Sync Users upon access provisioning

This topic has 2 replies, 3 voices, and was last updated 3 weeks, 2 days ago by Andrew Potter.

  • Author
    Posts
  • #28585
     ppalikkal
    Participant

    I m trying to sync my IDM managed users to target system. Currently all the users that are added in IDM gets synced to target system. The requirement is only those managed users whom I assign a role in IDM should get synced to target system.
    Can anyone help me with a solution for the same.

    #28586
     Bill Nelson
    Participant

    IDM includes role-based provisioning, but this functionality really only applies to target attribute values – not the object, itself. As such, you would need to create conditional logic in your mapping that evaluates the user’s role membership before they are provisioned to the target. Make sure your logic applies to any creation, modification or deletion events so you can manage the user on the target system accordingly.

    #28614
     Andrew Potter
    Participant

    Typically you might use the ‘sourceCondition’ filter in a mapping for this.
    See: https://backstage.forgerock.com/docs/idm/7.1/synchronization-guide/filtering-source-and-target.html#filtering-source-and-target

Viewing 3 posts - 1 through 3 (of 3 total)

You must be logged in to reply to this topic.

©2021 ForgeRock - we provide an identity and access platform to secure every online relationship for the enterprise market, educational sector and even entire countries. Click to view our privacy policy and terms of use.

Log in with your credentials

Forgot your details?