Currently, Active Roles has no limitations on how many objects can be gathered in a Managed Unit, even if those objects exist in Azure or Exchange Online.
This can result in the creation of programmatically expensive Managed Units, with too many remote objects to feasibly perform operations on or delegation permissions to.
The current implementation of Managed Units will need to be adjusted so that only a limited number of Azure or Exchange Online objects will be returned.
Enhancement ID 649176 has been created to change this functionality within Active Roles.
WORKAROUND 1
Limit Managed Unit queries to smaller subsets of objects and delegate access directly to Azure wherever possible.
WORKAROUND 2
Instead of using a Managed Unit to gather objects for delegation, leverage Access Rules to shape Access Template linkages wherever possible.
STATUS
An Enhancement Request has been created to change this functionality in Active Roles.
Product Management will evaluate the request and this feature may become available in a future release of the product.
There are no guarantees that this specific enhancement request will be implemented in a future release.
For more information regarding our Enhancement Request policy, refer to our Global Support Guide on the Support Portal at: https://support.oneidentity.com/essentials/support-guide/
© ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center