Skip to Content
Mar 26, 2015 at 02:08 PM

SAP IDM 8.0 Provisioning of group privilege assignments



I set up Active Directory as a target system. I imported the new packages for Eclipse and did the initial load for AD (System privileges were created).

When I assign the PRIV:AD:ONLY privilege to an identity, the identity gets provisioned to AD.

When I assign the PRIV:AD:ONLY privilege to a group, the group gets provisioned to AD.

So far so good.

But when I assign the group to the identity I get the error in the execution log:

Cannot obtain mskey for group privilege PRIV:GROUP:AD:CN\=MY AD GROUP\,CN\=GROUPS\, DC\=DUMMY\, DC\=COM

The CN represents my CN in the Active Directory, but, I have no PRIV:GROUP:AD privilege?

so I can not provision group assignments to AD and I used only the default packages with no modifications.

And an additional question, when does the RDS for 8.0 comes out?

Are there some predefined approval processes like in 7.2?

Thanks, Patrick