My Oracle Support Banner

How to Provision an Entitlement via Role Assignment to Only the Primary or Secondary Account (Doc ID 2332183.1)

Last updated on FEBRUARY 03, 2019

Applies to:

Identity Manager - Version 11.1.2.3.161018 and later
Information in this document applies to any platform.

Goal

Flow of account creation:
1. User Identity is on-boarded with birthright AD Account (Primary)
2. Then Access Policy Based Provisioning is used to assign Roles

3. A Secondary AD Account was provisioned (Request Based Provisioning)
Now User has one Primary and one Secondary AD Account.

4. A manager requests a new Role (which has AD Entitlements)
5. Review of accounts, it is observed that these Entitlements are assigned to both Primary and Secondary Accounts.

Is there a mechanism in OIM when a new role (with AD Entitlements) can be assigned to only the AD Primary Account or the Secondary Account.

 

Solution

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Goal
Solution
References


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.