Federated Identity Management
In the context of a user provisioning system, federation means allowing one application to act on behalf of another, to create, modify or delete user accounts on target systems.
An API (application programming interface) is exposed by _PRODUCT, supporting features such as creating or deleting users on target systems, modifying user membership in security groups on target systems and modifying user attributes.
The API (application programming interface) is accessed using SOAP and includes a WSDL specification.
The _PRODUCT API (application programming interface) is particularly useful for extending meta directories to manage new types of target systems and for enabling custom-written and third-party workflow engines to complete a user provisioning operation with actual updates to target systems, rather than with instructions to a human security administrator.


