I would like to suggest an improvement to the Active Directory account group(entitlements) reports. Currently, when generating a report that shows the removal of groups(entitlements) from AD accounts, we are unable to see the field that indicates which groups were removed.
It would be very useful to have this information available directly in the report columns.
Hi @caofrancoso Thanks for the suggestion. To submit a new idea for product improvement, please submit it in our Ideas Portal - that’s the best way to get an idea to our Product Management team. This article outlines how to/best practices submitting ideas + a link to our ideas portal:
First, I recommend searching the ideas portal, to see if an idea like this already exists, then voting on any others you prioritize.
Regarding your AD groups report, how are you generating these reports? Is this done via a search query or perhaps an API search? Which specific information is NOT available in your report column?
There may be API searches that can get you this information more comprehensively, but also, there are other features. For example…
Does your tenant have the Access History feature? This feature shows the entire timeline of exactly which entitlements were added or removed, with dates.
Thank you very much! I opened the “GOV-I-3860” portal.
I am using the Sailpoint search menu in the graphical interface. In the search menu, there is no column that shows the entitlement that was removed or inserted, only the action performed.
Using the access history menu, it is necessary to open identity by identity, making the process slow and with a high rate of human error during the analysis.
Thanks for the clarification @caofrancoso . Totally understand. You are looking for a default out of box column heading and column to indicate exactly which entitlement(s) were removed for those identities/accounts.
This information is available in the Events index. Although there is no UI column there either, you can still get the names of the entitlements removed, in case you needed a workaround.
As an API Search, something simple like this would reveal the info:
{ “indices”: [ “events” ], “query”: { “query”: “Remove Entitlement Passed” }} Then, parse the data in the “attributes” section, which has the following attributes (data points). I bolded the ones I think would be of greater interest to you: “attributes”: { “accountUuid” “cloudAppName” “appId” “sourceName”“accountName” “interface” “attributeName”“attributeValue” } Just thought I would offer 1 idea, while you await a response about your new idea.