You are viewing an earlier version of the admin guide. For the latest version, please visit EmpowerID Admin Guide v7.211.0.0.
Getting Started with Directory Systems
Before you connect EmpowerID to an external directory, there are a number of prerequisite steps you need to take. You only need to perform these steps the first time you connect to an external directory. These steps are as follows:
Setting the server role for each of your EmpowerID servers — Server roles determine what EmpowerID jobs (back-end processes) and Web services are enabled on a particular server. EmpowerID categorizes server roles in the following way:
All-in-One-Server – The server role runs all front-end Web services and back-end processes. This role is designed to be used if you have a small environment with only one EmpowerID server.
Application Server Full – This server role runs all back-end processes, known as Jobs in EmpowerID. By default it does not run any Web services.
Application Server Light – This server role runs the minimum number of back-end processes. By default, it does not run any Web services.
Default – This server role has no Jobs or Web services associated with it. When you install EmpowerID on a server, EmpowerID assigns this role to the server. This is to ensure no Jobs or Web services run on a server not designated for those Jobs or Web services. You need to change this to the appropriate role for each EmpowerID server for that server to function as intended.
Web Front-End – This server role runs all Web services. By default it does not run any back-end processes.
Reviewing the Join and Provision Rules – When you connect EmpowerID to an external directory or other identity-aware application and turn on inventory, EmpowerID evaluates the accounts in those external systems to determine whether EmpowerID People should be provisioned from those accounts. The logic that determines this is specified by the Join and Provision Rules, as well as the filters in the Identity Warehouse. Thus, before turning on inventory, you should review these rules and filters and adjust them as needed.
Step 1 – Configure the server roles for each of your EmpowerID servers
On the navbar, expand Infrastructure Admin > EmpowerID Servers and Settings and select EmpowerID Servers.
On the EmpowerID Servers page, click the EmpowerID Servers tab and search for the server whose role you want to configure.
Click the Edit button for that server.
In the dialog that appears, select the appropriate role from the EmpowerID Server Role drop-down.
Click Save to save the role and close the dialog.
Step 2 – Review the Join and Provision rules for your environment
As the AccountJoinAndProvision filter is used to target which accounts are eligible for both joining and provisioning, the filter should only be customized in situations where the custom criteria apply to accounts that are both join and provision targets.