Overview
Using the Access on Hire2Retire
you can provision and deprovision users on Vmware Identity Service.
Read the official documentation of Vmware Identity Service here.
Define Role Definition¶
Provisioning Type¶
Define Role(s)¶
You can assign a Role to any user based on their AD attributes. You can define complex conditions using AND and OR logic. You can also use thee Group memberships in AD to define Roles. For example:In Figure 2, user(s) with Department "Product Development" will get provisioned. Only users who get a Role assigned based on the conditions, will be provisioned. If the user is unassigned from a role based on their updated profile in AD, and you have selected to deprovision using Hire2Retire, user will be deprovisioned from Vmware Identity Service.
You can enable the "Do not deprovision upon change of role" checkbox to prevent users from being deprovisioned on Vmware Identity Service due to a role mismatch.
Process All Employees¶
All user(s) will be provisioned on Vmware Identity Service.
Provision User¶
You can decide to either provision or deprovision user(s)using Access.
-
Provisioning - You can provision one or more user(s) to the Vmware Identity Service according to the requirement. User(s) can be created, updated or reactivated in provisioning operation.
-
Deprovisioning - You can deprovision one or more user(s) according to the requirement. User accounts will be deactivated on Vmware Identity Service upon deprovisioning.
Map attributes on Vmware Identity Services¶
You can populate a user's profile in Vmware Identity Service by mapping attributes incoming from the AD. You can also use Hire2Retire's powerful data transformation capabilities using Excel Style functions.