SCIM Connector Removes All Roles When Deleting Provisioning Role
search cancel

SCIM Connector Removes All Roles When Deleting Provisioning Role

book

Article ID: 233566

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Suite

Issue/Introduction

When removing a provisioning role from a user account that possesses multiple roles within the SCIM Connector, all roles are removed from the account instead of only the intended role. This article provides the steps to configure the Connector XPress to ensure roles are handled correctly.

Environment

Identity Manager or Virtual Appliance 14.x

Cause

This is a configuration in the Connector XPress

Resolution

To resolve this issue, the "Force Modification Mode" attribute must be updated in Connector XPress. Follow these steps:

  1. Open Connector XPress.
  2. Navigate to the configuration menu for your SCIM connector.
  3. Locate the container setting labeled Force Modification Mode.
  4. Change the value to: DELTA_WITH_REMOVES_FIRST.
  5. If you cannot locate the "Force Modification Mode" attribute:
    • Go to the top menu and select Tools > Preferences.
    • Check the box for Show Extended Metadata.
    • Click OK.
  6. Once the change is applied, redeploy the connector.
  7. If you are testing via the Provisioning Manager, close and restart the application to reload the new metadata.