Entitlements (Provisioning)
EmpowerID supports automated provisioning and deprovisioning of birthright account identities in external target directories and applications through the configuration of provisioning policies. These policies can be assigned or scoped using any RBAC assignment point such as Business Role and Location, Query-Based Collection, or Management Role membership.
|
Prerequisites
|
RET Actions/Events
|
On Claim ActionThe four options and outcomes are:
|
On Transform ActionThe four options and outcomes are:
|
On Revoke ActionThe four options and outcomes are:
|
Register Event Option
|
AD/LDAP Account Creation Location LogicWhen provisioning users automatically via provisioning policies into AD or LDAP directories, EmpowerID must determine into which OU a person’s account should be provisioned. The default logic is to follow the RBAC mapping for the Location portion of a Person’s Business Role and Location to create the account in the Account Store OU mapped to that EmpowerID Location. In some cases, this default logic is not desired, and a custom rule should be implemented. For these cases, EmpowerID allows the creation of a plugin in Workflow Studio to handle this unique RET AD/LDAP Account Creation Location logic. | User Interface for Viewing the RET Inbox
|
RET Throttling Settings |
Related Docs Topics: