Employees can use mutual aid to reset their central password. Prerequisite is the question-answer pair which is stored for changing the central password.
To grant mutual aid
The employee for whom you want to grant mutual and can change their central password on this form.
To change the central password
If there is no personnel number stored with the employee, the field can remain empty.
The question for the central password appears.
Configuration parameter | Description |
---|---|
QER\Person\DefaultMailDomain |
This configuration parameter contains the default mail domain. The value is used to establish an employee's email address. |
The employee’s default email address is displayed on the mailboxes in the activated target system. The default installation from the One Identity Manager builds the default email address from the employee’s central user account and the default mail domain of the active target system.
The default mail domain is found in the configuration parameter "QER\Person\DefaultMailDomain".
How employees are handled, particularly in the case of permanent or partial withdrawal of an employee, varies between individual companies. There are companies that never delete employees, and only disable them when they leave the company.
The following methods are available in the One Identity Manager standard version:
The employee has temporarily left the company and is expected to return at a predefined date. The desired course of action could be to disable the user account and remove all group memberships. Or the user accounts could be deleted and reestablished with the employee’s return, even if it is with a new system identification number (SID).
Temporary disabling of an employee is triggered by:
|
NOTE: Configure and enable the schedule "Lock accounts of employees that have left the company" in the Designer. This schedule checks the start date for disabling and sets the option Temporarily disabled when it is reached. |
|
NOTE: Configure and enable the schedule "Enable temporarily disabled accounts" in the Designer. This schedule monitors the end date of the disabled period and enables the employee with their user accounts when the date expires. Employee's user accounts that were disabled before the period of temporary absence are also re-enabled once the period has expired. |
© 2023 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy