Provisioning Roles & Identity Policy

Question asked by diwakarshenoy on Jun 12, 2012
Latest reply on Jun 28, 2012 by diwakarshenoy
Hi All,
Has anyone encountered issues when trying to automate the process of assigning users to provisioning roles via Identity policies? I have a requirement on my project to automatically provision users to various target systems. I have created a custom attribute User Type and a provisioning role to achieve this. If User Type is Employee then I assign an employee provisioning role, if it is Contractor then I assign the contractor Provisioning role.

When creating user i set the User Type as employee / contractor. It is working fine when i create the user and it assigns to the right provisionign role, but when i update the user's user type attribute from employee to contractor or vice-versa, It does not update the provisioning role. I see the following error in the CAIM server console:
Global User xyz modification failed: Attribute 'eTIMEnabledState' cannot be modified in same request with incompatible changes ]; remaining name 'eTGlobalUserName=xyz,eTGlobalUserContainerName=Global Users,eTNamespaceName=CommonObjects,dc=im,dc=eta'

Any pointers to resolve this issue will be great.