next up previous contents index
Next: 14.9 Managing inventory Up: 14. Configuring Workflow Previous: 14.7 Defining request attributes   Contents   Index

Subsections

14.8 Managing account groups

ID-Synch uses account groups to configure ways to manage membership of corresponding groups on the following target systems:

The nightly update process can discover all available groups on a target system (e.g. Domain Users Group on Windows 2000), listing them in TARGETID.GRP files and loading them into the NOSGROUP table. After you configure ID-Synch to manage account groups using the Workflow configuration menu in the Central console (nph-psa.exe):

ID-Synch's account group management facility offers a more efficient and flexible way to manage account group membership than by mapping request attributes to target attributes.

Note:
The two methods are incompatible. If you map request attributes to target attributes, and group membership is changed using the Manage groups button in the New account request module (nph-idr.exe) or Account management console (nph-ida.exe), then the list created by mapping attributes will not be updated, and will become unsynchronized with group membership.

 

Membership of account groups can be:

Open
any user can be added or removed
Moderated
users can be added or removed if approved by an authorizer
Open to members of another group
users can be added or removed only if they belong to another managed group on the same or another target system

It is possible to set differing permissions for adding and removing users from groups. For example, a user may need authorization to join a group, and be removed without requiring authorization.


14.8.1 Setting up group management

To manage account groups on a target system:

  1. On the Workflow configuration menu click Account groups.

  2. Click Update next to the target system on which you want to manage account groups.

    ID-Synch displays a list of available groups for the target system, indicating which groups are currently managed.

  3. Click Update next to the group you want to manage.

    ID-Synch displays the Account groups management information page.

  4. Optional: Select a Location for the account group.

  5. Optional: Select a Type for the account group.

  6. Select Add type to determine how users can be added to the group.

  7. Select Remove type to determine how users can be removed from the group.

  8. If you selected Open to members of another group for Add/Remove type:

  9. Click Manage.

  10. If you selected Moderated for Add/Remove type, click Add.

    ID-Synch displays the Specify authorizer search criteria or Select an authorizer page. You must have authorizers defined to complete this procedure.

  11. Select the authorizer that you want to moderate the group, and click Select.

  12. Add more authorizers if required.

See also: Filtering account or groups available to users


next up previous contents index
Next: 14.9 Managing inventory Up: 14. Configuring Workflow Previous: 14.7 Defining request attributes   Contents   Index

  ID-Synch™ is an access management solution developed by M-Tech.

The full current version of this guide, shipped with the ID-Synch software, contains detailed reference information not included in this version.