Overview
Using the Access on Hire2Retire
you can provision and deprovision users on SailPoint.
Read the official documentation of SailPoint here.
Define Role Definition¶
Provisioning Type¶
Define Role(s)¶
You can assign a Role to any user based on their AD attributes. You can define complex conditions using AND and OR logic. You can also use the Group memberships in AD to define Roles. For example, In Figure 2 the rules are defined on the basis of Department (Equals). If the rules are passed then only user(s) will get provisioned. If no rule passes and the user(s) is present in SailPoint then deprovisioning is performed for the user(s).
Map the rules defined in first table with the Roles provided by SailPoint.
You can also select default roles in SailPoint. For if and only if 'Developer' Role is passed and it is not mapped in the second table then the selected default SailPoint Roles will be assigned to the user(s).
You can enable the "Do not deprovision upon change of role" checkbox to prevent users from being deprovisioned on SailPoint due to a role mismatch.
Provision All Employees¶
All user(s) will be provisioned on SailPoint.
Provision User¶
You can decide to either provision or deprovision using Access.
-
Provisioning - You can provision one or more user(s) to the SailPoint according to the requirement. User(s) can be created, updated or reactivated in provisioning operation.
-
Deprovisioning - You can deprovision one or more user(s) according to the requirement. User accounts will be deleted from SailPoint upon deprovisioning.
Map attributes on SailPoint¶
You can populate a user's profile in SailPoint by mapping attributes incoming from the AD. You can also use Hire2Retire's powerful data transformation capabilities using Excel Style functions.