• Active Roles 7.1 and Azure

    Hello community,

    I upgraded the installation of AR, and connected it to the customer's Azure. The question is: Is it possible to manage cloud only users, o to use Active Roles I MUST create also an on-permise user?

    Thanks a lot,

     

    G.O. 

  • Setting primary ARS Administration Server

    We're running two instances of ARS for redundancy and fail over but we're running into issues with debugging, replication, etc because it bounces between the servers when someone connects to the WI. 

    Is there a way to force the IIS server to only…

  • authOrig Errors

    Using WI, we are not able to set authOrig, as it gives us this error:

     

    • Administrative Policy returned an error. One or more values have incorrect format.

     

    In our 6.9 instance it works just fine, but in our 7.0 instance it only gives this error on the…

  • How to push a boolean FALSE in forward sync rule

    Hello 

    I want to push a boolean FALSE in a Forward Sync Rule in Active Roles Synchronisation Service?

    I tried sync new User from a SQL Database to Active Roles. At the sync process I have to fill edsaPasswordNeverExpire with false, because there is a policy…

  • Workflow - Show search results in notification

    Hello,

    Im trying to get the search results into a mail notification, I can perform actions to the search results (Disable users, change properties, etc) But I can not get the notification to send me users that matched the search condition.

    Anyone has…

  • AR Workflow - How can I generate daily reports of users matching certain conditions?

    Hello

     

    We need to generate a workflow that sends daily reports about users matching conditions such as the following:

    -Users with 30 days without changing password

    -Users with the "User cannot change password" option selected

    -Users that do…

  • Add Managed Unit to Self Service Site

    Hello,

    Can someone tell me how to add a managed unit to self-service webportal in ARS?

    I also need to add the search option to the self-service site.

    Any assistance is appreciated.

    I have both 6.9 and 7 that i use to manage separate domains.

    We plan to…

  • How to provision/de-provision user in SQL Server using Active Roles Synch Services

    Hi Forum,

    I am trying to build a sync workflow from a source AD domain to a SQL Server, using Active Roles Synchronization Service (7.0.3). 

    I am able to synch user from one source domain to a destination domain.  I found lots of resources on that.  However…

  • Adding contacts to a distribution list

    Using ARS 7 through the web interface, users are unable to search for contacts when adding objects to a distribution list. Users can find the contact in the global search, click the contact's "member of" and add the group that way but when adding a contact…

  • ARS 7 CSS Issues

    We've had this problem ever since we've installed ARS 7, we're about to push this out into production but this issue arises every so often. The dynamic CSS of the web interface makes some of the div's on the page huge, like 10000px wide and you get a…

  • edsva-ScheduledLink-Starttime & Endtime

    ARS version 7.0 on Windows 2012r2

    The question is about Temporal Group modification.   I have created a changed workflow which will pickup changes to a specific group.  Joining the group requires approval.  Once approval is granted, the workflow will add…

  • Need a way to not delete an account that is marked for litigation hold

    Hello Community,

     

    I'm trying to find a way that i can incorporate into my standard Deprovision Policy explained below.

    Corp deprovisioning policy for users.
    Disable Account
    Sets Password Random
    Group membership – Remove!
    Exchange Mailbox – disable…

  • Access template permissions after group add/removal

    We're working on implementing ARS 7.0 (clean install) after having 6.9 for quite awhile. We've kind of hit a snag with our elevated permissions.

     

    We have workstation support that uses temporal membership to "elevate" themselves into a group that…

  • Group Approvals

    We have a group that we want to have group approvals. This will computers addded to a group. The problem is the OU is sits in has been excluded from approvals. How can i make this one group have approval

  • Querying an object via SPML and returning only one attribute

    Hi, I am searching for a way to get only back one attribute when querying an object using the SPML provider. It is described that it is possible on the following site but we're struggling to find the correct syntax:
    http://documents.software.dell.com…

  • Possible to attached Workflow output as CSV?

    Hi,

    I'm using a scheduled Workflow to first locate and then deprovision inactive user accounts in AD. By itself the Workflow is fine (only using native tasks) and with the option enabled to "Attach a report of workflow execution to notification message…

  • Script a different person in a notification other than manager

    I am creating a user and trying to use the notification task in a workflow but i need a way to add a different person other than a manager to send to.  I have a virtual attrib that has a sam account name that would like to send the notification to.  the…

  • Updating EDS_CONTROL_OBJECT_DN Not Working - ARS 7

    I've created a workstation deprovisioning policy, this policy changes properties, disabled and moves a workstation to a deprovisioned OU. This isn't a form policy, it's an attribute setter command. It flips a boolean to true which kicks off the policy…

  • Using Quest Commandlets in onPostGet Function (Looping & Crashing ActiveRoles Service)

    I implemented a new script to our system yesterday that uses onPostGet to retrieve information and show information on a form after it loads. I have traced it down to running QAD commandlets in the onPostGet function. This leads to errors like:

    Recursion…

  • Active Roles - Attestation and Self Service

    Greetings to All,

     

    There might be many who will agree with me if I say ARS is the best solution for AD and Exchange management and automation. I was wondering, as we have come back to Quest, if the product manager could consider bringing in Attestation…

  • Customized workflow approval process

    Good day to all..

    We got a request from the customer saying.. If a user added to a specific group, workflow trigger a approvals mail to user's manager.

    We selected "Manager of person being added or removed from a Target group", in "Approvers…

  • New Active Roles Policy

    Hi,

    We want to add 2 new policy's on user creation these are

    Property Generation and Validation

    . accountExpires (accountExpires)

    .edsaMemberOf (edsaMemberOf)

     

    But we want them to be optional not Must be specifed, how can this be done?

     

    regards,

    B…

  • Use ARS and/or powershell to create groups - nested & add members automatically?

    We use the lousy nested structure for shared folder ntfs permissions where a domain local group contains a universal which contains a global and the global has the users.  I want to find a way to create the 3 groups required when a new folder is setup…

  • Local Admin

    We've recently had to remove the ARS svc account from the local admin of the server, but this causes the service account to fail with an access denied. If there a minimum amount of granular perms required to offset the need for a local admin? thanks!…

  • Active Roles - Validate no last name

    Hello, I am trying to create a process for provisioning service accounts, and I want to ensure that there is no last name field specified; I would like to either enforce a null value or disable (grey out) the last name field completely.

    Is that possible…