• Error After Running HR Synchronization

    Hi Everyone,

    Have anyone faced this issue after running the "HR Synchronization"?

    [810457] Error saving Person <PERSON_NAME> (<USERNAME>)
    [810306] Error running OnSaved in logic module 'VI.DB.Entities.EntityScriptLogic'.…

  • oneim-api container throws Script assembly not found in 'DialogScriptAssembly'

    We have a test environment, using mssql container mcr.microsoft.com/mssql/server:2022-latest and Windows containers for the components.

    For some time now we see the oneidentity/oneim-api:windows-amd64-9.3-windowsservercore-ltsc2022 image has been throwing…

  • How to Authenticate to the One Identity Application Server Using an Access Token Issued by OneLogin

    Hello everyone,

    I am trying to integrate OneLogin as an external Identity Provider for authentication against the One Identity Application Server, but I am struggling to find the correct approach.
    The scenario involves an external application that authenticates…

  • Password History Validation Issue with QBMPwdHistory Hash Comparison

    Hi All,


     One of our customers requires that, when setting a user password, the system checks the last 12 previously used passwords and prevents saving the new password if it matches any of them.

    During our analysis, we observed that the password history…

  • Configuring SendAs-Permissions for security groups through a process step with powershell

    Hello everyone, 


    we are currently trying to find a way to configure Send-As-permissions with Identity Manager. The problem is that there seems to be no integrated functionality to give an AD security group the send-as-permission, which would make it more…

  • Product version hidden for security reasons

    An Api query on ".../service/imx/config" provides the corresponding information about the exact product version.
    Information about the product used and its version should ideally not be displayed in order to avoid revealing detailed information…

  • Difference between the Entra ID connector from Starling and the Entra ID connector from One Identity Manager (on-premise)

    Hi everyone,

    I'm working with One Identity Manager and noticed that there are two different connectors for Entra ID (formerly Azure AD):

    • The Entra ID connector available through Starling Connect
    • The Entra ID connector included in the on-premises
  • Apply the rule of skipping the hierarchical manager when it comes to "AQL" and "Dismissal" - Incorrect approval decision

    Hello community,

    I am developing a workflow for access removal processes. I'm using One Identity Manager 8.2. Could you help me with this problem?

    I need to apply a rule to skip the hierarchical manager when the reason is "AQL" or "Termination".…

  • Attestation Collection - Access review details

    Hi Team

    I have enabled collection emails from "QER\Attestation\MailTemplateIdents\RequestApproverByCollection". Additionally, I want to add more pending attestation details in the same email, such as the Attestation case, due date, created date, and count…

  • Angular Web Portal Deployment Strategy - Transport Packages vs. Environment-specific Builds

    Hello,

    I am looking for help on the best deployment approach for our customized AngularWebPortal across multiple environments.

    Current Setup:

    • 3 environments: Production, Test, and Development (all running version 9.3.1)
    • Each environment has different…
  • How to resolve ibm verify token refresh issue using scim connector

    Unknown
    Unknown

    We are connecting to ibm security verify using scim connector of oneim 9.3.1 .Already timeout behaviour is set up to 5 min.Is this CR 34347 defect fix in version 9.3.1?we are still getting this timeout error whenever trying to browse ibm verify data via…

  • Unable to create base objects in UCI connector.

    Hi Experts,

    We are encountered with error BC30002: Type 'UCIRootSelectPage' is not defined while creating base objects in UCI connector on Sync Editor. 

    Target connection & One Identity Manager connection are successfully connected. 

    Please pour…

  • Updating a DateTime value using VID_PutValueSafe method

    Hello There,

    I am fetching a datetime value from a request property as String in following format "yyyy-MM-dd HH:mm:ss" and then parsing it into a datetime object of format "MM/dd/yyyy HH:mm:ss".

    Then I am trying to save this value…

  • Missing Identity in My Responsibilities card on dashboard

    Hi,

    I'm missing the "Identity" entry in the "My Responsibility" card on my dashboard.
    I have identities witch I directly responsible for.
    Other entries are there, as example System Entitlements or Business Roles.


    Why is it no longer…

  • Recalculate single Attestation Case on Event (Identity Manager 9.2)

    Hi,

    I have a question and hope you can help here.
    We have an Attestation Workflow with custom approval methods. When an Identity is temporarily deactivated I want to recalculate the corresponding Attestation Case (or bettter: just this approval step). 

  • Ports for Exchange Server

    Hello All,
    Does anyone know if the Identity Manager connector needs to be configured to use port 5986 (SSL) to Exchange if the winrm for Exchange is set for listening on that port?

    OR

    When it is changed over will the Job Server automatically know to try…

  • [One Identity Manager 9.3] Is it possible to disable auto-submit for attestation decisions?

    Hi everyone,

    I'm working with One Identity Manager 9.3 and noticed that during an attestation campaign, as soon as an approver makes a decision (approve or deny), the action is automatically processed — meaning the item is submitted without needing to…

  • Manager unable to revoke subordinates' access in Web Portal – One Identity Manager 9.3

    Hello,

    We are using One Identity Manager 9.3 and noticed that, even with the manager role, a manager is unable to revoke access that has already been approved and assigned to their subordinates via the Web Portal.

    Current scenario:

    • The manager is able…
  • Problem in creating user on the portal, skipping ID(CentralAccount).

    Hello, I am Rafael, a technician at Cintech Brazil. We are working on a project with the company Sanepar and we have a problem related to user creation on the portal, specifically in CentralAccount. We are facing an issue with the creation of Keys (Identifier…

  • Error: The type initializer for 'SAP.Middleware.Connector.RfcConfigParameters' threw an exception

    I get this error while trying to test SAP R/3 Connection -> ( [System.Exception] The type initializer for 'SAP.Middleware.Connector.RfcConfigParameters' threw an exception.)

    I have

    One Identity Manager 9.3

    SAPNCo 3.1.6

    .NET version 9.0.301

    VS…

  • How to enable custom theme branding in Angular portal using oneim-api-server (v9.2)

    Hello,

    I am currently working on customizing the Angular end-user portal of One Identity Manager, using the official oneim-api-server Docker image, version 9.2, deployed on Kubernetes.

    I would like to enable the use of custom themes located under:
    /var…

  • Automatically Removing Non-Inherited Active Directory Group Memberships in a Dynamic Role-Based Access Model

    I have defined two business roles, and each has been assigned an Active Directory group as a resource that users should inherit by belonging to one role or the other. Membership to both roles is dynamic. How can I enforce that all group membership assignments…

  • Web Portal unusable after login

    Hi everyone,

    I'm currently testing the API Server / Web Portal (oneidentity/oneim-api:9.2) deployed in Kubernetes, and I’m encountering a critical issue.


    The App Server is deployed and reachable (tested separately).

    The API Server has 2 replicas…

  • App Server Error – /appserver/update/allowed not found (Kubernetes deployment, version 9.2)

    Hello,

    I'm currently deploying One Identity Manager 9.2 in a Kubernetes environment, using the official Docker images:

    • oneidentity/oneim-appserver:9.2

    • oneidentity/oneim-api:9.2

    Context
    • I deployed the App Server with the appropriate environment…

  • Question about custom target systems and account tables

    Hi everyone,

    I'm working on a custom target system, and I noticed there's a table called UNSAccountB, but it doesn't follow the structure I need for my use case.

    Is it considered a good practice to extend the UNSAccountB table to meet custom…