<div dir="ltr">Quick question, I am assuming you are using the AD-LDAP connector (ri:memberOf), does inbound work during live sync or just during reconcile?<div><br></div><div>Thanks!</div><div>JASONĀ </div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><br></div></div></div>
<br><div class="gmail_quote">On Tue, Dec 20, 2016 at 4:10 AM, Marco Benucci <span dir="ltr"><<a href="mailto:m.benucci@nsr.it" target="_blank">m.benucci@nsr.it</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div bgcolor="#FFFFFF" text="#000000">
<p><font face="DejaVu Sans">I have successfully aligned AD
entitlement on midpoint users using a 2 step approach.<br>
<br>
<br>
Firstly I have made an inbound mapping of the attribute memberOf
in an extension and multivalue attribute.<br>
<br>
Then, with an object template I have used the
assignmentTargetSearch to assign midpoint roles (my AD
entitlement) to the user based on the attribute mentioned above.
I thought it could be possible to use the assignmentTargetSearch
even in inbound mapping on the resource, but </font>I did not
tested it.<br>
<br>
Thank you,<br>
Marco<br>
</p>
</div>
<br>______________________________<wbr>_________________<br>
midPoint mailing list<br>
<a href="mailto:midPoint@lists.evolveum.com">midPoint@lists.evolveum.com</a><br>
<a href="http://lists.evolveum.com/mailman/listinfo/midpoint" rel="noreferrer" target="_blank">http://lists.evolveum.com/<wbr>mailman/listinfo/midpoint</a><br>
<br></blockquote></div><br></div></div>