...
Introducation
There are various task features related to the system connectors that can be either enabled or disabled.
Identity features
The following identity functions features are supported:
Name | Description |
provisioning identities
Create / delete identities |
Create/delete identities in the CoreOne Suite. Attributes must be checked for uniqueness (locally, i.e. in the COS and in the real target system)
If enabled, identities for that target system will be calculated and created within the CoreOne Suite. | |
Provisioning identities | If enabled, identites will be provisioned to the target system. |
provisioning identity updates
Provisioning changes to identities and the associated attributes in the target system
deprovision identities
Deprovision identities in the target system
Update identities |
Updating identities and the associated attributes in the CoreOne Suite
If enabled, identites will be updated within the CoreOne Suite. | |
Provisioning identity updates | If enabled, calculated changes to identities will be provisioned to the target system. |
Deprovision identities | If enabled, identities will be deprovisioned in the target system if their life cycle has ended. |
Cleanup of inactive identities active |
Cleanup of inactive identities in the target system
Deactivates identities that did not login to the system after a certain time period. The period is configurable on the task definition. Defaults to 60 days. |
Check password changed active |
Check if password has been changed in the target system
...
Deactivates identities that did not change their password after the creation of the account within a certain time period. The period is configurable on the task definition. Defaults to 24 hours. |
Resources features
The following resource functions features are supported:
...
Name | Description |
Create/delete resources |
If enabled, managed resources for that target system will be calculated and created within the CoreOne Suite. |
Provision resources |
If enabled, managed resources will be provisioned to the target system. |
Update resources |
Update managed resource in the CoreOne Suite
If enabled, managed resources will be updated within the CoreOne Suite. |
Provisioning resource changes |
If enabled, calculated changes to managed resources |
will be provisioned to the target system. |
Deprovisioning resources |
If enabled, managed resources will be deprovisioned in the target system |
if their life cycle has ended. |
Provisioning resource allocations |
If enabled, resource allocations will be provisioned in the target system |
Deprovisioning resource allocations |
If enabled, resource allocations will be deprovisioned in the target system |
Provisioning resources-resource allocations |
If enabled, resource to resource allocations will be provisioned in the target system |
Deprovisioning resource resource allocations |
If enabled, resource to resource allocations will be deprovisioned in the target system |
Deactivate deprovision prevention for prolonged resource assignments | If enabled, deactivates the deprovision prevention for resource assignments that could be deprovisioned unintentionally. If this feature is deactivated, the resource assignment are protected from deprovisioning too early if there are other, valid resource assignments for the same resource. This feature is a preview flag for an improvement. It will be removed in a future version. In general, this feature should not be enabled. |
Cleanup features
The following cleanup functions features are supported:
Name | Description |
Is available in the expected/actual comparison log
Clean up expected/actual
Read back user account properties
Resource identity assignments Target system cleanup
Resource-resource assignments Target system cleanup
In the should-actual Log available | Log is available that tracks the expected values versus the actual results, allowing for comparison and review. |
Should be - Actually is - cleanup | Compare the expected values with the actual state and ensure necessary cleanup actions are performed to maintain system consistency. |
Read back account properties | Retrieve and verify the properties of the account to ensure they are accurately reflected in the system. |
Resource identity member target system clean up | Ensure that the resource identity member information is properly cleaned up on the target system to avoid discrepancies |
Resource resource member target system clean up | Perform the necessary cleanup of resource memberships within the target system to maintain data integrity. |