Blog
Enhancement: Exclude Inactive Identities from Attribute Sync!
Author
kirby_fitch
SailPoint
Description
SailPoint is excited to announce that Inactive (long-term) identities will be excluded from the attribute sync process! This enhancement is available in all sandbox tenants. It will begin rolling out to production tenants on October 26, 2024.
This enhancement was a top request following the initial release of New Capability: Management of Inactive Identities. Administrators will have more control over the the last update to leavers’ accounts, and see a reduction in unneeded provisioning load.
Problem
Attribute syncs to inactive identities’ accounts are unneeded in most cases. The extra traffic can cause infrastructure problems and interfere with leaver processes. 51 voters have asked us to solve this problem in this idea.
Solution
Inactive (long-term) identities will be excluded from the attribute sync process except when:
- The identity just became inactive (long-term). In this scenario, the system provisions one last sync to handle for OU moves, deletions, etc. specified in a Before Provisioning rule.
- The administrator requests it via the Synchronize Attributes action. Synchronize Attributes can also be called via /beta/identities/:identityId/synchronize-attributes.
What’s the updated view of how the three identity states are used?
Active identities will be included in all services. Inactive (short-term) will be excluded from some services. Inactive (long-term) will be excluded from most services.
| Area | Active | Inactive (short-term) | Inactive (long-term) |
|---|---|---|---|
Included | Excluded | Excluded | |
My Team UI for Managers | Included | Excluded | Excluded |
Included | Included | Excluded | |
Included | Included | Excluded | |
Included | Included | Excluded | |
Included | Included | Included | |
Included | Included | Included | |
Identity Attribution Promotion after Accounts Updated in Aggregations | Included | Included | Included |
Who is affected?
All customers who have implemented both identity states and attribute sync.
Action Required
Review and implement the Identity States feature if you haven’t yet. The Identity States feature enables you to mark identities as inactive to exclude them from access requests, manager views, and more. This enhancement adds one more reason to enable the Identity State feature. A guide to enable the feature is available here: New Capability: Management of Inactive Identities.
Important Dates
- Sandbox: Monday, September 30th
- Production: The week of Monday, October 7th
Additional Resources
New Capability: Management of Inactive Identities
To ask questions and Learn more please visit the Developer Community!