Overview
Using the Access on Hire2Retire
you can provision and deprovision users on PingIdentity.
Read the official documentation of PingIdentity here.
Define Role Definition¶
Provisioning Type¶
Define Role(s)¶
You can assign a Role to any user based on their AD attributes. You can define complex conditions using AND and OR logic. You can also use thee Group memberships in AD to define Roles. For example:In Figure 2, user(s) with Department "Product" will get provisioned. Only users who get a Role assigned based on the conditions, will be provisioned. If the user is unassigned from a role based on their updated profile in AD, and you have selected to deprovision using Hire2Retire, user will be deprovisioned from PingIdentity.
You can enable the "Do not deprovision upon change of role" checkbox to prevent users from being deprovisioned on PingIdentity due to a role mismatch.
Provision All Employees¶
All user(s) will be provisioned on PingIdentity.
Provision User¶
You can decide to either provision or deprovision using Access.
-
Provisioning - You can provision one or more user(s) to the PingIdentity according to the requirement. User(s) can be created, updated or reactivated in provisioning operation.
-
Deprovisioning - You can deprovision one or more user(s) according to the requirement. User accounts will be deleted from PingIdentity upon deprovisioning.
Map attributes on PingIdentity¶
You can populate a user's profile in PingIdentity by mapping attributes incoming from the AD. You can also use Hire2Retire's powerful data transformation capabilities using Excel Style functions.