Ensuring that all Dynamic Groups are controlled by a single Active Roles Administration Service job server
In large environments or where Dynamic Groups are heavily utilized, it may be necessary to ensure that all Dynamic Groups are always managed by a dedicated Active Roles Administration Service job server.
This can be ensured through the use of an Automation Workflow.
In the Active Roles Console, navigate to Configuration | Policies | Workflow
Create a new Automation Workflow.
Drag in a Search Activity, right-click on it and select Properties.
On the Scope and Filter tab, in the Find dropdown, change the option from All Objects to Groups.
Change the When searching the Organizational Unit or Container: radio button to Retrieve any objects in held in the Organizational Unit or container.
In the Search Options pane, under Retrieve only these group types: check off the Dynamic Group checkbox and click OK | OK.
Drag an Update Activity into the Search where it shows Drop Activities Here, then right-click on it and select Properties.
On the Activity Target tab, select the Object Found by Search Activity
On the Target Properties tab, choose Add Property | More Choices and add the edsaDGOriginatingService, then click OK.
In the Value column, select Define | Text string and add in the Fully-Qualified Domain Name of the machine hosting the desired Active Roles Administration Service job server.
In the Workflow options and start conditions at the top, click the Configure button.
Enable the Schedule option and configured the desired schedule.