Users Request and Provisioning Flashcards
What is #1 defining?
Quicklinks
Who can request for this Quicklink.
Creating a group of users for this quicklink.
What is #2 defining?
Quicklinks
Which users can be targeted/request access for.
Creating a group of users for this quicklink.
What is #3 defining?
Quicklinks
What can be requested (access).
Creating a group of users for this quicklink.
What can you request with #1.
Add or remove roles/entitlements
What can you request with #2.
Request, delete, modify accounts.
What can you request with #3.
Changed passwords on managed systems or IdentityIQ
Who submits the request?
requester
The requester is the individual or entity initiating the lifecycle request.
What is the request?
requested
The requested refers to the specific action or change being sought in the lifecycle request.
Which identity is the target of the access change?
requestee
The requestee is the individual or entity whose access is being modified as part of the request.
Important note to know about access given in Quicklinks.
Access is cumulative
List possible Provisioning Policies.
CUUPEDD
- Create
- Update
- Unlock
- Password
- Enable
- Delete
- Disable
Where do you go to Configure Account Dependency
Navigate to Applications > Application Definition in the IdentityIQ UI.
Select the application for which you want to define dependencies.
Go to the Provisioning Policies tab.
Under Application Dependencies, specify the dependent applications and their required fields.
Lifecycle Event possible Event Types
CRAMRAN
- Create
- Rule
- Attribute Change
- Manager
- Rapid Setup
- Alert
- Native Change
List the IdentityIQ actions that can trigger provisioning
User Initiated Actions
System Initiated Actions
Lifecycle Event-Driven Provisioning
List possible User Initiated Provisioning
CLAP
Certifications
Lifecycle Manager
Access Requests
Policy Violations
List possible System Initiated Provisioning
BAIR
Background Reconciliation
Aggregation
Identity Refresh-Driven Assignments
Role Assignments
List possible Lifecycle event initiated Provisioning
Joiner
Leaver
Manager Transfer
Reinstate
Summarize process for provisioning
The request is created as a provisioning plan.
The Provisioning Broker evaluates and compiles the provisioning plan, which often involves dividing the original plan into several partitioned plans. Each partitioned plan addresses a single application.
Each partitioned provisioning plan is passed to the appropriate handler.
The provisioning actions are confirmed and marked in Identity Cube, based on the mechanisms involved.
What are Lifecycle Events?
Activities that happen in the normal course of a person’s employment
* Joining the company (joiners)
* Changing departments/managers (movers)
* Leaving the company (leavers)
Describe the process of Attribute Synchroniztion
Attribute synchronization is an automated process of synchronizing changes to Identity Cube identity attributes (such as name, email, or department) from an authoritative source to target systems.
How Attribute Synchronization is Triggered?
Direct Edit to an Identity or Aggregation (Synchronize Attributes refresh option)