Symantec IGA

  • 1.  Unmanaged endpoints in CA Identity Portal 12.6.7

    Posted Jul 14, 2017 08:40 AM

    The customer is asking to have unmanaged resources, that is entitlements do appear on the profile of digital identity, especially for certification purposes, but on which no provisioning or reconciliation should be made. At first we thought of a multi-value attribute on the user profile to store those entitlements but then it is possible to made a review on that attribute values? Can you give us a better approach?



  • 2.  Re: Unmanaged endpoints in CA Identity Portal 12.6.7
    Best Answer

    Broadcom Employee
    Posted Jul 18, 2017 03:09 AM

    If IM is integrated with IG I would recommend using Provisioning Roles, with no attached account templates. This would make them look like fully managed roles and can be utilized in the same manner as managed roles, but with no provisioning action taking place.

    In IG they would appear as roles. They can also be automatically deprovisioned, and an implantation workflow can be put in place to trace the removal of the role