<div dir="ltr"><p>Dear midPoint community,</p><p>Hi, I'm Frost at a Japanese tech company in Japan.</p><p> </p><p>We would like to clarify the best practice for synchronizing/provisioning midPoint Roles using connectors to several services separately.</p><p>Each target service (e.g., GitHub, Box) has different configurations and schemas.<br><br><br></p><p>
When having over 2 connectors, what we'd like to do is..</p><p> ・Associate Role "Git A" to organization "A" on GitHub, and never associate it to Box.</p><p>
・Associate Role "Box B" to Group "A" on Box, and never associate it to GitHub</p><p> </p><p>As we discussed how we achieve this solution, we would need to take these three steps below.</p><p> </p><p>1: label roles<br>
2: join them into some groups<br>
3: filtering each role using group name to associate them to each target service.<br>
   (Role "Git A" to organization "A" on "GitHub", Role "Box B" to Group "A" on "Box", etc)</p><p> </p><p>Question:</p><p> </p><p>Are there any simple and versatile way to manage system, even when we need to use some new services such as "GCP" and "Entra"?</p><p>We'd like to know the best practice.</p><p><br></p><p>Regards,</p><p>Frost</p></div>