Quantcast
Channel: SCN: Message List
Viewing all articles
Browse latest Browse all 8451

Re: Remove all AD groups from a user

$
0
0

We usually use a batch job with a ToIdentityStore pass for this.

 

Source tab: depending on the process either a request object or the valid date (or whatever) is used to determine when all users which shall be processed on each day (scheduled nightly if time dependent or called using uRunJobNow if prcessed on the same day)

 

Destination: All PRIV:GROUP's of the users are selected with a {D} using a script (plus any other privileges like Java or SAP or ...)

Additionally we use our own plugins to handle the deprovisioning.

 

If you are not syncing all groups, use batch job with a FromLDAP and a filter on all users which shall be deprovisioned or re-calling the job (using two jobs alternatively)


Viewing all articles
Browse latest Browse all 8451

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>