This article describes how to synchronize inactive users via LDAP connection to Smart ID Identity Manager (there is also a use case to Synchronize active LDAP users to Identity Manager). Existing users in Identity Manager will be updated. The tool used to set up the synchronization is Identity Manager Admin. The batch synchronization can also be started manually from Identity Manager Operator. Read more here: section "View status of batch job" in Set up scheduled jobs in Identity Manager.
Step-by-step instruction for the administrator
Log in to Identity Manager Admin
- Log in to Identity Manager Admin with your administrator account.
Schedule the synchronization
To set up scheduling of the synchronization:
- In Identity Manager Admin, go to Home > Batch Synchronization.
- Select Synchronize inactive LDAP Users to Identity Manager.
- To adjust the scheduler, type the appropriate cron expression in Expression to schedule the job.
- Click Save.
Use case details
Overview and technical details
Use case description | As an administrator I want to sync inactive users via LDAP connection to Identity Manager
|
---|
Outcome | - User is created in Identity Manager if the user does not exist
- End state for user = "inactive"
- End state for related credentials = "inactive"/"locked", see details below
- End state for related certificates = "on hold"/"revoked", see details below
- The relation from user to credentials still exists
- All roles for the user are withdrawn
Related credentials | Credentials - end state | Certificates - end state |
---|
Card and related certificates | inactive | on hold | Temporary card and related certificates | locked | revoked | Virtual smart card and related certificates | inactive | on hold | Mobile ID and related certificates | inactive | on hold | Soft token and related certificates | inactive | on hold |
|
---|
Symbolic name | UsersAddonLDAPBatchSyncSynchronizeActiveLDAPUsersToIDMUsers
|
---|
Process name | Synchronize inactive LDAP Users to Identity Manager
|
---|
Component | Identity Manager Admin |
---|
Process start | Batch synchronization |
---|
Executable for | Administrator |
---|
Options
There are no options for this use case.