- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Provision account without entitlement
Hello,
How can we provision account on a target without a specific entitlement on a target like Active directory?
Our accounts does not have any standard group so we cannot give a default entitlement collected from the target for that.
This should be given when the identity is created in RSA without any form to fill by someone.(auto)
I suppose to use a joiner rule for that but not sure of the path to follow.
Thank you.
- Tags:
- Community Thread
- Discussion
- Forum Thread
- Identity
- Identity G&L
- Identity Governance & Lifecycle
- IG&L
- IGL
- provisioning
- RSA Identity
- RSA Identity G&L
- RSA Identity Governance & Lifecycle
- RSA Identity Governance and Lifecycle
- RSA IGL
- Rules
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi,
Thanks for the reply .
Finally we have found a solution by create a local entitlement collector which let you create manually an entitlement in RSA on the directly and give the possibility to create an active directory account with account template.
My initial question was not really clear I think, it was about the ability to provision an account to a target without a real entitlement on the target so this manual entitlement resolved the case.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hello,
One idea i used was creating two Active Directory groups. APP_AVEKSA_ONBOARDING and APP_AVEKSA_OFFBOARDING.
We have a rule that automatically adds any new joiners to APP_AVEKSA_ONBOARDING and the end result is a new Active Directory account.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi,
Thanks for the reply .
Finally we have found a solution by create a local entitlement collector which let you create manually an entitlement in RSA on the directly and give the possibility to create an active directory account with account template.
My initial question was not really clear I think, it was about the ability to provision an account to a target without a real entitlement on the target so this manual entitlement resolved the case.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hello Steve,
Did you end up creating a local entitlement and assigning them to the user so that account gets provisioned?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi Sunita,
Yes, we have create a local EDC et create entitlements manually in the directory.
After that, you have to create an account template and assign it to the directory with the option entitlements need an account.
If you wants to perform some actions like activate an account etc..., it's all done by workflow with decision on the entitlement name.
