Hello,
we noticed that the attribute is still mantaining a value of 1 after Jit Role expiration and removal from group (eg. Domain Admin).
We don't see a simple solution for that because, in some cases, it need to be maintained, while in other not.
Let me try to explain:
- I'm member of Domain Admins
- use Jit Role to be "Schema Admins"
- after Jit Role expiration my account is removed from Schema Admins
- AdminCount needs to be maintaned since I'm a domain admin
on contrary:
- I'm a standard user
- I'm added to Domain Admin with a Jit Role
- After expiratin, my account is removed from Domain Admins and the adminCount should be cleaned up
Do you see a possible solution doing a check before and after the Jit Role execution ?
Regards,
Red.
Hello,
we noticed that the attribute is still mantaining a value of 1 after Jit Role expiration and removal from group (eg. Domain Admin).
We don't see a simple solution for that because, in some cases, it need to be maintained, while in other not.
Let me try to explain:
on contrary:
Do you see a possible solution doing a check before and after the Jit Role execution ?
Regards,
Red.