Chat now with support
Chat with Support

Identity Manager 8.0 - Administration Guide for Active Roles Integration

Restoring Deprovisioned Active Directory User Accounts and Active Directory Groups in the One Identity Manager

Restoring Deprovisioned Active Directory User Accounts and Active Directory Groups in the One Identity Manager

You can restore deprovisioned Active Directory user account and Active Directory groups using One Identity Manager if required. The following methods are used to do this:

  • Undo Deprovisioning
  • Restoring Deleted Objects

Both methods initiate a process for deprovisioning Active Directory objects in Active Roles. The process finds the deprovisioning status, updates some of the Active Directory object properties, like the name and the Active Directory container, in the One Identity Manager database and sets the Active Directory object status to "changed". All the Active Directory object properties are loaded in the One Identity Manager database by the next synchronization and changed to "published".

Detailed information about this topic

Undo Deprovisioning

Use this method to undo Active Directory user account and Active Directory group deprovisioning. You can use this method independent of the deprovisioning method implemented.

To undo Active Directory user account deprovisioning

  1. Select the category Active Directory | User accounts | Deprovisioned accounts.
  2. Select the user account in the result list.
  3. Select Undo deprovisioning.
  4. Confirm the security prompt with Yes.
  5. Confirm with OK.

To undo Active Directory group deprovisioning

  1. Select the category Active Directory | Groups | Deprovisioned groups.
  2. Select the group in the result list.
  3. Select Undo deprovisioning.
  4. Confirm the security prompt with Yes.
  5. Confirm with OK.
Related Topics

Restoring Deleted Objects

You can use this method as an alternative for Active Directory user accounts and Active Directory groups you have deprovisioned using the method "Deprovision not delete". You find the deprovisioned Active Directory object, in this case, in the One Identity Manager database with status "Deleted".

To restore a user account

  1. Select the category Active Directory | User accounts.
  2. Select the user account in the result list.
  3. Click Undo delete in the result list toolbar.

To restore a group

  1. Select the category Active Directory | Groups.
  2. Select the group in the result list.
  3. Click Undo delete in the result list toolbar.
Related Topics

Appendix: Default Project Template for Active Roles

Appendix: Default Project Template for Active Roles

A default project template ensures that all required information is added in the One Identity Manager. This includes mappings, workflows and the synchronization base object. If you do not use a default project template you must declare the synchronization base object in One Identity Manager yourself.

Use a default project template for initially setting up the synchronization project. For custom implementations, you can extend the synchronization project with the .Synchronization Editor

The template uses mappings for the following schema types.

Table 12: Mapping Active Roles schema types to tables in the One Identity Manager schema.
Schema type in Active Roles Table in the One Identity Manager schema
builtInDomain ADSContainer
computer ADSMachine
contact ADSContact
container ADSContainer
domainDNS ADSDomain
group ADSGroup
inetOrgPerson ADSAccount
msDS-PasswordSettings ADSPolicy
msExchSystemObjectsContainer ADSContainer
oganization ADSContainer
organizationalUnit ADSContainer
printQueue ADSPrinter
rpcContainer ADSContainer
user ADSAccount
Related Documents