I want to hide remove button only for accounts on Remove Access(through Outbox remove button). Can any one suggest to achieve this task.
There is no much configuration we can change with that out of the box functionality
One way, is to set a filter (as in the screenshot below) and then configure it for all other users.
However, this can be easily removed by the end users.
Another approach would be to replace the our of the box remove functionality with a custom form which will have a similar functionality.
Here is an example to a custom form which will remove existing access but will not show the accounts
Thanks for the inputs.
If we go for second approach without giving any filter not displaying any accounts. However, I have account based access and if I go with form based approach and remove the entitlements. I can't see the account information for the entitlements to be removed in the PV_CHANGE_REQUEST_ACTIVITY table.
We are not able to see the entitlement belongs to either account or userid through form based revocation. Through button we can see the account info(screenshot below) and it's helps for provisioning.
How can we show account info through form for remove access?
Not sure I understand what you mean.
What product version are you currently on?
What is the expected behavior?
If you are using the out of the box form and try to remove the exact same authorizations, are you getting a different result?
Currently we are using 6.9 P25 version.
Using Remove access button, Remove button is showing showing for account and entitlements. I want to hide remove button for only accounts.
Could you suggest me how can I achieve this task.
I understand what you are trying to achieve.
What is not clear is why the suggested approach can't be used in your scenario.
Are you getting different results when removing entitlements using a Remove Access button vs the new custom form you created?
If there are differences, add some screenshots
If I go with custom form approach I am have below challenges,
This might be related to application configuration.
In your BMK application configuration, check the Requests tab
Is the Entitlements Require Account configured to Yes or No?
If it's No, then it might be a reason why your change request is generating User Changes and not Account Changes
Here is my setup.
User with 2 accounts and the same app-role is assigned to both accounts
When trying to run the form, I can see only 1 instance of the app-role.
It looks like the system is presenting the distinct authorizations which the user holds.
Not sure whether it's the designed behavior for that field or not.
I suggest you raise a support case to get a formal response.
In the created change request, the system will attempt to remove the app-role from 2 accounts
Thanks Boris !!.
I will raise the support case for this issue.
Retrieving data ...