Synchronize Users and Roles

Due to various factors, users go out-of-sync with the provisioning roles that are assigned to them.
cim143
Due to various factors, users go out-of-sync with the provisioning roles that are assigned to them.
Few possible reasons for out-of-sync are:
  • Earlier attempts to create necessary accounts failed due to hardware or software problems in your network, causing missing accounts.
  • Provisioning roles and account templates change, and this creates extra or missing accounts.
  • Administrators use native tools on an endpoint to add or delete accounts. If you have not explored the endpoint again to update the provisioning directory, users end up having extra or missing accounts.
As a result, an administrator synchronizes users and provisioning roles to ensure that each user has the necessary account on the managed endpoints as defined in the provisioning role.
Follow the given methods to synchronize users and provisioning roles:

Check Role Synchronization

By using
Check Role Synchronization
task, an administrator can check if the user accounts comply with the provisioning roles, and accordingly perform synchronize operation.
An administrator can check the extra and missing accounts of a user. If the user is out-of-sync with the provisioning roles, the administrator can perform
Synchronize
operation so that the user has the necessary accounts on the managed endpoints. This task also ensures that each account belongs to the correct account templates.
Note:
Using this task, you can synchronize only one user at a time with the provisioning roles.
Follow these steps:
  1. Log in to the
    Identity Manager
    User Console.
  2. Navigate to
    Users
    ,
    Synchronization
    ,
    Check Role Synchronization
    .
  3. Select a user.
    A screen appears showing the expected accounts, extra accounts, and missing accounts of a user.
  4. If the user accounts are out-of-sync, click
    Synchronize
    to make the accounts match the account templates in the provisioning role.
    • Add missing accounts:
      Select this option to create missing accounts on the endpoint. If more than one account template for the user prescribes the same account, the account is created by merging all relevant account templates. This account is assigned to those account templates, which are currently not synchronized with the account.
    • Remove extra accounts:
      Select this option to delete extra user accounts. However, users can have legitimate reasons for having these accounts. If that is the case, leave this option unchecked.
      On certain endpoints, the account deletion function is disabled; therefore, the account is not deleted.
  5. Click
    Yes
    .
Note:
Synchronization does not happen when a template is removed from the provisioning role by using the
Modify Provisioning Role
task.

Synchronize User with Roles

By using
Synchronize User with Roles
task, an administrator can synchronize out-of-sync users with the provisioning roles that are assigned to them.
Note:
You can check the extra or missing accounts of a user with Check Role Synchronization task. However, this task allows you to check and synchronize only one user at a time with its assigned roles.
Follow these steps:
  1. Log in to the
    Identity Manager
    User Console.
  2. Navigate to
    Users
    ,
    Synchronization
    ,
    Synchronize User with Roles
    .
  3. Select user(s).
    • Add missing accounts:
      Select this option to create missing accounts on the endpoint. If more than one account template for the user prescribes the same account, the account is created by merging all relevant account templates. This account is assigned to those account templates, which are currently not synchronized with the account.
    • Remove extra accounts:
      Select this option to delete extra user accounts. However, users can have legitimate reasons for having these accounts. If that is the case, leave this option unchecked.
      On certain endpoints, the account deletion function is disabled; therefore, the account is not deleted.
    Note:
    When you modify these properties in the
    Synchronize User with Roles
    admin task, the same values reflect here too.
  4. Click
    Yes
    .

Synchronize User with Roles in Bulk

An administrator can synchronize users with provisioning roles in bulk. To perform bulk synchronization, you must first enable
Remove extra accounts
and
Add missing accounts
properties in the
Synchronize User with Roles
admin task and then perform a bulk loader operation.
Follow these steps:
  1. Log in to the
    Identity Manager
    User Console.
  2. Modify
    Synchronize User with Roles
    admin task to configure properties that let you add missing accounts and remove extra accounts on endpoints.
    1. Navigate to
      Roles and Tasks
      ,
      Admin Tasks
      ,
      Modify Admin Task
      .
    2. Search for
      Synchronize User with Roles
      admin task.
    3. In the
      Profile
      tab, click
      Configuration Properties
      .
    4. In the
      Task Configuration Properties
      screen, configure the following properties:
      • Remove extra accounts:
        By default, this property is set to
        false
        . Set this property to
        true
        to delete extra accounts on the endpoints.
      • Add missing accounts
        : By default, this property is set to
        false
        . Set this property to
        true
        to create missing accounts on the endpoints.
      Note:
      The values that you set for these properties here impacts the same properties that are used in Synchronize User with Roles task.
    1. Click
      OK
      .
  3. Synchronize users with roles in bulk using Bulk Loader.
    1. Navigate to
      System
      ,
      Bulk Loader
      .
    2. Upload a file (.csv). This file contains all users that must be synchronized with the provisioning roles.
      Note:
      The
      action
      column in the .csv file can have any value other than Create, Modify, and Delete.
    3. In the
      Loader Record Details
      screen, configure the following fields:
      1. What field represents the action to perform on the object?
        : Select
        action
        from the drop-down.
      2. What field will be used to uniquely identify the object?
        : Select a field from the drop-down on which an action must be performed.
      3. Click
        Next
    4. In the
      Loader Actions Mapping
      screen, configure the following fields:
      1. What is the Primary Object?
        : Select
        USER
        from the drop-down.
      2. Select a task to execute for action '<action>'
        : Select
        Synchronize User with Roles
        from the drop-down.
      3. Click
        Finish
        .

Check Role with Users Synchronization

By using
Check Role with Users Synchronization
task, an administrator can check if the provisioning role is synchronized with all its assigned users, and accordingly perform synchronize operation to ensure that users have necessary accounts on endpoints.
Few points to consider:
  • Using
    Check Role with Users Synchronization
    task, you can synchronize only one role at a time with its assigned users.
  • Check Role with Users Synchronization
    task from TEWS is not supported.
Follow these steps:
  1. Log in to the
    Identity Manager
    User Console.
  2. Navigate to
    Users
    ,
    Synchronization
    ,
    Check Role with UsersSynchronization
    .
  3. Select a role.
    A screen appears showing the missing accounts for the selected role, if any.
  4. Click
    Synchronize
    to create missing accounts on endpoints.

Synchronize Role with Users

By using
Synchronize Role with Users
task, an administrator can synchronize provisioning roles with its assigned users.
Few points to consider:
  • You can check the missing accounts for a role with Check Role with Users Synchronization task. However, this task allows you to check and synchronize only one role at a time with its assigned users.
  • In a nested roles scenario, even the included roles are considered for synchronization with users.
  • The
    Synchronize Role with Users
    task is supported only for endpoints that are reachable.
  • The
    Synchronize Role with Users
    task does not support removal of extra accounts. This is not supported because a user who is assigned to multiple provisioning roles with account templates mapped to the same endpoints lead to out-of-sync condition.
  • Synchronization of multiple provisioning roles with account templates mapped to the same endpoints fails.
  • Synchronization of multiple provisioning roles with users from TEWS is not supported.
  • To experience good performance, avoid synchronizing multiple roles at a time.
Follow these steps:
  1. Log in to the
    Identity Manager
    User Console.
  2. Navigate to
    Users
    ,
    Synchronization
    ,
    Synchronize Role with Users
    .
  3. Select a role(s) that needs to be synchronized with users.
  4. Click
    Select
    .
  5. Click
    Yes
    to confirm synchronization operation.