on 02-15-2017 2:18 PM
Hi,
I am trying to create a Dynamic Group in SAP IDM based on the Active Directory group. The issue I have is I dont see any users assigned to the Dynamic group based on the membership for AD Group. I have followed the steps as in one of the threads and still not able to get the users assigned to dynamic group. Please let me know whats the missing piece is?
Please see below steps for my config:
Hello Pavan,
I just wrote a blog on SAP IDM Dynamic Group. Hope it will helpful to resolve your issue.
Regards,
C Kumar
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hello Pavan,
If the issue raised in this thread has been fixed then please close the thread by marking/updating the correct answer.
For any new issue, please open a new thread with proper details and supporting screenshots.
Regards,
C Kumar
Hello Pavan,
is ID store No.1 really your used store?
Did your SQL statement return results when you tried it directly in the database via SQL developer or similar tools?
Also: If I read your query correctly, you look for the mskey of the AD group, not the mskeys of its members...
You have to change your query to look for the members of that group (try idmv_vallink_basic).
.
Regards,
Steffi.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Steffi, Thanks for the response. I have verified the SQL statement and it does get me the mckey for the groups. And my ID store is 1. I think you are right on that the query should look for members of group but I am sorry not sure how to create a dynamic group to look for members of the group. Please clarify if you referred to the query in the resolve dynamic group source or in the target definition of the Dynamic group.
Please help me with the query if you could. Appreciate the advice.
Hello Pavan,
I was talking about the target filter of the dynamic group itself.
You should create its SQL query in the SQL developer (looks like you are on Oracle) and if you get the correct results there, transfer it to the dynamic group target filter. That's easier IMO, because then you know which attributes you need.
Like I wrote in my last reply: Have a look at the view "idmv_vallink_basic". Select for one mskey of one of the AD groups and look at the attributes and searchvalues you get. Then go from there.
.
Regards,
Steffi.
Hello Pavan,
Steffi is right, please modify your SQL query and run it in SQL developer (for Oracle) first and verify that it is returning the correct results.
Please also focus on following points while writing target filter for Dynamic Group
Regards,
C Kumar
User | Count |
---|---|
83 | |
10 | |
10 | |
9 | |
7 | |
6 | |
5 | |
5 | |
4 | |
4 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.