<div dir="ltr"><div>Hi Ivan</div><div><br></div><div>I've attached my configs:</div><div>Resource: AD Resource</div><div>Role: Rbac Role - SOC - Sec</div><div>Role: Metarole AD Group</div><div>Role: gs_snow_sec_soc</div><div>Role: gs_jira_sec_soc</div><div>Role: gs_spo_sec_soc</div><div><br></div><div><span class="gmail-tlid-translation gmail-translation" lang="en"><span title="" class="gmail-">I checked the mapping and there is only one field like strong in my Resource - AD:</span></span></div><div><span class="gmail-tlid-translation gmail-translation" lang="en"><span title="" class="gmail-"><attribute id="18"><br> <c:ref xmlns:ri="<a href="http://midpoint.evolveum.com/xml/ns/public/resource/instance-3">http://midpoint.evolveum.com/xml/ns/public/resource/instance-3</a>">ri:description</c:ref><br> <outbound><br> <strength>strong</strength><br> <source><br> <c:path>description</c:path><br> </source><br> </outbound><br> <inbound id="20"><br> <target><br> <c:path>description</c:path><br> </target><br> </inbound><br> </attribute></span></span></div><div><br></div><div>Best Regards</div><div><br></div><div>Gus<br></div><div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">Em seg., 22 de jun. de 2020 às 08:29, Ivan Noris <<a href="mailto:ivan.noris@evolveum.com">ivan.noris@evolveum.com</a>> escreveu:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div>
<p>Hi Gus,</p>
<p>I don't know if you are referring to a specific sample, e.g. for
the metarole.</p>
<p>Sharing it would be helpful.</p>
<p>So far my only idea is to check if the (2nd order) mapping for
association has strong strength.</p>
<p>Best regards,</p>
<p>Ivan<br>
</p>
<div>On 22. 6. 2020 1:18, Gus Lou wrote:<br>
</div>
<blockquote type="cite">
<div dir="ltr"><span lang="en">Hi Guys<br>
I need the permissions of users assigned to a Role (Rbac role
named "Sec - SOC") to be updated after adding a new group
(gs_spo_sec_soc) to this Role.<br>
After adding the group to the role, I ran a recompute task, I
expected the new group to be added to users but it didn't. If
I add a new user to the role he receives all groups.<br>
<br>
Did I do something wrong, did any steps miss?<br>
<br>
I followed the instructions on the wiki:<br>
<a href="https://wiki.evolveum.com/display/midPoint/Recompute+Task" target="_blank">https://wiki.evolveum.com/display/midPoint/Recompute+Task</a><br>
<br>
And also in this thread:<br>
<a href="https://lists.evolveum.com/pipermail/midpoint/2014-November/000639.html" target="_blank">https://lists.evolveum.com/pipermail/midpoint/2014-November/000639.html</a><br>
<br>
<b>My Lab</b><br>
01 Midpoint 4.1<br>
01 Active Directory (Connector Ldap / AD 3.0) Resource<br>
01 Metarole: "Metarole for groups - AD" (inducement to Active
Directory (LDAP) Resource<br>
03 Groups (gs_snow_sec_soc, gs_jira_sec_soc, gs_spo_sec_soc)
assigned to Metarole<br>
</span>
<div><span lang="en">01 Rbac Role "Sec - SOC" inducements
(gs_snow_sec_soc, gs_jira_sec_soc, gs_spo_sec_soc) <br>
</span></div>
<div><span lang="en"><br>
</span></div>
<div><span lang="en"><br>
</span></div>
<div><span lang="en">Best Regards</span></div>
<div><span lang="en">Gus<br>
</span></div>
<div><span lang="en"><br>
</span></div>
</div>
<br>
<fieldset></fieldset>
<pre>_______________________________________________
midPoint mailing list
<a href="mailto:midPoint@lists.evolveum.com" target="_blank">midPoint@lists.evolveum.com</a>
<a href="https://lists.evolveum.com/mailman/listinfo/midpoint" target="_blank">https://lists.evolveum.com/mailman/listinfo/midpoint</a>
</pre>
</blockquote>
<pre cols="72">--
Ivan Noris
Senior Identity Engineer
<a href="http://evolveum.com" target="_blank">evolveum.com</a>
</pre>
</div>
_______________________________________________<br>
midPoint mailing list<br>
<a href="mailto:midPoint@lists.evolveum.com" target="_blank">midPoint@lists.evolveum.com</a><br>
<a href="https://lists.evolveum.com/mailman/listinfo/midpoint" rel="noreferrer" target="_blank">https://lists.evolveum.com/mailman/listinfo/midpoint</a><br>
</blockquote></div>