Cloud target system |
Name of the target system. |
Canonical name |
Name of the target system conforming with DNS syntax.
target system name.parent target system name.primary system name
Example: DHW2k01.Testlab.com |
Distinguished name |
Cloud target system's distinguished name. This distinguished name is used to form distinguished names for child objects. If the target system does not supply any distinguished names, you can enter the target system identifier here, for example.
Syntax example: DC = <target system> |
Display name |
Name that is displayed in the One Identity Manager tools for the target system. |
Account definition (initial) |
Initial account definition for creating user accounts. This account definition is used if automatic assignment of employees to user accounts is used for this cloud target system and user accounts should be created which are already managed (Linked configured state). The account definition's default manage level is applied.
User accounts are only linked to the employee (Linked) if no account definition is given. This is the case on initial synchronization, for example. |
Deferred deletion [days] |
Number of days to defer deletion operations for this target system. For more information, see Setting deferred deletion for cloud target system user accounts. |
Target system managers |
Application role in which target system managers are specified. The target system managers only modify the cloud target system objects assigned to them. Therefore, each cloud target system can have a different target system manager assigned to it.
Select the One Identity Manager application role whose members are responsible for administration of this cloud target system. Use the button to add a new application role. |
Synchronized by |
Type of synchronization through which the data is synchronized between the target system and One Identity Manager. You can no longer change the synchronization type once objects for this target system are present in One Identity Manager.
If you create a cloud target system with the Synchronization Editor, One Identity Manager is used.
Table 28: Permitted values
One Identity Manager |
Universal Cloud Interface connector |
Universal Cloud Interface connector |
No synchronization |
none |
none |
NOTE: If you select No synchronization, you can define custom processes to exchange data between One Identity Manager and the target system. |
Types of system entitlements used |
Types of system entitlements to which user accounts can be assigned in this cloud target system. |
User account contains memberships |
Specifies for which types of system entitlements, memberships are maintained in the user accounts.
Enable the system entitlements with maintained user account memberships. The memberships are stored in the CSMUserHasGroup, CSMUserHasGroup1, CSMUserHasGroup2, CSMUserHasGroup3 tables.
Disable the system entitlements with maintained system entitlements memberships. The memberships are stored in the CSMUserInGroup, CSMUserInGroup1, CSMUserInGroup2, CSMUserInGroup3 tables.
Example:
In the System entitlement types used menu, the values Group and System entitlement 1 are selected. In the User account contains memberships menu, only the value System entitlement 1 is selected.
The memberships in the system entitlements are stored in the CSMUserHasGroup1 (System entitlement 1: Assignments to user accounts) and CSMUserInGroup (User accounts: Assignments to groups) tables. |
Description |
Text field for additional explanation. |
Manual provisioning |
Specifies whether changes to cloud objects in the One Identity Manager database are automatically provisioned in the cloud application. If this option is not set, processes for automatic provisioning of object modifications are configured.
Set this option, if object modifications are not allowed to be published automatically in the cloud application. Use the Web Portal to transfer the changes to the cloud application. For more information about provisioning object modifications, see the One Identity Manager Administration Guide for Connecting to Cloud Applications.
IMPORTANT: If you set this option, ensure that data, using regular and frequent synchronization,
is kept consistent! |
User account deletion not permitted |
Specifies whether user accounts in the cloud target system can be deleted. If this option is set, user account can only be disabled. |