- Bulk-load account
- Direct Provision account
- Request-based account
- Reconciliation account
- Access Policy provision account
Access Policies Harvesting is a new feature added to OIM after R2 PS2 release that Access Policies in OIM can manage bulk-loaded and reconciled accounts
To enable AP Harvesting in OIM:
· Set
the value of
XL.AllowAPHarvesting
and XL.AllowAPBasedMultipleAccountProvisioning
system properties to TRUE.
·
Set
the retrofit flag to ON for the policy to be linked by selecting Retrofit
Access Policy.
·
Designate
a field on the process form as the discriminator field and set the value of the
Account Discriminator
property to True.
With above configured, OIM is able link
the reconciled and bulk loaded accounts to pre-existing access policies by
running the 'Evaluate User Policies' scheduled task, and therefore, such
reconciled and bulk loaded accounts can be managed via access policies. This is
also referred to as access policy harvesting.
However, for those directed provisioned
and request-based accounts they are still not participated in to AP Harvesting.
That means they are not yet managed by access policies within OIM.
There are cases that provision operations
(either through direct provision/ request base) taken places prior to Access
Policies implementation taking into account. Especially, for production or
enterprise system these accounts could be up to thousands prior Access Policies
provision mechanism were adapted. These accounts some how need to be addressed
so that one can take the advantage of using access policies to manage all the
identity accounts in the enterprise.
In order to fully OIM AP harvesting all types of accounts in the system, we would need to Access Policies in OIM to manage both request-based and direct provisioned type accounts as well.
To achieve this, one should consider to upgrade to OIG 12c 12.2.1.3.0 where fix of
27599841 is included. If that's not an option then may need to check with oracle for the fix of this bug.
Additionally, there are two other system properties below introduced by the fix should be set to TRUE.
XL.APHarvestRequestAccount
XL.APHarvestDirectProvisionAccount
With all these configured then Access Policies in OIM now can fully manage all type of accounts.
No comments:
Post a Comment