cancel
Showing results for 
Search instead for 
Did you mean: 

How to Delete AD privileges

Ckumar
Contributor
0 Kudos

Hi,

I am using SAP NetWeaver Identity Management Version: 7.2, Service pack 7

Few days back I have deleted same users from AD by running the job in identity centre.

These users have corresponding AD privileges in IDM.

After successfully deletion of users from AD i tried to remove their AD privileges (XYZ_ONLY and System_XYZ privilege) from backend.

For few users its worked fine and user's corresponding privileges has been removed successfully while for some users it didn't work.

when i checked the status of the privileges of failed users, its showing as Removal of assignment Requested, but privileges are not getting removed.

Please help me out to solve this issue.

PS- I don't know exactly how to know the service pack. As per my knowledge if i am using Version 7.20.X YYYY-MM-DD then my service pack is X.

Please tell me the proper way and path to know the service pack if i am wrong.

Thanks in Advance

Regards,

C Kumar

Accepted Solutions (1)

Accepted Solutions (1)

Ckumar
Contributor
0 Kudos

Thanx kelvin and Peter for your reply,

I have solved this issue.

Actually i faced this issue with those privileges which were Direct privileges.

To remove them i used

{e}{Direct_Reference=1}<PRIV:GROUP:REPOSITORY:PRIVNAME>

after using this i have successfully removed the corresponding privileges.

Regards,

C kumar

Answers (2)

Answers (2)

Former Member
0 Kudos

It should automatically remove them if you've done it from a task.  If it was a job then you'll need to sort it out.

However, when you manually remove it, it will try and remove the account, which may not now work given that you've already deleted it.  You could try a hard remove (as per Kelvins comment) but you might also need to disable the automated tasks on the Repository when you do it so it doesn't try and deprovison them again

Peter

Former Member
0 Kudos


Hi Kumar,

The log shows any errors?

You could try to create a new ToIdentityStore Pass.

And pass the values to remove the privileges.

MXREF_MX_PRIVILEGE     {e}<PRIV:GROUP:REPOSITORY:PRIVNAME>