This section describes the procedures to configure User centric memberships for Groups, UserGroups and AccountGroups.
For more information see:
This section describes the procedures to configure User centric memberships for Groups, UserGroups and AccountGroups.
For more information see:
This section describes the procedure to configure User centric membership for Groups in Synchronization Editor.
To configure User centric membership for Groups
Field | Value |
Schema Type | UCIGroup |
Display Name | UCIGroup(Group) |
Class Name | UCIGroup_Group |
Description | UCIGroup_Group |
System Objects --> Condition | ResourceType = Group |
NOTE: Synchronization Editor is used to create a new schema class. For more information, see Creating a new schema class using Synchronization Editor.
Field | Value |
Schema Type | UCIUserInGroup |
Display Name | UCIUserInGroup(Group) |
Class Name | UCIUserInGroup_Group |
Description | UCIUserInGroup_Group |
System Objects --> Condition | UID_UCIGroup <> 'leave it as empty' |
System filter |
UID_UCIGroup in (select UID_UCIGroup from UCIGroup where ResourceType = 'Group') |
The new schema classes are created and the changes are saved.
Edit default mapping for Group.
To edit default mapping for Group:
List | Value |
One Identity Manager schema class | UCIGroup(Group) |
Target system schema class | Group (all) |
NOTE: Add the group members mapping under User object in Synchronization Editor.
Create <vrtMembers> property for Groups
Add vrtMembersGroup parameter with M:N type schema type with the below configuration.
To add the virtual parameters:
Field/ Option | Value |
Name | vrtMembersGroup |
Display name | GroupMembers |
Select the following options:
NOTE: Select UCIUserInGroup(Group) schema type for vrtMembersGroup parameter.
To create mappings:
NOTE: You can create a mapping by dragging the property vrtMembersGroup in the UCIUser pane and dropping it to the property groups~value in the SCIMUser pane.
This section describes the procedure to configure User centric membership for UserGroups in the Synchronization Editor.
To configure User centric membership for UserGroups
Create the new schema class UCIGroup(UserGroups) , with UCIGroup Schema type, using the details provided in the table:
Field | Value |
Schema Type | UCIGroup |
Display Name | UCIGroup(UserGroups) |
Class Name | UCIGroup_UserGroups |
Description | UCIGroup_UserGroups |
System Objects --> Condition | ResourceType = UserGroups |
NOTE: Synchronization Editor is used to create a new schema class. For more information, see Creating a new schema class using Synchronization Editor.
Create the new schema class UCIUserInGroup(UserGroups), with Schema typeUCIUserInGroup, using the details provided in the table:
Field | Value |
Schema Type | UCIUserInGroup |
Display Name | UCIUserInGroup(UserGroups) |
Class Name | UCIUserInGroup_UserGroups |
Description | UCIUserInGroup_UserGroups |
System Objects --> Condition | UID_UCIGroup <> 'leave it as empty' |
System filter |
UID_UCIGroup in (select UID_UCIGroup from UCIGroup where ResourceType = 'UserGroups') |
The new schema classes are created and the changes are saved.
To create mappings for UserGroups:
Field | Value |
Mapping name | UserGroups |
Mapping direction | Both directions |
NOTE: Select the option Maps objects referenced by multiple references.
Field | Value |
One Identity Manager schema class | UCIGroup(UserGroups) |
Target system schema class | UserGroups (all) |
The new mapping rule ConanicalName <-> vrtcononicalName is displayed in the Property mapping rules section in the Schema property in One Identity Manager list.
Create Initial Synchronization workflow for UserGroups.
To create Initial Synchronization workflow for UserGroups.
Field | Value |
Name | UserGroups |
Mapping | UserGroups |
Synchronization direction | One Identity Manager |
Revision filtering | Use revision filter |
Exception handling | Use workflow default |
The UserGroups workflow is displayed in the Workflow section.
To create Provisioning workflows for UserGroups.
Field | Value |
Name | UserGroups |
Mapping | UserGroups |
Synchronization direction | Target system |
Revision filtering | Use workflow default |
Exception handling | Use workflow default |
The UserGroups workflow is displayed in the Workflow section.
Create <vrtMembers> property for UserGroups.
Add vrtMembersUserGroups parameter with M:N type schema type with the below configuration.
To add the virtual parameters:
Field/ Option | Value |
Name | vrtMembersUserGroups |
Display name | UserGroupMembers |
Select the following options:
NOTE: Select UCIUserInGroup(UserGroups) schema type for vrtMembersUserGroups parameter.
To create mappings:
NOTE: You can create a mapping by dragging the property vrtMembersUserGroups in the UCIUser pane and dropping it to the property userGroups~value in the SCIMUser pane.
This section describes the procedure to configure User centric membership for Groups in Synchronization Editor.
To configure User centric membership for AccountGroups
Field | Value |
Schema Type | UCIGroup |
Display Name | UCIGroup(AccountGroups) |
Class Name | UCIGroup_AccountGroups |
Description | UCIGroup_AccountGroups |
System Objects --> Condition | ResourceType = AccountGroups |
NOTE: Synchronization Editor is used to create a new schema class. For more information, see Creating a new schema class using Synchronization Editor.
Field | Value |
Schema Type | UCIUserInGroup |
Display Name | UCIUserInGroup(AccountGroups) |
Class Name | UCIUserInGroup_AccountGroups |
Description | UCIUserInGroup_AccountGroups |
System Objects --> Condition | UID_UCIGroup <> 'leave it as empty' |
System filter |
UID_UCIGroup in (select UID_UCIGroup from UCIGroup where ResourceType = 'AccountGroups') |
The new schema classes are created and the changes are saved.
To create mappings for AccountGroups:
Field | Value |
Mapping name | AccountGroups |
Mapping direction | Both directions |
NOTE: Select the option Maps objects referenced by multiple references.
Field | Value |
One Identity Manager schema class | UCIGroup(AccountGroups) |
Target system schema class | AccountGroups (all) |
The new mapping rule ConanicalName <-> vrtcononicalName is displayed in the Property mapping rules section in the Schema property in One Identity Manager list.
Create Initial Synchronization workflow for AccountGroups.
To create Initial Synchronization workflow for AccountGroup
Field | Value |
Name | UserGroups |
Mapping | UserGroups |
Synchronization direction | One Identity Manager |
Revision filtering | Use revision filter |
Exception handling | Use workflow default |
The AccountGroups workflow is displayed in the Workflow section.
To create Provisioning workflows for AccountGroups.
Field | Value |
Name | AccountGroups |
Mapping | AccountGroups |
Synchronization direction | Target system |
Revision filtering | Use workflow default |
Exception handling | Use workflow default |
The AccountGroups workflow is displayed in the Workflow section.
Create <vrtMembers> property for AccountGroups
Add vrtMembersAccountGroups parameter with M:N type schema type with the below configuration.
To add the virtual parameters:
Field/ Option | Value |
Name | vrtMembersAccountGroup |
Display name | AccountGroupMembers |
Select the following options:
NOTE: Select UCIUserInGroup(AccountGroups) schema type for vrtMembersAccountGroups parameter.
To create mappings:
NOTE: You can create a mapping by dragging the property vrtMembersAccountGroups in the UCIUser pane and dropping it to the property accountGroups~value in the SCIMUser pane.
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center