One Identity 7.1 PersonWantsOrg - Person is not authorized to make requests at this point

I have had this problem long ago using the API however the old forums posts are not helpful.

Currently, in a mostly fresh install of One Identity 7.1 if I try to create a PersonWantsOrg request using Object Browser (logged in as viadmin) I get "This employee X is not authorized to make requests at this point". What is the secret sauce here? Is there a permission the requestor or requestee need to have? If so, what is the permission? 

-Josh

Parents Reply
  • On a mostly out-of-the-box fresh install of OneIM 7.1: Test scenario is a new business role - nothing special - called "Test Role". Nothing is assigned to the role. Created assignment resource, added it to a shelf. Went into Object Browser clicked add button for PersonWantsOrg, selected it from the drop down for UID_Org, selected myself from drop down for UID_PersonInserted, selected my "Test user" from drop down in UID_PersonOrdered - hit save - get the error above. The only non out of the box thing in this scenario is this is not the default ITShop but a new one. The new shop has a Customers object with a dynamic role. The test user is a customer of the shop and the shop shows assigned in the users 360 view. The test user also shows up in the 360 view of the shop under "Employees with access to this shop". The assignment resource is listed on the shelf on the shelfs 360 view.

Children