You can automatically disable Unix accounts when users are de-provisioned in ActiveRoles Server.
To de-provision Unix users
- From the ActiveRoles Server Console, navigate to Configuration | Policies | Administration.
- From the Action menu, select New | Deprovisioning Policy.
- When the New Deprovisioning Policy Object Wizard starts, click Next.
- On the Name and Description page, enter Disable Unix accounts for deprovisioned users in the Name box and click Next.
- On the Policy to Configure page, locate the Safeguard Authentication Services Integration Pack and select the Deprovision Unix User policy type and click Next.
- On the Policy Parameters page, select the UnixDisable parameter and click Edit.
- On the Edit Parameter page, open the Value: drop-down menu, select True and click OK.
- On the Policy Parameters page, select the PrimaryGidNumber parameter and click Edit.
- On the Edit Parameter page, specify an integer value for the Primary GID number and click OK.
- On the Policy Parameters page, click Next.
- On the Enforce Policy page, click the Add button.
- On the Select Objects page, click Browse, select Active Directory (to apply this policy to all new users), and click OK.
- On the Select Objects page, select the Active Directory item at the top of the list, click Add and then click OK.
- On the Enforce Policy page, click Next.
- Click Finish to create the new policy object and close the wizard.
When you de-provision a user account, the Integration Pack automatically disables the user's Unix attributes.
To automatically Unix-enable groups
- From the ActiveRoles Server Console, navigate to Configuration | Policies | Administration.
- From the Action menu, select New | Provisioning Policy.
- When the New Provisioning Policy Object Wizard starts, click Next.
- On the Name and Description page, enter Unix-enable new groups in the Name box and click Next.
- On the Policy to Configure page, locate the Safeguard Authentication Services Integration Pack and select the Provision Unix Group policy type and click Next.
- On the Policy Parameters page, select the AutoUnixEnable parameter and click Edit.
- On the Edit Parameter page, open the Value: drop-down menu, select True and click OK.
- On the Policy Parameters page, click Next.
- On the Enforce Policy page, click the Add button.
- On the Select Objects page, click Browse, select Active Directory (to apply this policy to all new Active Directory groups), and click OK.
- On the Select Objects page, select the Active Directory item at the top of the list, click Add and then click OK.
- On the Enforce Policy page, click Next.
- Click Finish to create the new policy object.
- On the ActiveRoles Server dialog, click OK to return to the ActiveRoles Server Console.
When you provision a new group account, the Integration Pack automatically Unix-enables the users associated with that account. That is, it populates the user's Unix attributes.
You can automatically disable Unix accounts when groups are de-provisioned in ActiveRoles Server.
To de-provision Unix groups
- From the ActiveRoles Server Console, navigate to Configuration | Policies | Administration.
- From the Action menu, select New | Deprovisioning Policy.
- When the New Deprovisioning Policy Object Wizard starts, click Next.
- On the Name and Description page, enter Disable Unix accounts for deprovisioned groups in the Name box and click Next.
- On the Policy to Configure page, locate the Safeguard Authentication Services Integration Pack and select the Deprovision Unix Group policy type and click Next.
- On the Policy Parameters page, select the UnixDisable parameter and click Edit.
- On the Edit Parameter page, open the Value: drop-down menu, select True and click OK.
- On the Policy Parameters page, click Next.
- On the Enforce Policy page, click the Add button.
- On the Select Objects page, click Browse, select Active Directory (to apply this policy to all new groups), and then click OK.
- On the Select Objects page, select the Active Directory item at the top of the list, click Add and click OK.
- On the Enforce Policy page, click Next.
- Click Finish to create the new policy object and close the wizard.
When you de-provision a group account, the Integration Pack automatically clears the group's Unix attributes rendering it Unix-disabled.