Provisioning Global User Password Generation Behavior for Identity Manager
search cancel

Provisioning Global User Password Generation Behavior for Identity Manager

book

Article ID: 60284

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Suite

Issue/Introduction

Identity Manager performs a "Create Global User" operation when a Provisioning Role is assigned to a user and no corresponding Provisioning Global User exists. Password assignment during this process depends on whether a password is provided within the submitted task.

Environment

Identity Manager 14.x

Resolution

  1. Bulk Loading Configuration: For bulk-assigned Provisioning Roles, include a default password within the feed input file. Relying on default provisioning server profile settings for password generation is discouraged.
  2. PolicyXpress Configuration: Configure UI-type PolicyXpress policies using the following parameters:
    • State: Submission
    • Event: CreateUser
    • Action: Set the %PASSWORD% well-known variable.
  3. Task Submission: Ensure the generated random password is explicitly submitted with the task. Inclusion via a specific event without explicit task submission results in the "Create Global User" call failing to access the password value.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.