Definition
A Manual Provisioning Policy allows to define that manual provisioning or deprovisioning Workflow is launched when the Role assignment status changes.
The configuration of a Role Request Policy is divided into 3 parts:
-
Classic properties of a configuration of a XML (version, encoding, kit DataSet...)
-
The Workflow Strategies that define which:
-
Provisioning/Deprovisioning Workflows to launch to validate the manual provisioning
-
Dimensions can be displayed
-
Dimensions can be updated
-
-
The Worfklow Action to configure notifications.
The manual provisioning Workflow can be launched when:
-
the role/super role is assigned to a user (manually or by policy)
-
the role assignment status changes from DELAYED to ASSIGNED
-
updating a role assignment
-
the role assignment is unfrozen
The manual deprovisioning Workflow can be launched when:
-
the role assignment status changes from ASSIGNED to DELETED
Configuration
You can access the Manual Provisioning Policy configuration :
-
by clicking on "Portal" → “Manual Provisioning Policies”
-
by clicking on "System" → "Configurations" → "Business Model" and perform an import/export.
Properties
|
Properties name |
Type |
Mandatory |
Description |
Values (default value in bold) |
|---|---|---|---|---|
|
id |
|
YES |
The id is the unique identifier of the Manual Provisioning Policy.
It is case sensitive and no special characters (except - or _) are allowed. |
- |
|
name |
|
YES |
The Manual Provisioning Policy name. The name may be different from the identifier.
|
- |
|
description |
|
NO |
Allows to describe the purpose of the Manual Provisioning Policy. |
- |
|
priority |
|
NO |
Used to indicate the priority between several configured Manual Provisioning Policies on the same object type. |
0, 1, 2... |
|
active |
|
NO |
Used to define if the Manual Provisioning Policy is activated or not. |
true, false |
|
scope |
- |
YES |
Allows to configure on which Role the Manual Provisioning Policy will be applied. |
- |
|
workflowStrategyForCreate workflowStrategyForUpdate workflowStrategyForDelete |
|
YES |
Used to indicate the Workflow Strategy used for manual Provisioning. It is the same configuration as in Role Request Policy.
|
- |
Example
Read Next
-
Business Policies A Business Policy allows to configure how to trigger actions on Object Types through a Feature with an optional configured Workflow.
-
Object Policies An Object Policy is an Identity Management Service Policy allowing to execute arbitrary actions on Managed Objects, either on a scheduled basis, or in reaction to an Object Operation.
-
Deduplication Policies A Deduplication Policy describes how duplicates should be searched for when creating a managed object.
-
Feature Access Policies A Feature Access Policy is composed of a right which encompasses several Features.
-
Manual Provisioning Policies -
Object Lifecycle Policies An Object Lifecycle Policy allows to configure rules, on all Object Types, that will alter an Object attribute directly when certain lifecycle events occur.
-
Password Policies A Password Policy determines how passwords should be composed and which rules apply to their lifecycle.
-
Role Request Policies A Role Request Policy allows to define if a Role can be requested, for whom, by whom, and using which Workflow.
-
Workflow Administration Policies A Workflow Administration Policy is composed of a right which encompasses several Features.
-
Memority MFA Account Policies A Memority MFA Policy allows to configure how multi factor authentication should be applied to a population of user
-
Homepage Selection Policies A Memority Home Page Selection Policy allows to configure differents home page depending on user rights.
-
SoD Policies In Memority, SoD rules are based on a SoD policy. A SOD Policy allows to define what kinds of conflicts you can specify and what attributes the system will use to detect them.