[midPoint] Sync Virtual Identities and AD Groups using roles

m.benucci m.benucci at nsr.it
Mon Dec 12 16:57:19 CET 2016


Hi,

I have imported users from an Active Directory and 

I have successfully synchronized AD groups with midPoint roles using a metarole.

Provisioning and Synchronization seems to works well.

  

Now, given a midPoint Role (an AD entitlement),  I would like to know if is possible to know who is assigned to this role (e.g. I would like to know from midPoint who is assigned to the role/entitlement "Domain Admin").

  

I suppose I necessarily need to assign the role to an user to see if he is a member of it, is there a way to automate this assignment process?

  

  

Thank you.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20161212/00e28a6b/attachment.htm>


More information about the midPoint mailing list