• Force change password on LDAP account

    Hello everyone,

    We want to force to change password on ISAM LDAP account.

    I read that this can be done through "ShadowLastChange" parameter on LDAP accounts, but I don't see this parameter on Target System.

    Can you help me?

    Thanks,

    Gius…

  • How to open link in a new browser window password reset portal

    Hi all,

    When I log in with the admin portal in configuration, I can enter the URL for the password reset portal. I want it to open in a new tab when I click on this URL, but it's not happening. Could you help me with this subject

    Best regards,

  • How Can We See Our Authorization as a List Instead of Hyperview

    Hi all,

    Our customer want to see on authorizations (ADGROUP, LDAPGROUP etc.) as a list or grid instead of hyperview. Is it possibble? Could you lead us for this subject?

    Best regards,

  • Is there any guide or whitepaper available on best practice for installation and architecture of Identity Manager?

    Hi, 

    I am looking for any official documentation which has recommendation for One Identity Manager's architecture and hardware capacity estimation.

    Any input on this is greatly appreciated.

    Thanks

  • Web Portal How to change Product Name?

    Hi all,

    I cannot change the name of the product. I found how to change the logo from the admin portal, but I am unable to change the Productname. Could you assist me with this?

    Thank you,


  • Keep group membership after termination

    Hello experts,

    Can someone tell me if we can keep group membership of a group assigned by a business role after termination? We have the AD account deferred for 90 days after termination. 

    Thank you,

    Lu

  • REST API Script - how to determine the authenticated user's username within 1IM Script?

    Would like to know API authenticated user account calling script function so that we can log which account is calling what API script with what parameters, and may be provide finer access control to the script functionality.

    Right now, I see just one…

  • Custom Application - Setting a role via UNSAccountBHasUNSGroupB - POSH4 Connector

    Hello Community, I need some help.

    I´m developing a Powershell Connector for a SaaS Service (1IM 9.1.1) and I want to use a bit more entitlements instead of hardcoded value calculations. I have schemas for User, Locations and Role. The locations are reflected…

  • Not able to Authenticate using Access token(in authentication header) for authentication to API server

    With the implementation of the API server, we want to expose our One Identity Manager capabilities via API's within our organization. In our test setup we successfully managed to authenticate to the authentication API using the oauthrolebased api, and…

  • Permisson to revoke account definition

    Hi everyone,

    we want to enable a role based permisson group to revoke the account definition of an ADs Account. 
    We already tried to assign the task permission to the permisson group but it didnt work. (1. User Interface -> 2. Task definitions -> 3. RevokeAccountDef…

  • Difficulty with cross-object value template

    Hello everyone,

    Could you please advice in creation of simple template for a column in Person table, where I'll use the value from ADSAccount table.

    I have tried the following within CustomProperty10 column of Person table:

    Value = $FK(UID_ADSAccount…

  • Lock down reporter in Webportal

    Hello, Does anyone have instructions or can lead me on how to lock down reporter? Here are some things we would like to consider doing.

    • Remove the "New Report" button
    • Hide tables to choose for reports
    • Hide columns to select in a table for …
  • Report for ADSAccountInADSGroup returns empty

    Hi Everybody,

    We are trying to create new report from Web Portal. While using the Base Table ADSAccountInADSGroup for the report it returns empty result. For other tables (for example ADSAccount, ADSGroup etc.) new reports are working correctly. 

  • Current user reference in template for visibility script

    Hello Experts, 

    Can anyone tell me if there is a way to reference the current user in a template? I need to add something in the visibility script to be true based on role.

    Any help is appreciated. 

    Thank you,

    Lu 

  • Question about OIM Data Import Issues

    Hello, when importing a CSV file in Data Import tool for person table, is there a way to split the full name field into two separate fields for last name and first name?

  • setting up an Angular development environment locally on my laptop.

    Hello,
    
    I'm currently working with OI Manager v.9.0 LTS and I'm trying to set up an Angular development environment locally on my laptop. 
    I have a question regarding cross-site cookie transmission in this Angular development environment. To enable…
  • SCIM: The request contains invalid parameters or values

    Hello,

    I am trying to connect to a Target System using oAuth authentication method via SCIM. We are using the version 9.0 LTS.

    We populate all the correct values and when we try to test the connection we get the below error message:

    Error returned:…

  • Caches management of Angular Web Portal

    Hello everyone,

    We are making a custom app for one of our solution from the Angular codebase v92. We are building using npm run build. But we see there is a caches that is not getting cleared when we have deployed the custom app. Can anyone of you please…

  • web service

    "Hello, we want to pull individuals from our service desk platform(website) into the identity manager. I'm considering doing this via a web service, but I'm unsure of how to proceed. Could you help me?

  • Virtual schema property

    We want to use in the mapping of the Person and AD schemas, the 3rd schema (Locality table), because the Person schema which we are using in the mapping contains only UID of the location, but not the name. We want to bring the name of Location from another…

  • ADS_ADSDomain_Maintain_OtherSID frozen "Write permission denied for value Canonical Name"

    Hi all,

    We installed an OIM environment with multiple AD-Domains.

    three of these Domains are connected using an AppServer for SQL Connection and one is configured to connect to the Database directly.

    The sync with the "local" domain (direct Database…

  • SFtpComponent - Put

    Hello Experts,

    I'm trying to get a process orchestration in place to SFTP a file. I'm having issues and don't see much on documentation.

    When I ssh to the SFTP server I get the fingerprint and use that for the config parameter. Although when…

  • Add CentralAccount from PersonOrdered to PersonWantsOrg table

    Hello, I performed a Schema extension on the PersonWantsOrg table with the intention of introducing PersonOrdered's CentralAccount, I'm trying to get the value but I can't, I tried the following code:

    If Not String.IsNullOrEmpty($UID_PersonOrdered…

  • How to create a custom scheduled task

    How to create a custom scheduled task such as daily maintenance or how to modify it, to define a verification task, for example the last login, this for when a person or user on a specific custom target system is more than XY days without signing in,…

  • Identity Manager 9.2 and SCIM-connector

    Hi guys!

    Just a headsup, but I think the SCIM-connector in 9.2 is broken.

    After upgrading, three DPR_Shell_Migrate-processes got frozen (we have three SCIM target systems). When I tried to open the connectors in the sync editor and pasting the Base64…