I have AD groups assigned to Department with inheritance - how to assign this groups only to employees in this department which meet the condition?
- Products
- Solutions
- Resources
- Trials
- Support
- Partners
- Communities
I have AD groups assigned to Department with inheritance - how to assign this groups only to employees in this department which meet the condition?
What condition? OneIM does not support conditional inheritance (it would produce an audit nightmare).
But you can either create a new dynamic business role based on your condition and assign the AD Group and the employees there. The condition could include your department as well.
All employees has attribute in Person table with status 1/2(Candidad/Employee), so the groups assigned to department must assign only to employyes with status 2 in this department and sub departments
Did you think about using categories (at your groups and accounts) to control the inheritance of those groups to your candidates/employees? https://support.oneidentity.com/technical-documents/identity-manager/8.1.5/administration-guide-for-connecting-to-active-directory/36#TOPIC-1645496
Or, if the candidates should not inherit any groups, you could uncheck the flag IsGroupAccount at all user accounts associated with the candidates.