In these cases it may be appropriate to create an independent resource object for each target system group. There are some substantial advantages to this approach:
- In the user resource view an administrator will clearly see what target system group or application the user has access to
- Attestation works cleaner
- Out of the box reports works better
There is also nothing that stops you from doing a "mix and match" approach where some AD groups are represented as independent resource objects and other are grouped under a general "Add AD group" resource object.
The implementation basically follows the steps in Support for request based OIM group memberships other than the fact that you will not need any object form as the group name is reflected in the resource object itself.
No comments:
Post a Comment