AD Owner is not getting updated in SailPoint

Hi all,

we are seeing a case where owner of the AD entitlements are not getting updated. The owner has been updated on the AD side already. The group aggregation is all success.

Below is the template of the aggregation task:

<?xml version='1.0' encoding='UTF-8'?>
<!DOCTYPE TaskDefinition PUBLIC "sailpoint.dtd" "sailpoint.dtd">
<TaskDefinition formPath="/monitor/tasks/accountGroupAggregationTask.xhtml" name="AD Group Aggregation" resultAction="Rename"  subType="task_item_type_acct_grp_aggregation" type="AccountGroupAggregation">
  <Attributes>
    <Map>
      <entry key="accountGroupRefreshRule" value="Rule-FrameWork-Group-Refresh"/>
      <entry key="aggregationType" value="group"/>
      <entry key="applications" value="AD"/>
      <entry key="checkDeleted" value="false"/>
      <entry key="deltaAggregation" value="false"/>
      <entry key="descriptionLocale" value="en_US"/>
      <entry key="enablePartitioning" value="false"/>
      <entry key="groupSchema"/>
      <entry key="haltOnMaxError" value="false"/>
      <entry key="noGroupCycleDetection" value="True"/>
      <entry key="promoteClassifications" value="false"/>
      <entry key="taskCompletionEmailNotify" value="Disabled"/>
    </Map>
  </Attributes>
  <Description>Task template for application group scanning.</Description>
  <Owner>
    <Reference class="sailpoint.object.Identity" id="" name="spadmin"/>
  </Owner>
  <Parent>
    <Reference class="sailpoint.object.TaskDefinition" id="" name="Account Group Aggregation"/>
  </Parent>
</TaskDefinition>

we added noGroupCycleDetection  to resolve pruning cyclic warning.

We have the appropriate schema as below


schema.png

I found the resolution where IIQ won’t set the entitlement owner automatically based off a schema attribute.

This can be accomplished via an account group refresh rule. AD Group aggregation only brings group objects in SailPoint, but it does not set meta data like group owner etc.

To set a group owner, we need to create a “Group Aggregation Refresh Rule” and select in the AD Group Aggregation task or define an entry in the AD application as follows:

entry key=“apAdditionalApplicationMGroupRefreshRule” value=“AD-Additional-GroupRefresh”/>

Additional info can be found on my other developer forum post here: