EmpowerID supports automated provisioning and deprovisioning of birthright account identities in external target directories and applications through the configuration of provisioning policies. |
...
These policies can be assigned or scoped using any RBAC assignment point such as Business Role and Location, Query-Based Collection, or Management Role membership.
|
View file | ||
---|---|---|
|
|
...
Prerequisites
|
...
|
RET Actions/Events
|
...
|
...
|
...
|
On Claim ActionThe four options and outcomes are: |
...
|
...
|
...
|
...
|
...
|
...
|
...
|
|
On Transform ActionThe four options and outcomes are: |
...
|
...
|
...
|
...
|
|
On Revoke ActionThe four options and outcomes are: |
...
|
...
|
...
|
...
|
|
Register Event Option |
...
|
...
|
...
|
...
|
...
|
...
|
...
|
AD/LDAP Account Creation Location |
...
LogicWhen provisioning users automatically via provisioning policies into AD or LDAP directories, EmpowerID must determine into which OU a person’s account should be provisioned. The default logic is to follow the RBAC mapping for the Location portion of a Person’s Business Role and Location to create the account in the Account Store OU mapped to that EmpowerID Location. In some cases, this default logic is not desired, and a custom rule should be implemented. For these cases, EmpowerID allows the creation of a plugin in Workflow Studio to handle this unique RET AD/LDAP Account Creation Location logic. |
...
RET Throttling Settings |
|
Insert excerpt | ||||||
---|---|---|---|---|---|---|
|
Info |
---|
Related Docs Topics: |