Exchange Mailbox (On-Premise) Provisioning Policies
Provisioning Policies allow you to automate the provisioning, moving, disabling, and de-provisioning of resources for users based on their roles, memberships, and locations within your organization.
This article demonstrates the following:
How to create a provisioning policy that provisions on-premise Exchange mailboxes
How to assign the provisioning policy to an EmpowerID actor type
Prerequisites
EmpowerID must first be connected to Active Directory. For details, see Connecting to Active Directory.
For Exchange mailboxes, you must have an Active Directory with an Exchange Organization.
RET provisioning and RET deprovisioning must be enabled on the Active Directory account store.
Provisioning policies can be targeted against any number or combination of Management Roles, groups, Business Roles and Locations, Query-Based collections, as well as individual people.
Create the provisioning policy
n the navbar, expand Identity Lifecycle, and select Provisioning Policies (RETs).
On the Policies page, click the Add button at the top of the grid.
Â
Under Choose Type, Select Exchange User Mailbox from the Object Type To Provision drop-down.
Â
In the General section of the form, fill in the following fields:
Name – Enter a name for the policy.
Description – Enter a description for the policy.
Mailbox Load Balancing Group – Enter the mailbox load balancing group.
Exchange Organization – Enter the name of your Exchange Organization.
Depends on Resource System – Select the Active Directory domain with the Exchange Organization. This specifies that the user must have an AD account in that domain before provisioning the mailbox.
In the Throttling Settings section of the form, specify the provisioning and deprovisioning thresholds for the policy. These settings are as follows:
All Provisions Require Approval – If this option is selected, the provisioning of each RET specified by the policy will need to be approved by a user delegated access to the Resource Entitlement Inbox.
All Deprovisions Require Approval – If this option is selected, the deprovisioning of each RET specified by the policy will need to be approved by a user delegated access to the Resource Entitlement Inbox.
Require Approval if Provision Batch Larger Than Threshold – This field allows you to set a numeric value that needs to be reached by a single run of the Resource Entitlement Inbox before an approver needs to approve the provisions. If the threshold is reached, EmpowerID will not provision any of the mailboxes until approval is granted.
Require Approval if Deprovision Batch Larger Than Threshold – This field allows you to set a numeric value that needs to be reached by a single run of the Resource Entitlement Inbox before an approver needs to approve the deprovisions. If the threshold is reached, EmpowerID will not deprovision any of the mailboxes until approval is granted.
In the Advanced section of the form, do the following:
Select a desired option from the On Claim Action drop-down. You have the following options:
Do Nothing – No action occurs. This tells EmpowerID to simply mark any previous resources assigned to the user that match this policy as RET-managed resources. For example, if the user already has an Exchange mailbox and is placed in a Management Role targeted by the RET policy, EmpowerID marks that user's mailbox as RET managed.
Publish Workflow Event – Executes custom workflow code.
Select a desired option from the On Revoke Action drop-down. You have the following options:
Do Nothing – No action occurs.
Deprovision – The mailbox is deleted if the person no longer meets the RET's criteria to receive the resource.
Disable – The mailbox is disabled if the person no longer meets the RET's criteria to receive the resource.
Publish Workflow Event – Executes custom workflow code.
Click Save to create the policy.
After EmpowerID creates the policy, you should be directed to the completed Policy Details page for the policy.
Â
Next, assign the policy you created to one or more targets, as demonstrated below.
How to assign the provisioning policy
On the Policy Details page, click the Find Policies breadcrumb.Â
Â
Search for the policy you just created and then click the Display Name link for it.
This directs you to the View page for the policy. This page allows you to manage the policy as needed.ÂÂ
On the View page, click the Assignees accordion to expand it. This accordion allows you to assign the policy to any of the following EmpowerID actor types:
Business Roles and Locations – All people in the selected Business Role and Location combinations receive the resource granted by the policy.
Management Roles – All people in the selected Management Roles receive the resource granted by the policy.
Management Role Definitions – All Management Roles that are children of the selected Management Role Definition receive the resource granted by the policy.
Query-Based Collections (SetGroup) – All people in the selected collection receive the resource granted by the policy.
Groups – All people in the selected groups receive the resource granted by the policy.
People – All people selected receive the resource granted by the policy.
From the Assignees accordion, click the Add button above the assignee type to which you are making the assignment.
In the Add Entry pane that appears, search for and select the appropriate assignee.
Enter a number to specify the priority for the RET policy in the Priority field. This value is used to determine the priority of the RET if the user qualifies for the same RET via another assignment, such as being a member of a group that has the same policy. The lower the number, the higher the priority.Â
Â
Click Save.
Back in the main form, click Save.
Â
Â