Chat now with support
Chat with Support

Identity Manager 8.0 - Administration Guide for Connecting to Cloud Applications

Synchronizing Cloud Applications through the Universal Cloud Interface Setting up Synchronization with a Cloud Application Base Data for Managing Cloud Applications Cloud Applications Container Structures in a Cloud Application User Accounts in a Cloud Application Groups in a Cloud Application Permissions Controls in a Cloud Application Provisioning Object Changes Managing Provisioning Processes in the Web Portal Additional Information for Experts Appendix: Default Project Template for Cloud Applications

Configuring Memberships Provisioning

Configuring Memberships Provisioning

Memberships, for example, user accounts in groups, are saved in assignment tables in the One Identity Manager database. During provisioning of modified memberships, changes made in the target system will probably be overwritten. This behavior can occur under the following conditions:

  • Memberships are saved in the target system as an object property in list form (Example: List of users accounts in the property members~value of a Cloud group).
  • Memberships can be modified in either of the connected systems.
  • A provisioning workflow and provisioning processes are set up.

If a membership in One Identity Manager changes, the complete list of members is transferred to the target system by default. Memberships, previously added to the target system are removed by this; previously deleted memberships are added again.

To prevent this, provisioning can be configured such that only the modified membership is provisioned in the target system. The corresponding behavior is configured separately for each assignment table.

To allow separate provisioning of memberships

  1. Start the Manager.
  2. Select the category Universal Cloud Interface | Basic configuration data | Target system types.
  3. Select Configure tables for publishing.
  4. Select the assignment tables for which you want to allow separate provisioning. Multi-select is possible.
    • The option can only be set for assignment tables whose base table has a column XDateSubItem.
    • Assignment tables, which are grouped together in a virtual schema property in the mapping, must be labeled identically.
  5. Click Enable merging.
  6. Save the changes.

For each assignment table labeled like this, the changes made in the One Identity Manager are saved in a separate table. During modification provisioning, the members list in the target system is compared to the entries in this table. This means that only modified memberships are provisioned and the members list does not get entirely overwritten.

NOTE: The complete members list is updated by synchronization. During this process, objects with changes but incomplete provisioning are not handled. These objects are logged in the synchronization log.

For more detailed information about provisioning memberships, see the One Identity Manager Target SystemClosed SynchronizationClosed Reference Guide.

Supporting Analysis of Synchronization Issues

Help for Analyzing Synchronization Issues

You can generate a report for analyzing problems which occur during synchronization, for example, insufficient performance. The report contains information such as:

  • Consistency check results
  • Revision filterClosed settings
  • ScopeClosed applied
  • Analysis of the synchronization buffer
  • Object access times in the One Identity Manager database and in the target system

To generate a synchronization analysis report

  1. Open the synchronization project in the Synchronization EditorClosed.

  2. Select the menu Help | Generate synchronization analysis report and answer the security prompt with Yes.

    The report may take a few minutes to generate. It is displayed in a separate window.

  3. Print the report or save it in one of the available output formats.

Deactivating Synchronization

Deactivating Synchronization

Regular synchronization cannot be started until the synchronization project and the schedule are active.

To prevent regular synchronization

  1. Open the synchronization project in the Synchronization EditorClosed.

  2. Select the start up configuration and deactivate the configured schedule.

    Now you can only start synchronization manually.

An activated synchronization project can only be edited to a limited extend. The schema in the synchronization project must be updated if schema modifications are required. The synchronization project is deactivated in this case and can be edited again.

Furthermore, the synchronization project must be deactivated if synchronization should not be started by any means (not even manually).

To deactivate the loaded synchronization project

  1. Select General on the start page.
  2. Click Deactivate project.
Detailed information about this topic

Base Data for Managing Cloud Applications

The following data is relevant for managing a cloud application in the One Identity Manager.

  • Administrators

    In One Identity Manager, you can assign employees to any cloud application, who can configure synchronization of the cloud application with One Identity Manager. There is a default application role for administrators in One Identity Manager. Assign the employees to this application role, who are authorized to configure synchronization and run manual provisioning. Create more application roles if required.

    For more information, see Administrators.

  • Operators

    In One Identity Manager, you can assign employees to any cloud application, who can execute manual provisioning. There is a default application role for operators in One Identity Manager. Create more application roles if required.

    For more information, see Operators.

  • Auditors

    In One Identity Manager, you can assign employees to any cloud application, who can audit provisioning processes in the Web Portal. There is a default application role for auditors in One Identity Manager. Create more application roles if required.

    For more information, see Auditors.

  • Server

    Servers must know your server functionality in order to handle cloud specific processes in One Identity Manager. For example, the synchronization server.

    For more information, see Editing a Server.

Related Documents