Dependency-aware correlation and Role Mining
K
KaHo Man
When a system is dependent on another system, HelloID should first process and correlate the primary system. The resulting correlation and account-linking information should then be used when processing the dependent system.
For correlation, HelloID should:
Process and correlate the primary system first.
Link the accounts in the primary system.
Make the resulting correlation and account data available to the dependent system.
Use this information when correlating accounts in the dependent system.
The same logic should apply to Role Mining. Role Mining should respect these system dependencies and use the correlation results from the primary system when processing the dependent system.
Implementation benefit
During an implementation, this approach removes the need to import entitlements into the primary system solely for Role Mining purposes.
Instead, the primary system can first be correlated, after which its correlation and account information can be used to process the dependent system and perform Role Mining.
This simplifies the implementation process, reduces unnecessary entitlement imports in the primary system, and makes better use of the existing relationships between primary and dependent systems.
Twan Duvigneau
Hi KaHo, I'm not really sure what you're trying to resolve here. Do you want to split the system snapshot into seperate parts? One to import the accounts (for correlation), one to import entitlements (for the business rules) and one to import entitlement memberships (for role mining and reconciliation)?
The way i see it when implementing a tenant with the primary system (lets say Active Directory) and a dependant system (lets say EntraId) is setting up the account entitlement business rules, running the import for Active Directory, correlate and import, and after that execute the EntraId import/correlation. After that you can execute the role mining over both systems. I'm not really seeing what dependencies would add to this.
I can imagine that when role mining it would suggest roles for EntraId entitlements, which require the Active Directory system as dependency. Would you want Role mining to make sure that the condition also has the Account Entitlement for Active directory configured because of the dependency? That would only require HelloID to query if the EntraId system has depencancies, in which case it should add the Account Entitlement for Active Directory, or make sure its in another suggested role that covers the scope of the suggested role/rule. I'm not really seeing how that would require changes to the whole snapshot functionality.
Just curious what you're trying to fix here exactly :)
K
KaHo Man
Twan Duvigneau, during implementation we often don't import the entitlements already. If we don't do that for example for the target Exchange Online, then we cannot execute role mining for that system. Correlation is set to userprincipalname of the AD account vs userprincipalname at Exchange Online. Alternatively we could use business email for correlation, that way we could use role mining, but the result is heavily dependend on whether the email business is always the same as userprincipalname and registered correctly at the HR side.
Twan Duvigneau
KaHo Man We always execute our role mining after having our account entitlements managed in business rules/imported, so we never really have any issues with this