How to provision users in bulk to Active Directory Group with OIM

How to provision users in bulk into Active Directory Group with Oracle Identity Manager OIM.

Oracle Identity Manager (OIM) can integrate with Active Directory as a target system for provisioning users in Active Directory. With Oracle Identity Manager as the central Identity Management system one can manage, provision, deprovision or terminate user accounts as per the policy defined in OIM. The OIM connector for Microsoft Active Directory User Management is required for this integration. With this connector in place OIM can manage the lifecyle of user accounts in Active Directory.

There are situations where there is a need to provision hundreds of users. This is a typical scenario where one needs to bulk provision users into a Active Directory Group via OIM. (instead of provisioning users one by one manually which can be tedious and time consuming). This post deals with provisioning users to a Group in Active Directory (provisioning users to AD is a related but different use case).

Here lets assume the scenario is that AD users are managed by OIM, in other words OIM does all the provisioning operations into AD.

If OIM (Oracle Identity Manager) is provisioning users to AD then, it is assumed the (1) you have OIM connector for AD User Management already installed [refer OIM Connector Guide for Active Directory User Management] and AD exists as a Resource Object in OIM and (2) the user already exists in OIM and AD. Now you have to provision the user into the AD group - so you need to create an access policy in OIM which will have a rule to assign the AD group as provisioning operation/task. Of course this is assuming that you done the number (1) pre-requisite of having a OIM connector for AD User Management and AD exists as a Resource Object in OIM. The AD group will be assigned to the users as an entitlement. Here is good blog which provides all the steps of creating a creating such an Access Policy (the blog is for OIM 11gR PS3 11.1.2.3). The only difference between this blog and your requirement is that this blog gives an example of LDAP group in OUD, whereas your requirement is that of a Group in AD.


Make sure you have the two pre-requisites (1), (2), already in place as given above. The Access Policy will be applied to users as defined above (so it could be thousands of users that can be provisioned into an AD Group). Same steps would apply for any other target Directory, such as OID or OUD.

Comments

Post a Comment

Popular posts from this blog

VMware fix for Invalid manifest and ova file import failed errors

Session Timeout in Oracle Access Manager

SOAPUI - import certificate