LDAP Role Membership Reconciliation scheduled job deleting all members from a role

(Doc ID 2194890.1)

Last updated on OCTOBER 19, 2016

Applies to:

Identity Manager - Version 11.1.2.2.0 and later
Information in this document applies to any platform.

Symptoms

OIM configured with ldapsync when a member is removed directly from a role in the LDAP backend after running the LDAP Role Membership Reconciliation scheduled job all the users are removed from the role in OIM.

Use case is the following:

A role has been created in OIM with several members

 

 

Ldapsync creates the role in OIM with its members (attribute uniquemember)

 

 

An application, user deletes one of the members directly from the LDAP backend

 

 

LDAP Role Membership Reconciliation schedule job is run to keep in sync OIM and LDAP

 

 

All the members from the role are deleted from OIM

 

 

Cause

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms