Identity state

The identity life cycle is controlled by an identity's state. The state is changed automatically by system - when an identity is created, a default contract to the identity is added.

Identity states:

When identity becomes valid (i. e., at least one of their contracts becomes valid) and the identity has an account on at least one target system, then the new password is generated and changed on all identity's accounts ⇒ identity will have the same password in all accounts. Notification (see acc:newPasswordAllSystems template) is sent to identity about which of their accounts were changed.

Synchronization and provisioning

(since 10.8.0) The identity state attribute is possible to provision or synchronize to/from target system. Both types of operation support default transformation to/from string representation on the target system. Transformation to the corresponding identity state during synchronization is case insensitive. When provisioning is performed identity states are represented with following string values and synchronization is able to identify them.