You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在SailPoint IIQ中配置排除非活跃Identity的认证排除规则?

SailPoint IIQ 认证排除规则(CertificationExclusion)

规则用途

  • 排除标记为非活跃的Identity,避免其权限进入认证流程
  • 支持自定义过滤指定的权限(Entitlement)和角色(Role)
  • 适用场景:
    • 经理认证场景中自动排除非活跃员工的权限审核项
    • 分层审核场景:团队负责人先完成权限初审后,经理终审时排除已完成初审的项

完整规则代码

<?xml version='1.0' encoding='UTF-8'?>
<!DOCTYPE Rule PUBLIC "sailpoint.dtd" "sailpoint.dtd">
<Rule created="1691658072552" id="c0a8c78e89de1e298189deadb1e82b9e" language="beanshell" modified="1691659060902" name="Exclusion rule Ent and role" type="CertificationExclusion">
  <Description>This rule is an example Certification Exclusion rule that removes all of the certifiable items from a certification if the identity being certified is marked as inactive.</Description>
  <Signature returnType="String">
    <Inputs>
      <Argument name="log" type="org.apache.commons.logging.Log">
        <Description>
          The log object associated with the SailPointContext.
        </Description>
      </Argument>
      <Argument name="context" type="sailpoint.api.SailPointContext">
        <Description>
          A sailpoint.api.SailPointContext object that can be used to query the database if necessary.
        </Description>
      </Argument>
      <Argument name="entity" type="AbstractCertifiableEntity">
        <Description>
          The AbstractCertifiableEntity that is part of the certification.
          Currently, this is either an Identity, ManagedAttribute, or Bundle.
        </Description>
      </Argument>
      <Argument name="certification" type="Certification">
        <Description>
          The certification that this identity is part of.
        </Description>
      </Argument>
      <Argument name="certContext" type="CertificationContext">
        <Description>
          The CertificationContext that is being used to generate the
          certification.
        </Description>
      </Argument>
      <Argument name="items" type="List">
        <Description>
          List of Certifiable items that are currently part of the
          certification for this identity.  Any items that should be excluded
          from the certification should be deleted from this list and added
          to the itemsToExclude list.
        </Description>
      </Argument>
      <Argument name="itemsToExclude" type="List">
        <Description>
          A List of Certifiable items that should not be included in the
          certification.  This list will be empty when the rule is executed
          and any items that should not be part of the certification should
          be moved from the items list to the itemsToExclude list.
        </Description>
      </Argument>
      <Argument name="state">
        <Description>
          A Map containing state information.
        </Description>
      </Argument>
    </Inputs>
    <Returns>
      <Argument name="explanation" type="String">
        <Description>
          An optional explanation describing why the items were excluded.
        </Description>
      </Argument>
    </Returns>
  </Signature>
  <Source>


  import sailpoint.object.Certifiable;
  import sailpoint.object.Link;
  import sailpoint.object.Bundle;
  import sailpoint.object.EntitlementGroup;
  import sailpoint.object.Attributes;
  import java.util.List;
  import java.util.ArrayList;
  import sailpoint.object.Identity;
  //Iterate through certification items
  Iterator it = items.iterator();
  while ( it.hasNext() )
  {
    Certifiable certifiable = (Certifiable) it.next();
    //Exclude Roles
    if (certifiable instanceof Bundle)
    {
      Bundle role = (Bundle) certifiable;
      rolename = role.getFullName();
      //Exclude birthright roles
      if(rolename.startsWith(""))
      {
        it.remove();
        itemsToExclude.add(certifiable);
      }
    }
    //Exclude Entitlements
    if (certifiable instanceof EntitlementGroup)
    {
      EntitlementGroup entgrp = (EntitlementGroup) certifiable;
      Attributes atts = entgrp.getAttributes();
      List entlist = atts.getKeys();
      Iterator entit = entlist.iterator();
      while (entit.hasNext())
      {
        String attrname = entit.next();
        String attrval = atts.getString(attrname);
        if(attrname.equalsIgnoreCase("RoleId") &amp;&amp; attrval.equalsIgnoreCase("4"))
        {
          it.remove();
          itemsToExclude.add(certifiable);
        }
      }
    }
  }

  //Exclude Identity   
  Identity currentUser = (Identity) entity;

  if ( currentUser.isInactive()) {
    log.error("Inactive User: " + currentUser.getDisplayName());
    log.error("Do not certify.");
    itemsToExclude.addAll(items);
    items.clear();
    explanation = "Not certifying inactive users";
  }
  return explanation;


  </Source>
</Rule>

规则逻辑说明

  1. 非活跃身份过滤:将当前认证实体转换为Identity对象,判断其是否处于非活跃状态。若是则将所有待认证项移至排除列表,同时在日志中记录该操作,并返回排除原因说明。
  2. 指定角色过滤:遍历所有认证项,识别出类型为Bundle(对应IIQ中的Role)的项,通过角色名称前缀进行过滤(当前代码中前缀为空,需根据业务需求修改rolename.startsWith("")中的参数),符合条件的角色将被排除。
  3. 指定权限过滤:遍历类型为EntitlementGroup的认证项,检查其属性中是否存在RoleId等于4的条目,符合条件的权限组将被排除。

内容的提问来源于stack exchange,提问作者NoBody

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 22:49:49