fix this issue or why this is happening.
Thanks,
Mahesh
BenNelson
(Ben Nelson)
February 20, 2025, 8:01pm
2
Are the groups coming in as well? Or are they also falling off. Might want to perform a non-optimized aggregation on entitlements and accounts.
uppala
(Mahesh Babu Uppala)
February 20, 2025, 8:39pm
3
Hi Ben, aggregated without optimizations, still results are same.
I can clearly see in access history system removed access which we provisioned before aggregation.
BenNelson
(Ben Nelson)
February 20, 2025, 8:41pm
4
So the groups are still coming in the aggregation or are they falling off as well? I think in general, SailPoint recommends that you do an entitlement aggregation before the account aggregation to ensure account-entitlement relationships are correct. Are you doing that as well?
uppala
(Mahesh Babu Uppala)
February 20, 2025, 9:48pm
6
Hi Ben,
Assigned Below Access to User
It Got Provisioned and as you suggested ran entitlement aggregation system didn’t removed access
later kicked off Account Aggregation with out optimization and it removed two entitlements
uppala
(Mahesh Babu Uppala)
February 20, 2025, 9:56pm
7
Yes we checked account and entitlement relationship they are correct
jesvin90
(Jesvin Joseph)
February 21, 2025, 7:21am
8
Hi @uppala ,
Have you checked in your source system (Workday) to see if the entitlements are actually assigned to the user.?
The entitlement removal in IDN after an aggregation is often associated with a failed provisioning in the endpoint.
uppala
(Mahesh Babu Uppala)
February 21, 2025, 3:20pm
9
Hi Joseph,
Thanks for giving me new direction
Steps performed and outcome
Requested 3 Access Profiles to users and SailPoint completed provisioning and showing all of them are provisioned.
Checked Workday Accounts Source out of 3 Access Profiles only 1 Access Profile is Actually Provisioned.
After Aggregation its matching with source (SailPoint Realized and removing not provisioned access) .
Workday Accounts Team Assigned one of the not provisioned Access Profile Manually in Workday Accounts its Added without any issues.
Thanks,
Mahesh
system
(system)
Closed
April 22, 2025, 3:20pm
10
This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.