Resources
Here you will find different settings to define resource, resource types, and resource folders.
Add resource types
- To add a new resource type, click New in the Resource types overview.
- In the New Resource dialog box that opens, type a unique Name for the resource type.
- From the drop-down menu, select a relevant Resource category to associate with the new resource type.
- If you want to allow the assignments for the resources of the created type to have additional attributes, check the Allow attributes checkbox.
- In the Attribute set field, click the lookup icon to open the Attribute set dialog. From this dialog box, choose an attribute set to associate with the new resource type.
- The Business key field allows you to add a business key for the created resource type.
- Optionally, in the New Resource dialog box, select the Allow child resources checkbox to allow resources that do not belong to the role resource category to be able to specify child resources.
- Enable the Allow delegation setting to allow identities with this resource to delegate their access to another identity for a limited period of time, for example when the identity is on vacation or in the case of a leave of absence.
Add resource types: Fulfillment (general)
-
In the Provisioning attribute set field, click the lookup icon to select an attribute set that has provisioning relevance. The attributes are also presented to the sync engine as a bundle. If you do not select any attribute sets here, all assignment attributes are considered relevant to provisioning.
-
Select the Reconcile on attribute level checkbox to enable provisioning updates in case of any discrepancies in the provisioning attributes in the Omada Identity Data Warehouse. The checkbox is not selected by default.
-
Select the Reconcile account name checkbox to enforce the account name reconciliation during provisioning updates.
limitations- This feature is dependent on the target system supporting account renaming and ensuring that the account name is appropriately mapped in OPS for correctly performed import.
- If, for example, the account name is used as the lookup key in the connector, renaming the account is not possible since the existing account in the target system retains the old account name and cannot be found using the new account name.
- The account name cannot be directly mapped in the reconciliation map.
- Additionally, for technical identities, their actual and desired state accounts are not covered by this feature and they are linked based on the account name, rather than the account type, unlike normal identities.
- This feature is dependent on the target system supporting account renaming and ensuring that the account name is appropriately mapped in OPS for correctly performed import.
-
In the Reconciliation attributes map field provide a mapping string used by RoPE when account assignment attributes or permission assignment attributes are loaded from the Data Warehouse. This mapping string maps ES/RoPE attribute names to Data Warehouse attribute names. If a resource type specifies an attribute string, RoPE only looks for the mapped attributes in the ODW. If a resource type does not specify an attribute string, RoPE assumes that all provisioning attributes are present in the ODW and have the same names as in Enterprise Server.
The mapping string has the following format:
[Attribute system name in ES/RoPE]=[Attribute name in Data Warehouse];...
. It is case sensitive and cannot contain duplicate attribute names; neither ES/RoPE attribute names nor Data Warehouse attribute names, for example,FirstName=givenName;LastName=sn
. -
Select the Exclusively managed checkbox to make assignments for the resources to be deprovisioned if they do not have a Desired state reason. The checkbox is not selected by default.
-
In the Post-validity days field, type a number of days in which the assignments calculated for resources of this type are included after the validity period ends. The extension of the validity is intended only to extend the validity period of an identity (as it was designed for identity onboarding and offboarding). In the case of other objects, the object is kept in the calculation for the duration of the post-validity, and it is maintained in the disabled state.
Add resource types: Fulfillment (MIM)
This section is relevant only for systems configured for using MIM as fulfillment mechanism.
- In the MIM MA CS resource object type field, type the name of a resource object to show calculated resources in the MA as objects of this type.
- In the MIM MA CS assignment object type field, type the name of an assignment object type to show calculated accounts and calculated resource assignments in the MA as objects of this type.
- Select the checkbox Make members/membership information available in the sync engine? to enable that the sync engine receives information about the accounts that are members of the resource (if the resource is a non-account) or the resources that the account is a member of (if the resource is an account).