When requesting an access that is in SoD violation, the requester and in turn the approver are notified by the possible SoD violation. They have though the option to request and approve it anyway.

It would be good to be able to set an option on the SoD policy, that will require the SoD owner to be inserted at the end the approval chain when the request is expected to violate that SoD policy.

Comments

  • This feature to detect potential SoD violations and require further SoD approval is available in Identity Governance 3.5 as of Dec 2018.