Need Help Setting Up an Entitlement SOD Policy

I’m trying to setup a policy (Entitlement SOD Policy) in IIQ 8.5 for the first time. I have no violation formatting rule set, no violation business process, no alerts. I click the ‘Create New Rule’ button and put some text into the Summary field. Again, no violation rules or business processes.

In ‘First Entitlement Set’ I’m just adding a single entitlement from the list - I select the application as our Active Directory application, I add an attribute - member of, and select one of the AD groups.

When I click Done, I get the error “Incomplete configuration of match terms”.

This is as simple as I can get it - I haven’t even added the actual logic with the and, or, etc.

What is going on? I’m not able to figure out what it’s looking for - there really isn’t a lot to configure in the Policy. Is there something else I need to configure somewhere else in IIQ? How would I specify the ‘match terms’ - I don’t see any options for that in the Policy configuration.

If someone can point me in the right direction I’d appreciate it! It seems like it should be simple, but just not working for me!

Hi @karen_delucia - have you added anything to the “Second Entitlement Set”?

When you use an Entitlement SOD Policy, IIQ compares the user access to entitlements in the first and second entitlement sets. If the user has at least 1 entitlement in both sets, a violation is thrown.

If you’re requirement is to through a violation for any user that has that single AD group, I would recommend using an Advanced Policy here instead, or you could use the same entitlement in both sides (first and second sets) of the policy.

Ah, OK. I get it now. I didn’t have anything in the Second Set. I thought it was going to check the user’s existing access in their identity against what was in one or more of the Sets in the policy. I got it now! Thank you!

@karen_delucia You can also refer to the attached policy management document.
8.4_IdentityIQ_Policy_Management.pdf (331 KB)