Clarification on Role Owner Synchronization in CA Identity Governance and Identity Manager Integration
search cancel

Clarification on Role Owner Synchronization in CA Identity Governance and Identity Manager Integration

book

Article ID: 219943

calendar_today

Updated On:

Products

CA Identity Suite CA Identity Governance CA Identity Manager

Issue/Introduction

This article clarifies the expected behavior when integrating CA Identity Governance (IG) with CA Identity Manager (IM). Specifically, it addresses why the Role Owner configured in Identity Governance does not reflect as the Provisioning Role Owner within Identity Manager.

Environment

Identity Governance 14.x & 15

Cause

This behavior is Working as Designed. The concept of "Role Owner" serves distinct purposes in each product:

  • Identity Governance: The Role Owner is designated specifically for approval workflows and governance oversight.
  • Identity Manager: Provisioning Role ownership is tied to the administrator identity (connector account) used to facilitate communication between the Governance and Identity Manager environments (Universe Connector).

Resolution

When provisioning roles are created in Identity Governance and exported to Identity Manager via the connector (CA IdentityMinder), the ownership attribute in Identity Manager defaults to the administrative account configured on the connector level.

This ensures that the connector has the necessary service privileges to manage the role object lifecycle. The owner selected in Identity Governance does not override this service account in Identity Manager.