OneIM SQLServerDatabasesConnector UserGuide
OneIM SQLServerDatabasesConnector UserGuide
One Identity Manager Native Database Connector User Guide for Connecting SQL Server Databases
Updated - January 2020
Version - 8.1.2
Contents
Error handling 34
About us 35
Contacting us 35
Technical support resources 35
Index 36
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases
3
1
Using this native database connector, you can synchronize external databases with the One
Identity Manager database. One Identity Manager supports connecting to SQL Server
databases, amongst others. The native database connector can therefore also be used to
synchronize One Identity Manager databases with different product versions or modules.
The native database connector cannot load any random external database system data
configuration. For example, custom data types and columns containing value list are not
currently supported.
The native database connection does not provide a project template for setting up
synchronization. You must create synchronization configuration components
(mappings, workflows, start up configurations ...) manually after the synchronization
project has been saved.
In the Synchronization Editor, external database tables and columns are referenced as
schema types and schema properties.
1. Install and configure a synchronization server and declare the server as Job server in
One Identity Manager.
2. Provide One Identity Manager users with the required permissions for setting up
synchronization and post-processing of synchronization objects.
3. Create a synchronization project with the Synchronization Editor.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 4
Native database connector for SQL Server databases
Users and permissions for
synchronizing
In the synchronization with the database connectors, there are three use cases for mapping
synchronization objects in the One Identity Manager data model.
In the case of non-role-based login to One Identity Manager tools, it is sufficient to add one
system user in the DPR_EditRights_Methods permissions group. For detailed
information about system users and permissions groups, see the One Identity Manager
Authorization and Authentication Guide.
User Tasks
There are different steps required for role-based login, in order to equip One Identity
Manager users with the required permissions for setting up synchronization and post-
processing of synchronization objects.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 5
Native database connector for SQL Server databases
Table 2: User and permissions groups for role-based login: Mapped as custom
target system
User Tasks
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 6
Native database connector for SQL Server databases
User Tasks
Table 3: User and permissions groups for role-based login: Mapped as default
tables
User Tasks
Table 4: Users and permissions groups for role-based login: Mapped in custom
tables
User Tasks
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 7
Native database connector for SQL Server databases
User Tasks
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 8
Native database connector for SQL Server databases
Detailed information about this topic
1. In the Manager, select the default application role to use to edit the objects you want
to synchronization.
l Establish the application role's default permissions group.
If you want to import employee data, for example, select the Identity
Management | Employees | Administrators application role. The default
permissions group of this application role is vi_4_PERSONADMIN.
2. In the Designer, create a new permissions group.
l Set the Only use for role based authentication option.
3. Make the new permissions group dependent on the vi_4_SYNCPROJECT_ADMIN
permissions group.
The vi_4_SYNCPROJECT_ADMIN permissions groups must be assigned as the parent
permissions group. This means that the new permissions group inherits the
properties.
4. Make the new permissions group dependent on the default permissions group of the
selected default application role.
The default permissions group must be assigned as a subgroup. This means that the
new permissions group inherits the properties.
5. Save the changes.
6. In the Manager, create a new application role.
a. Assign the selected application role to be the parent application role.
b. Assign the new permissions group.
7. Assign employees to this application role.
8. Save the changes.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 9
Native database connector for SQL Server databases
To set up an application role for synchronization (use case 3):
1. In the Designer, create a new permissions group for custom tables, which are
populated though synchronization.
l Set the Only use for role based authentication option.
2. Guarantee this permissions group all the required permissions to the custom tables.
3. Create another permissions group for synchronization.
l Set the Only use for role based authentication option.
4. Make the permissions group for synchronization dependent on the permissions group
for custom tables.
The permissions group for custom tables must be assigned as parent permissions
group. This means the permissions groups for synchronization inherits its properties.
5. Make the permissions group for synchronization dependent on the vi_4_
SYNCPROJECT_ADMIN permissions group.
The vi_4_SYNCPROJECT_ADMIN permissions groups must be assigned as the parent
permissions group. This means the permissions groups for synchronization inherits
its properties.
6. Save the changes.
7. In the Manager, create a new application role.
a. Assign the Custom | Managers application role as the parent
application role.
b. Assign the permissions group for the synchronization.
8. Assign employees to this application role.
9. Save the changes.
For detailed information about setting up application roles and permissions groups, see the
One Identity Manager Authorization and Authentication Guide.
The synchronization server must be declared as a Job server in One Identity Manager.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 10
Native database connector for SQL Server databases
Use the One Identity Manager Service to install the Server Installer. The program executes
the following steps:
NOTE: To generate processes for the Job server, you need the provider, connection
parameters, and the authentication data. In the default case, this information is determ-
ined from the database connection data. If the Job server runs through an application
server, you must configure extra connection data in the Designer. For detailed inform-
ation about setting up Job servers, see the One Identity Manager Configuration Guide.
NOTE: The program executes remote installation of the One Identity Manager Service.
Local installation of the service is not possible with this program. Remote installation is
only supported within a domain or a trusted domain.
To remotely install the One Identity Manager Service, you must have an
administrative workstation on which the One Identity Manager components are
installed. For detailed information about installing a workstation, see the One Identity
Manager Installation Guide.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 11
Native database connector for SQL Server databases
NOTE: You can use the Extended option to make changes to other properties
for the Job server. You can also edit the properties later with the Designer.
4. On the Machine roles page, select Job server.
5. On the Server functions page, select Native database connector.
6. On the Service Settings page, enter the connection data and check the One Identity
Manager Service configuration.
NOTE: The initial service configuration is predefined already. If further changes
need to be made to the configuration, you can do this later with the Designer. For
detailed information about configuring the service, see the One Identity Manager
Configuration Guide.
l For a direct connection to the database:
a. Select Process collection | sqlprovider.
b. Click the Connection parameter entry, then click the Edit button.
c. Enter the connection data for the One Identity Manager database.
l For a connection to the application server:
a. Select Process collection, click the Insert button and select
AppServerJobProvider.
b. Click the Connection parameter entry, then click the Edit button.
c. Enter the connection data for the application server.
d. Click the Authentication data entry and click the Edit button.
e. Select the authentication module. Depending on the authentication
module, other data may be required, for example, user and password.
For detailed information about the One Identity Manager authentication
modules, see the One Identity Manager Authorization and
Authentication Guide.
7. To configure remote installations, click Next.
8. Confirm the security prompt with Yes.
9. On the Select installation source page, select the directory with the install files.
10. On the Select private key file page, select the file with the private key.
NOTE: This page is only displayed when the database is encrypted.
11. On the Service access page, enter the service's installation data.
l Computer: Name or IP address of the server that the service is installed and
started on.
l Service account: User account data for the One Identity Manager Service.
l To start the service under the NT AUTHORITY\SYSTEM account, set
the Local system account option.
l To start the service under another account, disable the Local system
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 12
Native database connector for SQL Server databases
account option and enter the user account, password and password
confirmation.
l Installation account: Data for the administrative user account to install
the service.
l To use the current user’s account, set the Current user option.
l To user another user account, disable the Current user option and enter
the user account, password and password confirmation.
l To change the install directory, names, display names or description of the One
Identity Manager Service, use the other options.
12. Click Next to start installing the service.
Installation of the service occurs automatically and may take some time.
13. Click Finish on the last page of the Server Installer.
NOTE: In a default installation, the service is entered in the server’s service
management with the name One Identity Manager Service.
l If the two databases have different One Identity Manager versions, the database with
the earlier version must be connected as the target system. This means that
synchronization is configured on the database with the newer version.
l To have write access to the target system database, this database must
l Be connected through an application server
l Have at least Version 7.0.
l For data changes in the target system database, the REST API of the application
server is used. The HTTP request methods POST, GET, PUT and DELETE must be
permitted by the application server’s web server.
l The following applies for encrypted databases:
l Both databases to be synchronized use the same private key.
l The encrypted data is transmitted in encrypted form during synchronization.
The data is not decrypted in this process.
l The following applies to synchronizing in the Target system direction:
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 13
Native database connector for SQL Server databases
Objects that are only in the target system database cannot be marked as outstanding
in the target system. The MarkAsOutstanding processing method is not available for
the synchronization steps.
Data Explanation
Synchronization All One Identity Manager Service actions are executed against
server the target system environment on the synchronization server.
Data entries required for synchronization and administration
with the One Identity Manager database are processed by the
synchronization server.
Installed components:
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 14
Native database connector for SQL Server databases
Data Explanation
Base object You cannot normally specify a base object for synchronizing with
database connectors. In this case, assignment of one base table
and the synchronization server is sufficient.
l Select the Base table from the menu in which to load the
objects. The base table can be used to defined
downstream processes for synchronization. For more
information about downstream processes, see the One
Identity Manager Target System Synchronization
Reference Guide.
l The Synchronization servers menu displays all Job
servers for which the Native database connector
server function is activated.
Variable set If you implement specialized variable sets, ensure that the start
up configuration and the base object use the same variable set.
2. Add mappings. Define property mapping rules and object matching rules.
3. Create synchronization workflows.
4. Create a start up configuration.
5. Define the synchronization scope.
6. Specify the base object of the synchronization.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 15
Native database connector for SQL Server databases
7. Specify the extent of the synchronization log.
8. Run a consistency check.
9. Activate the synchronization project.
10. Save the new synchronization project in the database.
If you execute the project wizard in expert mode or directly from Synchronization Editor,
additional configuration settings can be made. Follow the project wizard instructions
through these steps.
1. Start the Launchpad and log on to the One Identity Manager database.
NOTE: If synchronization is executed by an application server, connect the
database through the application server.
3. On the System access page, specify how One Identity Manager can access the
target system.
l If access is possible from the workstation on which you started
Synchronization Editor, you do not need to make any settings.
l If access is not possible from the workstation on which you started
Synchronization Editor, you can set up a remote connection.
Enable the Connect using remote connection server option and select the
server to be used for the connection under Job server.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 16
Native database connector for SQL Server databases
external database.
4. Select the database system to which you want to connect on the Select database
system page.
l Select SQL Server.
5. Configure the system connection.
For more information, see Connecting a system to an SQL Server database on
page 18.
6. You can save the current configuration as a template on the Save configuration
page. When you reconnect to a database system of the same type, you can use this
configuration as a template.
l Click and enter the name and repository of the configuration file.
7. You can save the connection data on the last page of the system connection wizard.
l Set the Save connection locally option to save the connection data. This can
be reused when you set up other synchronization projects.
l Click Finish, to end the system connection wizard and return to the
project wizard.
8. On the One Identity Manager Connection tab, test the data for connecting to the
One Identity Manager database. The data is loaded from the connected database.
Reenter the password.
NOTE: If you use an unencrypted One Identity Manager database and have not
yet saved any synchronization projects to the database, you need to enter all
connection data again. This page is not shown if a synchronization project
already exists.
9. The wizard loads the target system schema. This may take a few minutes depending
on the type of target system access and the size of the target system.
10. Select a project template on the Select project template page to use for setting up
the synchronization configuration.
NOTE: The native database connector does not provide a default project template
for setting up synchronization. If you have created your own project template, you
can select it to configure the synchronization project. Otherwise, select Create
blank project.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 17
Native database connector for SQL Server databases
11. Enter the general setting for the synchronization project under General.
Property Description
Script Language in which the scripts for this synchronization project are
language written.
Scripts are implemented at various points in the synchronization
configuration. Specify the script language when you set up an empty
project.
IMPORTANT: You cannot change the script language once the
synchronization project has been saved.
If you use a project template, the template's script language is
used.
Data Explanation
User and password User account and password used by the native database
connector to log in to the external database. Make a user
account available with sufficient permissions.
URL Web address for the application server if a One Identity Manager
database is to be connected as the target system
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 18
Native database connector for SQL Server databases
Data Explanation
1. Enter the connection parameters on the Database connection page. Enter all the
parameters required by the database connector to create a connection with the
selected database system.
l To enter additional system-specific information about the system connection,
click Advanced.
The database system connection is tested the moment you click Next.
2. Enter a display name and a unique identifier for the database connection on the
Describe the database page.
Property Description
Display name of Display name of the database for display in the One Identity
database Manager tools.
3. You can enter a file on the Load configuration page from which the connection
configuration can be loaded. This data is used in subsequent steps in the connection
wizard and can be modified there.
4. Select the time zone for the time zone data in the database on the page, Time zone
selection. The time zone is required to convert the time saved in the database into
the local time. The local time is displayed in the One Identity Manager tools.
5. You can specify additional connection settings on the Initializing page. Write a
script in the database syntax to specify number and date formats, language, and
data sort order, for example. This script is then executed every time you
connect the system.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 19
Native database connector for SQL Server databases
6. On the Select partial schemas page, you can reduce the database schema by
selecting partial schemas. If the database contains several schema, specify here,
which schemas are loaded into the synchronization project.
l Enable all the schemas to process in the Partial schemas/owner list.
7. The database schema is loaded on the Schema detection page. during which One
Identity Manager tries to identify a known schema.
l If a One Identity Manager schema is detected, the Fill in system
description completely option is displayed. If you only want allow read-only
access to the database, you can deactivate this option.
If the schema is loaded successfully, the next step in the sequence can be
carried out.
8. The Configure system access page opens when you enable the Fill in system
description completely option on the Load schema page. Enter the connection
data for the application server of the target system database.
Property Description
Property Description
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 20
Native database connector for SQL Server databases
Property Description
Property Description
Key name Column group identifier. Permitted characters are letters and
underscore. A virtual schema property is formed from the column
group with the name vrtColumnGroup<column group>.
Columns Columns included in the column group. Mark all the columns that
together make up the unique key.
b. You can enter information about object relations in the Define data
relations page.
Property Description
Target(s) Columns to which the reference refers. Enter table and column
names in the following syntax: [<schema>].<table
name>.<column name>. If a reference points to several column,
enter the targets in a comma delimited list. The target
columns must be labeled as key columns.
TIP: You can copy the column name of a referenced column
using the Copy fully qualified column names item in the
context menu and add this as a target.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 21
Native database connector for SQL Server databases
c. You can enter additional schema information on the Complete schema page.
Property Description
Sort criteria Specifies whether the value in this column represents the path
for in an object hierarchy. If this table’s objects are sorted by this
hierarchies column, it results in a list sorted in hierarchical order. This
makes it possible to resolve object dependencies. Only one
column per table can be marked as a sort criterion. An
example is the CanonicalName column.
Property Description
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 22
Native database connector for SQL Server databases
10. You can specify special operations for changing data in the external database on the
Define data operations page. This is only required, if the default operations
INSERT, UPDATE and DELETE cannot be used in the external database system.
Property Description
Strategy Description
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 23
Native database connector for SQL Server databases
Property Description
11. The Extend target system schema page opens if you enable the Fill in system
description completely option on the Load schema page or make settings on the
Define data operations page. You can add virtual schema properties to the target
system schema here. Use the virtual schema properties to provide additional data
for your own DML handling.
Property Description
Hide Specifies whether table are hidden if no settings have been changed.
unconfigured
tables
Schema Tables in the target system schema for which virtual schema proper-
ties can be added or exist already.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 24
Native database connector for SQL Server databases
Property Description
field
12. The Extend target system schema page opens if you enable the Fill in system
description completely option on the Load schema page or make settings on the
Define data operations page. You can add virtual schema properties to the target
system schema here. Use the virtual schema properties to provide additional data
for your own DML handling.
Property Description
Hide Specifies whether table are hidden if no settings have been changed.
unconfigured
tables
Schema Tables in the target system schema for which virtual schema proper-
ties can be or are created
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 25
Native database connector for SQL Server databases
To edit or delete a virtual schema property
a. In the Schema column, open the node of the table with the schema properties
that you want to edit or delete.
b. Click Edit or remove.
c. Edit the properties of the virtual schema property.
- OR -
Click Delete.
Related topics
Updating schemas
All the schema data (schema types and schema properties) of the target system schema
and the One Identity Manager schema are available when you are editing a
synchronization project. Only a part of this data is really needed for configuring
synchronization. If a synchronization project is finished, the schema is compressed to
remove unnecessary data from the synchronization project. This can speed up loading the
synchronization project. Deleted schema data can be added to the synchronization
configuration again at a later point.
If the target system schema or the One Identity Manager schema has changed, these
changes must also be added to the synchronization configuration. Then the changes can be
added to the schema property mapping.
To include schema data that have been deleted through compressing and schema
modifications in the synchronization project, update each schema in the synchronization
project. This may be necessary if:
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 26
Native database connector for SQL Server databases
Select the Configuration | One Identity Manager connection category.
2. Select the General view and click Update schema.
3. Confirm the security prompt with Yes.
This reloads the schema data.
To edit a mapping
Starting synchronization
Synchronization is started using scheduled process plans. A scheduled process plan is
added once a start up configuration is assigned to a schedule. Use schedules to define
executing times for synchronization.
NOTE: Synchronization can only be started if the synchronization project is enabled.
To execute synchronization regularly, configure, and activate the a schedule. You can also
start synchronization manually if there is no active schedule.
IMPORTANT: As long as synchronization is running, you must not start another
synchronization for the same target system. This applies especially, if the same
synchronization objects would be processed.
If you want to specify the order in which target systems are synchronized, use the start up
sequence to run synchronization. In a start up sequence, you can combine start up
configurations from different synchronization projects and specify the order of execution.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 27
Native database connector for SQL Server databases
For detailed information about start up configurations, see the One Identity Manager Target
System Synchronization Reference Guide.
Analyzing synchronization
Synchronization results are summarized in the synchronization log. You can specify the
extent of the synchronization log for each system connection individually. One Identity
Manager provides several reports in which the synchronization results are organized under
different criteria.
l In the Designer, enable the DPR | Journal | LifeTime configuration parameter and
enter the maximum retention period.
This means, all memberships and assignments remain intact until the outstanding objects
have been processed.
Start target system synchronization to do this.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 28
Native database connector for SQL Server databases
To allow post-processing of outstanding objects
Related topics
Property Description
Display name Name of the target system type as displayed in One Identity Manager
tools.
Show in compli- Specifies whether the target system type for compliance rule wizard
ance rule wizard can be selected when rule conditions are being set up.
Text snippet Text snippets used for linking text in the compliance rule wizard.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 29
Native database connector for SQL Server databases
To add tables to the target system synchronization
NOTE: The connector must have write access to the target system in order to publish
outstanding objects that are being post-processed. That means, the Connection is
read-only option must no be set for the target system connection.
l For each table for which you want to publish outstanding objects, create a process,
which is triggered by the event HandleOutstanding and which executes the
provisioning of the objects. Use the AdHocProjection process function of the
ProjectorComponent process component. For detailed information about defining
processes, see the One Identity Manager Configuration Guide.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 30
Native database connector for SQL Server databases
Table 20: Methods for handling outstanding objects
Publish The object is added in the target system. The Outstanding label
is removed for the object.
The method triggers the HandleOutstanding event. This runs a
target system specific process that triggers the provisioning
process for the object.
Prerequisites:
l The table containing the object can be published.
l The target system connector has write access to the target
system.
l A custom process is set up for provisioning the object.
NOTE: By default, the selected objects are processed in parallel, which speeds up
execution of the selected method. If an error occurs during processing, the action is
stopped and all changes are discarded.
Bulk processing of objects must be disabled if errors are to be localized, which means the
objects are processed sequentially. Failed objects are named in the error message. All
changes that were made up until the error occurred are saved.
Related topics
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 31
Native database connector for SQL Server databases
made in the target system will probably be overwritten. This behavior can occur under the
following conditions:
l Memberships are saved in the target system as an object property in list form
(Example: List of user accounts in the Members property of an Active Directory group).
l Memberships can be modified in either of the connected systems.
l A provisioning workflow and provisioning processes are set up.
For each assignment table labeled like this, the changes made in One Identity Manager are
saved in a separate table. During modification provisioning, the members list in the target
system is compared to the entries in this table. This means that only modified
memberships are provisioned and the members list does not get entirely overwritten.
NOTE: The complete members list is updated by synchronization. During this process,
objects with changes but incomplete provisioning are not handled. These objects are
logged in the synchronization log.
You can restrict single provisioning of memberships with a condition. Once single provi-
sioning has been disabled for a table, the condition is deleted. Table that have had the
condition deleted or edited are marked with the following icon: . You can restore the
original condition at any time.
1. Select the auxiliary table for which you want to restore the condition.
2. Right-click on the selected row and select the Restore original values
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 32
Native database connector for SQL Server databases
context menu item.
3. Save the changes.
For more detailed information about provisioning memberships, see the One Identity
Manager Target System Synchronization Reference Guide.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 33
Native database connector for SQL Server databases
2
Error handling
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 34
Error handling
About us
About us
One Identity solutions eliminate the complexities and time-consuming processes often
required to govern identities, manage privileged accounts and control access. Our solutions
enhance business agility while addressing your IAM challenges with on-premises, cloud and
hybrid environments.
Contacting us
For sales and other inquiries, such as licensing, support, and renewals, visit
[Link]
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 35
About us
Index
I ndex
A publish 30
application server 13
P
B provisioning
D Q
encrypted 13
database connector R
native 4
remote connection server 14
REST API 13
E
encrypted database 13 S
schema
J changes 26
edit 10 update 26
synchronization
start 27
M
synchronization configuration 14, 16
membership
synchronization log 28
modify provisioning 31
synchronization server 14
configure 10
O install 10
object Job server 10
delete immediately 30
outstanding 28, 30
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 36
Index
T
target system synchronization
table to assign 29
target system type 29
V
variable set 14
W
workflow 14
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQL Server Databases 37
Index
The primary use cases for mapping synchronization objects in One Identity Manager are: 1) Mapping custom target systems, 2) Mapping default tables like Person and Department, and 3) Mapping custom tables. These cases help in managing permissions by allowing systems to be synchronized effectively, whereby administrators can create custom permissions groups, enabling them to tailor access controls specific to their organization's needs .
Role-based login involves creating customized permissions groups for application roles, which require a more structured permissions setup to carry out administrative tasks using One Identity Manager tools. Non-role-based login, on the other hand, can function with a simpler setup, needing only a specific system user in the permissions group DPR_EditRights_Methods for access .
Compressing schema data in One Identity Manager removes unnecessary data, thereby streamlining the synchronization project, which results in improved load times and overall performance. However, when a schema is updated due to changes in the target system or One Identity Manager schema, compressing must again incorporate necessary changes, ensuring accurate synchronization and data integrity .
Target system managers in One Identity Manager are responsible for creating, changing, or deleting target system objects and managing password policies. They handle administrative tasks within the target system. Target system administrators, however, focus on overseeing application roles for various target systems, specifying managers, and authorizing employees. They do not directly manage target systems' administrative tasks .
Defining a unique system identifier during database connection setup in One Identity Manager is critical because it distinguishes the database uniquely within the identity management environment. Overlooking this step can lead to erroneous data processing, potential data loss, and conflicts due to misidentification among databases, impacting overall system integrity and operations .
If direct access to a target system is not possible, One Identity Manager provides the option to set up a remote connection. This involves enabling the 'Connect using remote connection server' option in the Synchronization Editor and selecting the desired server for the connection, which facilitates remote system access necessary for synchronization setup .
To establish custom permissions groups for synchronization projects in One Identity Manager, administrators must create a new permissions group in the Designer that relies on an existing permissions hierarchy. The new group should be dependent on the vi_4_SYNCPROJECT_ADMIN permissions group, which serves as the parent, ensuring it inherits necessary properties. Additionally, it should also be dependent on the default permissions group relevant to the application role in use, ensuring comprehensive permissions coverage .
Setting up a system connection to an SQL Server database in One Identity Manager involves selecting the correct database system, configuring the connection parameters, and optionally saving the setup as a template for future usage. Configuration templates are significant because they allow for quick and consistent setups for similar synchronization projects in the future, reducing repetitive work and potential configuration errors .
Scheduled process plans in One Identity Manager start synchronization by associating a startup configuration with a schedule, which specifies execution times. This scheduling ensures that synchronization occurs consistently and predictably, contributing to the reliability and timeliness of data updates and integration across systems .
When establishing a new synchronization project in One Identity Manager, selecting the script language is crucial because it dictates how scripts will be implemented throughout the synchronization configuration. The choice is irreversible post-setup, making early decision-making vital. The chosen language affects script coherence and compatibility with the organization's existing systems and development practices .