Hello,
I am using OIM 8.1.4.
One of the functional requirements of my company is that when an employee's exit date is reached, that all AD group memberships are removed except a limited number of special assignments (O365 related).
In our configuration the employees get their AD group memberships via either:
- Employee => Business Role => System Role => AD Group(s)
- Employee => System Role => AD Group(s)
I initially thought I could manage this by setting the XOrigin flag for the special AD group assignments to 3 (indirect + direct) and then when OIM executed the removal process (manage level's retain group settings are not enabled) it would take into account this flag and leave these direct group memberships.
Unfortunately this is not what happens, all the groups are removed irrespective of the XOrigin flag. It seems that the removal of the AD groups dictated by the manage level's retain group settings does not take into account the XOrigin flag. After the processes have done their job, I see in the object browser that the employee still has the business roles assigned, the system roles are assigned (XIsInEffect: true) and the ad groups are also still assigned (XIsInEffect: false).
So my question is, can you advise me how I can configure the system or implement a process that ensures that the AD group removal process is able to exclude a number of special AD group assignments of being removed. So it seems a small extension on the existing OOB processes but have no idea how to tackle.
Many thanks in advance for your assistance.
Regards,
Mrs. Wilke Jansoone