nerdexam
SailPoint

SAILPOINT-CERTIFIED-IDENTITYIQ-ENGINEER · Question #115

A client wants users who belong to an IdentitylQ workgroup named Management to be able to request entitlements and roles, but only for other users whose location attribute is the same as theirs. Is…

The correct answer is A. Yes. This solution correctly addresses the client's requirement. By setting the membership match list to "All" and configuring "Who can members request for?" as "share attributes with the requester," with the attribute set to location, the system ensures that users in the…

Access Request and Lifecycle Management

Question

A client wants users who belong to an IdentitylQ workgroup named Management to be able to request entitlements and roles, but only for other users whose location attribute is the same as theirs. Is this a population that will achieve the goal? Solution: Create a quicklink population, set the membership match list to "All," and set "Who can members request for?'' as share attributes with the requester, with the attribute set to location.'

Options

  • AYes
  • BNo

How the community answered

(27 responses)
  • A
    81% (22)
  • B
    19% (5)

Explanation

This solution correctly addresses the client's requirement. By setting the membership match list to "All" and configuring "Who can members request for?" as "share attributes with the requester," with the attribute set to location, the system ensures that users in the "Management" workgroup can only request roles and entitlements for other users who share the same location. This setup effectively filters based on the location attribute, aligning with the client's needs. Based Access Control Guide

Topics

#quicklink population#shared attributes#access request#location-based population

Community Discussion

No community discussion yet for this question.

Full SAILPOINT-CERTIFIED-IDENTITYIQ-ENGINEER Practice