You can use the Active Roles Web Interface to enable an existing Active Roles user with Starling Connect management capabilities.
To provision an existing Active Roles user for SaaS products
- 
On the Active Roles Web Interface navigation bar, click Directory Management. 
- 
On the Views tab in the Browse pane, click Active Directory. The list of Active Directory domains is displayed. 
- 
Click the specific domain, Container or the Organizational Unit, and then select the check box corresponding to the specific user, which you want to provision for SaaS products. 
- 
In the Command pane, click Provision Object in SaaS Products. The SaaS Products tab displays the list of registered Starling Connect connectors. The Starling Connect connectors for which you can provision users are displayed with selected check boxes. 
- 
Click Finish. The user is provisioned on the selected connected systems as per the policy applied. 
  
    
For an existing Active Roles Starling Connect user, you can use the Active Roles Web Interface to update the properties. When Active Roles user properties are updated, if the user property is mapped to Starling Connect User properties, then the changes are reflected for the selected connected system.
 
    
You can use the Active Roles Web Interface to delete an existing Active Roles Starling Connect user. When the Active Roles user is deleted, then the user is deleted on the selected connected system.
 
    
Active Roles provides the ability to deprovision SaaS product users. When an Active Roles user is deprovisioned, if the user is mapped to Starling Connect, then the user is deprovisioned from the selected connected system. This means the Active Roles SaaS product user is prevented from logging on to the network and connecting to any of the connected systems through the registered connectors.
The Deprovision command on a user updates the account as prescribed by the deprovisioning policies.
Active Roles comes with a default policy to automate some commonly-used deprovisioning tasks, and allows the administrator to configure and apply additional policies.
To deprovision a user for a SaaS product
- 
On the Active Roles Web Interface navigation bar, click Directory Management. 
- 
On the Views tab in the Browse pane, click Active Directory. The list of Active Directory domains is displayed. 
- 
Click the specific domain, Container or the Organizational Unit, and then select the check box corresponding to the specific user, which you want to deprovision for SaaS products 
- 
Select the user, and in the Command pane, click Deprovision. A message is displayed prompting you to confirm the account deprovision. 
- 
Click Yes to continue. Wait while Active Roles updates the user. After the task is completed, a message is displayed that the account is deprovisioned successfully from Active Roles. If the user is mapped to Starling Connect, then the user is deprovisioned from the connected systems. 
 
To undo deprovision of a user for a SaaS product
- 
On the Active Roles Web Interface navigation bar, click Directory Management. 
- 
On the Views tab in the Browse pane, click Active Directory. The list of Active Directory domains is displayed. 
- 
Click the specific domain, Container or the Organizational Unit, and then select the check box corresponding to the specific user, which you want to undo deprovision for SaaS products. 
- 
In the Command pane, click Undo Deprovisioning. The Password Options dialog is displayed. 
- 
Select the option to Leave the Password unchanged or Reset the password, and click OK.