SAP IdM 8.0 no master process (good practices)
Hi guys,
Here is one good tip, I wanted to share with you 🙂
Each time when I start a new project, I have to create the process, responsible for creating the user accounts into the back-end systems. In order to save some work/time, I have created a custom package responssible for the No Master Process:
- Create new custom package (….masterprocess)
- In this package create the process responsible for assigning the only privilege
- Link this process in each Repository type, then an automatic provisioning, will be triggered in case of assignment when the ONLY is missing:Â Â
Hope you like it ?
Simona Lincheva
Hi Simona,
That's good practice. I also use a similar/same way to handle master privilege.
BTW, how do you handle termination scenario? Do you remove all direct role/privilege assignments when identity is terminated? Some customer prefer to keep the account locked in the system.
I would like to understand how you do it and the rationale behind it?
Thanks,
Chenyang
Hi  Chenyang,
Thanks for the comment 🙂
As for your question, depends on the customer (...and on the back-end licensing policy, as for the ABAP systems the only thing you need is to set validity and lock the user 🙂 ).
Possible scenarios:
Note: in case the back-end system is AD, some customers want to move the user accounts into an inactive OU (again keep or remove the access).
In addition, now we should think about the GDPR :))), here again depending on the company policy we have to maintain the inactive accounts -Â https://blogs.sap.com/2018/04/23/gdpr-compliance-and-sap-idm/
BR,
Simona
Hi Simona,
thanks for sharing this practice 🙂
In our current Business-Role-Design every Business Role has every ONLY-Privilege included. The problem is that sometimes the IDM tries to delete the user when a business role expired, although there are existing business roles with ONLY-Privileges.
So I'm thinking to switch to your presented practice. Do you think it is possible to remove all ONLY-Privileges from the business roles without IDM deleting all users from the backend systems? Will the IDM trigger the no-master-process when there are no only-privs left?
Hope you can answer my questions 🙂
Best Regards,
Felix