立即与支持人员聊天
与支持团队交流

Identity Manager 9.1.3 - Administration Guide for Connecting to Custom Target Systems

Managing custom target systems Setting up scripted data provisioning in a custom target system Managing user accounts and employees Managing assignments of groups and system entitlements Login information for user accounts Mapping custom target system objects in One Identity Manager Treatment of custom target system objects in the Web Portal Basic configuration data for custom target systems Configuration parameters for managing custom target systems

Disabling user accounts

The way you disable user accounts depends on how they are managed.

Scenario: User accounts are linked to employees and are managed through account definitions.

User accounts managed through account definitions are disabled when the employee is temporarily or permanently disabled. The behavior depends on the user account manage level. Accounts with the Full managed manage level are disabled depending on the account definition settings. For user accounts with a manage level, configure the required behavior using the template in the UNSAccountB.AccountDisabled column.

Scenario: The user accounts are linked to employees. No account definition is applied.

User accounts managed through user account definitions are disabled when the employee is temporarily or permanently disabled. The behavior depends on the QER | Person | TemporaryDeactivation configuration parameter

  • If the configuration parameter is set, the employee’s user accounts are disabled when the employee is permanently or temporarily disabled.

  • If the configuration parameter is not set, the employee’s properties do not have any effect on the associated user accounts.

To the user account when the configuration parameter is disabled

  1. In the Manager, select the Custom Target Systems > <target system> > User accounts category.

  2. Select the user account in the result list.

  3. Select the Change main data task.

  4. On the General tab, set the Account is disabled option.

  5. Save the changes.
Scenario: The user accounts are not linked to employees.

To disable a user account that is no longer linked to an employee

  1. In the Manager, select the Custom Target Systems > <target system> > User accounts category.

  2. Select the user account in the result list.

  3. Select the Change main data task.

  4. On the General tab, set the Account is disabled option.

  5. Save the changes.
  • For more information about deactivating and deleting employees and user accounts, see the One Identity Manager Target System Base Module Administration Guide.
    Related topics
  • Deleting and restoring user accounts

    NOTE: As long as an account definition for an employee is valid, the employee retains the user account that was created by it. If the account definition assignment is removed, the user account that was created from this account definition, is deleted.

    You can delete a user account that was not created using an account definition through the result list or from the menu bar. After you have confirmed the security alert the user account is marked for deletion in the One Identity Manager. The user account is locked in One Identity Manager and permanently deleted from the One Identity Manager database and the target system depending on the deferred deletion setting.

    For more information about deactivating and deleting employees and user accounts, see the One Identity Manager Target System Base Module Administration Guide.

    To delete a user account that is not managed using an account definition

    1. In the Manager, select the Custom Target Systems > <target system> > User accounts category.

    2. Select the user account in the result list.

    3. Click in the result list.
    4. Confirm the security prompt with Yes.

    To restore a user account

    1. In the Manager, select the Custom Target Systems > <target system> > User accounts category.

    2. Select the user account in the result list.

    3. Click in the result list.

    Related topics

    Displaying the user account overview

    Use this task to obtain an overview of the most important information about a user account.

    To obtain an overview of a user account

    1. In the Manager, select the Custom Target Systems > <target system> > User accounts category.

    2. Select the user account in the result list.

    3. Select the User account overview task.

    Groups in custom target systems

    Groups and system entitlements represent the objects used in the target system to control access to target system resources. A user account obtains the required permissions for accessing target system resources through its memberships in groups and system entitlements.

    To create a group

    1. In the Manager, select the Custom Target Systems > <target system> > Groups category.

    2. Click in the result list.

    3. On the main data form, edit the main data of the group.

    4. Save the changes.

    To edit group main data

    1. In the Manager, select the Custom Target Systems > <target system> > Groups category.

    2. Select the group in the result list.

    3. Select the Change main data task.

    4. On the main data form, edit the main data of the group.

    5. Save the changes.
    Related topics
    相关文档

    The document was helpful.

    选择评级

    I easily found the information I needed.

    选择评级