Active Directory sync - OneIM as master on specific groups

Hi,

Is it possible to configure One Identity as master on a subset of all AD-groups? We want to be able to take full control over specific groups (preferably via a flag on the groups) while still remaining in partial control over all other groups.

Full control:
- If a user is added directly in AD and not in OneIM, this membership is removed in the next sync

Partial control:
- If a user is added directly in AD and not in OneIM, this membership is synced into OneIM

I'm thinking that I can create a new mapping/workflow in the sync-project for the full control groups, but I'm not sure how to solve this.

  • Hi,
    I hope that you have already managed to find a solution, if this is not the case here are a couple of tips. The goal is to have different synchronizing for the same type of objects that these two don't interfere with each other it is needed to create new schema classes on the One Identity side and on the target system side. These schema classes need a scope based on the flag. On the One Identity side the scope needs to based on the column that the flag is mapped against. Then create two mappings for the partial control and the full control. Then create the workflows for the mappings. For the Full control the correct way is to have a sync that has the direction to the target system.