cancel
Showing results for 
Search instead for 
Did you mean: 

Group Membership Provisioning Issue

Former Member
0 Kudos

Hi All,

we are working for a banking client and have implemented two identity manager

SAP and SAILPOINT,

SAP IDM has been advised to work only for group membership provisioning not for user creation.

The approach what we are trying to follow is

Run the initial load and fetch all the users and group from Target system to SAP IDM and then will assign the user to group.

Please note Provisioning is disabled.

The task is failing i.e when i am trying to assign a group to a use after the initial load (User and Group both are there in AD), its not working.

Is it because i have disabled the provisioning and group membership task is dependent on them?

Accepted Solutions (0)

Answers (1)

Answers (1)

former_member2987
Active Contributor
0 Kudos

Hi there,

Most likely.

Please make sure that Identity IQ has been configured to create the accounts before you try to manipulate them via SAP IDM.

I'd advise only using IIQ for certification, and using IDM for SAP and AD provisioning.  It does both of those quite nicely (and easier that IIQ in my opinion)

However, I realize this might not be your decision

Regards,

Matt

Former Member
0 Kudos

I tried identifying but didn't find anything fishy which can stop group provisioning.

After checking in plugin i can see "Assign user membership is using schedule rule as provisioning.

If changing this type to " on demand or some other attribute, Is it going to help? or its just the schedule rule.

Are there any checks performed at the time of group assignment?

Regards,

Rosy

former_member2987
Active Contributor
0 Kudos

Rosy,

Take a look here on the forum.  This topic came up less than two weeks ago.

I think it will point you in the right direction.

Odds are, you're not the first to ask a particular question in IDM so it helps to do a quick search first

Regards,

Matt

IDM Moderator