Symantec IGA

  • 1.  In Identity Manager I create a user. This user is not created as a Global User in the Provisioning Manager.

    Posted Nov 19, 2018 08:05 AM

    Using vApp 14.2 Identity Suite I am able to create a new user in Identity Manager. However this new user is not created as a Global User in the Provisioning Manager. What can be the cause of this? As far as I know the Userstore for Identity Manager and the Global User are synchronized. How can I get a Global User when I create a User in Identity Manager? 



  • 2.  Re: In Identity Manager I create a user. This user is not created as a Global User in the Provisioning Manager.

    Posted Nov 19, 2018 08:33 AM

    Have you added a Provisioning Role to the user? It is possible to have a user in the User Store only if the User has no provisioning needs.



  • 3.  Re: In Identity Manager I create a user. This user is not created as a Global User in the Provisioning Manager.
    Best Answer

    Broadcom Employee
    Posted Nov 20, 2018 05:44 AM

    When creating a user in IDM make sure that you always assign a provisioning role at the time of creation. It can be an empty provisioning role with no account template. This ensures that the user gets created in the Provisioning Store at the same time, and that the password set in IDM is also set in the provisioning store.

     

    If you assign the provisioning role AFTER creating the user in IDM, then the user will get created in the Provisioning Store, but the password will not be there (as IDM can only access the hashed password in the user store at this point in time, which it obviously can not decrypt). This will then cause problems if you try to provision the user to endpoints. So use something like PX to ensure that all users get a provisioning role at time of creation (assuming that this is what you want).

     

    Pearse



  • 4.  Re: In Identity Manager I create a user. This user is not created as a Global User in the Provisioning Manager.

    Posted Nov 20, 2018 08:18 AM

    Dear Sidney and Pearse,

    Thank you for your help. I have created a default prov.role in IDM. When I create a new user and give this default prov.role, than a Global User is also created within provisioning store.