cancel
Showing results for 
Search instead for 
Did you mean: 

MX_INACTIVE behavior in IDM 7.2 SP9

Former Member
0 Kudos

Dear all,

according to SAP since SP9 behavior of MX_INACTIVE was changed so modify operations on inactive identity are allowed now.

That's fine, it was not really comfortable to remove MX_INACTIVE, perform a change,  enable the MX_INACTIVE again.

Actually my question related to state showed in IDM after I switch identity to Inactive state.

Basically what happen then is that the identity loose all privileges in backend system - GOOD.

But in IDM I see all the privileges still assigned with status OK.  - Not good.

I would expect the status will be e.g. "Not Asssigned", but not OK.

I would like to hear an opinion of IDM experts here before asking SAP support directly.

Thank you in advance.

Best Regards,

Jiri

Accepted Solutions (1)

Accepted Solutions (1)

normann
Advisor
Advisor
0 Kudos

Hi Jiri,

I would recommend you to not use the MX_INACTIVE attribute for your scenario at all. There is so many dependencies coming with it and if something does not work perfectly, you cannot even clean up manually as you have to reactivate users which leads to provisioning again and and and...

My recommendation is: just remove all privileges from the user, so the user gets deprovisioned. If you want the user to not be visible in UI anymore use ACLs or an attribute to filter which tasks can be executed on those users.

Regards

Norman

Former Member
0 Kudos

Hi Norman,

thank you for your advice, I think we will go the way you described.

Regards,

Jiri

former_member2987
Active Contributor
0 Kudos

Former Member if this is the case, please mark Norman's answer as correct to close this thread. Thanks!!

Answers (0)