Differences
This shows you the differences between two versions of the page.
Next revision | Previous revision Last revision Both sides next revision | ||
tutorial:adm:systems_-_ad_remove_group_membership_when_the_contract_is_excluded [2020/03/03 15:38] doischert created |
tutorial:adm:systems_-_ad_remove_group_membership_when_the_contract_is_excluded [2020/03/04 08:28] tsunami ↷ Page moved and renamed from tutorial:adm:systems_-_ad:remove_group_membership_when_the_contract_is_excluded to tutorial:adm:systems_-_ad_remove_group_membership_when_the_contract_is_excluded |
||
---|---|---|---|
Line 1: | Line 1: | ||
====== Systems - AD: Remove group membership when the contract is excluded ====== | ====== Systems - AD: Remove group membership when the contract is excluded ====== | ||
- | By default, when a contract is excluded, IdM will not remove the account' | + | By default, when a contract is excluded, IdM will not remove the account' |
- | As a result, when an identity' | + | As a result |
===== Change behavior for individual roles ===== | ===== Change behavior for individual roles ===== | ||
Line 15: | Line 15: | ||
{{ : | {{ : | ||
- | Open the detail by clicking the magnifying glass, you will see this. | + | Open the detail by clicking the magnifying glass. You will see this. |
+ | {{ : | ||
+ | Open the detail of the attribute ldapGroups by clicking the magnifying glass. You will see this. | ||
- | ===== Set it on for all roles in the AD synchronization workflow ===== | + | {{ : |
+ | {{ : | ||
+ | Check the checkbox next to "Skip value when contract is excluded" | ||
+ | ===== Set this behavior on using the AD synchronization workflow ===== | ||
+ | Alternatively, | ||
+ | First, I will show you how to turn this feature on for all AD roles. | ||
+ | |||
+ | <note tip>This requires you to have the current workflow from the Extras module! Older versions will not support this.</ | ||
+ | <note warning> | ||
+ | |||
+ | In the left menu, go to Settings > Configuration. | ||
+ | |||
+ | {{ : | ||
+ | |||
+ | Then when you click the green button Add, a dialog will open. Type in Key | ||
+ | |||
+ | < | ||
+ | |||
+ | and Value " | ||
+ | |||
+ | {{ : | ||
+ | |||
+ | Click save. During the next synchronization of AD groups, all AD roles will automatically set to be removed from inactive contracts (even existing ones. | ||
+ | |||
+ | You can also use this workflow to set this behavior for individual roles in bulk. As shown above, add a new property with Key | ||
+ | |||
+ | < | ||
+ | |||
+ | and as a Value, type in the names of the relevant roles separated by comma. You can only use this if your roles do not have a comma in their names! | ||
+ | |||
+ | {{ : | ||
+ | |||
+ | Click save. When the next synchronization runs, all roles specified in the Value here will be set to be removed the contract becomes inactive. |