The CreatorCon Call for Content is officially open! Get started here.

Duplicate Role records are seen on the User Role Related list with LDAP configuration imports users.

sonalin
Tera Expert

Observed on the instance the Roles are getting assigned to users repeatedly as a duplicate record.

find_real_file.png

find_real_file.png

Could any one help me understand this scenario of how Roles are getting imported from the AD. The LDAP server import schedule executed every day for all the users and the user/users is/are automatically created/updated on the SN side.

 

3 REPLIES 3

shloke04
Kilo Patron

Hi,

Roles are generally not added to User or Group Profile from AD at least OOB it does not add it to the profile.

This is a manual step where some one from the team might have added the Role manually and the other role which you are seeing is coming from the group.

So, what would have happened as below:

1) User was added to the group from AD integration and the group might be having that Role so user has got the role as shown in your screenshot below:

2) Additionally some one might have added the role directly to the user profile and hence you are seeing two records in your screenshot attached below:

find_real_file.png

If you see ITIL user in yellow looks like a Group through which Role has been granted where as the other is a manual addition directly on the user Profile.

On User Table in Roles related list there is a field named as "Granted By' check if that has a value then definitely it came from a group else some one has added it manually.

You can add Created and Updated by in Roles related list and see who has updated the profile,

Hope this helps. Please mark the answer as correct/helpful based on impact.

Regards,
Shloke

Hope this helps. Please mark the answer as correct/helpful based on impact.

Regards,
Shloke

Thank you for your reply Shloke.

The only reason I am searching Why I see the Granted By is  (empty) most of the times.

find_real_file.png

Here The Roles are never assigned manually to the itil users except the admins of the ITSM/ Other apps.

All Roles they get it from the groups they belong to.

The only scenario explained to me is when a user profile created in AD it is cloned form an existing similar kind of a user profile.

My Question is still why the Granted By column shows (empty). And How to get rid of this duplicate list of Roles and have an optimized list view of Roles.

Thanks,

Sonali.

okay. I see now, there is another factor which need to be considered and that is what it is happening in your case probably:

1) When a role is added to a group , and say when Group Members are coming in from AD and adding the users to the group if you are pulling that data as well considering then the role also gets added to the profile as per ServiceNow concept.

2) So now that role may or may not contain several other child Roles as well. For example, if ITIL role gets added to a user profile coming from the Group, Granted by shows as empty, but the additional role which ITIL inherits also gets added and it shows for those records as Inheritance = True.

3) Also there is a field named as "Inheritance Count" on the same Role related list which will tell you the count as well.

If you look at your screenshot inheritance is True for most of them.

Hope this helps. Please mark the answer as correct/helpful based on impact.

Regards,
Shloke

 

Hope this helps. Please mark the answer as correct/helpful based on impact.

Regards,
Shloke