Wrong Policy Violations is showing during the access request

When submitting an entitlement request for an identity, the system is displaying incorrect policy violations. Specifically, we are experiencing this issue with Entitlement SOD policies. Please note that these policies were added to the identities via the backend.

For example, when requesting an entitlement for Application1, policy violations related to other applications, which the user already has, are being flagged instead. Please refer the below screenshots for the same

Hi @snhvi

Please check your policy configuration details. You may have configured it in combination with other applications. This behavior, where it checks for existing access during a request, is expected.

Hi @pattabhi ,

Thanks for the response.

We are encountering this issue with only some users, even though policies were assigned to all identities through the backend. Is there a way to prevent this policy detection from occurring repeatedly for these specific users?

Thanks,

Sanghavi

try disabling the policy and it will not detect it.

Dear @snhvi

There are a few options for disabling violation detection:

  1. First, as Naveen suggested, you could simply disable the policy.
  2. However, a more appropriate solution is to exclude these users from the policy definition.
  3. Alternatively, you can disable the setting that detects violations during the access request submission.