[midPoint] [Question] Best practice for versatile and selective Role provisioning to multiple target services (GitHub, Box, etc.)
Frost K
kfrost3217058 at gmail.com
Tue Jun 9 08:53:48 CEST 2026
Dear midPoint community,
Hi, I'm Frost at a Japanese tech company in Japan.
We would like to clarify the best practice for synchronizing/provisioning
midPoint Roles using connectors to several services separately.
Each target service (e.g., GitHub, Box) has different configurations and
schemas.
When having over 2 connectors, what we'd like to do is..
・Associate Role "Git A" to organization "A" on GitHub, and never associate
it to Box.
・Associate Role "Box B" to Group "A" on Box, and never associate it to
GitHub
As we discussed how we achieve this solution, we would need to take these
three steps below.
1: label roles
2: join them into some groups
3: filtering each role using group name to associate them to each target
service.
(Role "Git A" to organization "A" on "GitHub", Role "Box B" to Group "A"
on "Box", etc)
Question:
Are there any simple and versatile way to manage system, even when we need
to use some new services such as "GCP" and "Entra"?
We'd like to know the best practice.
Regards,
Frost
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20260609/045c121f/attachment.htm>
More information about the midPoint
mailing list