Behaviour of "Disable/Delete User After End Date" Task
Hi Expert,
We ran the given OOTB task "Disable/Delete User After End Date" and the behavior is always delete. How,if possible, to change the behavior to disable?
Thanks in advance.
SK
In order to change the behavior, you have to set the system manager preference called "Period to Delay User Delete" to something bigger than the task will make the user disabled and will automatically delete them at a future date.
Similar Messages
-
User not disabled after end date (9i)
Hi All,
The Disable after end date schedule task disabled 7 users but did not disable 1 user.
Any know issue around this.
Thanks
DonHi Gyanprakash,
i can not try disable manually, its in production. The log for disable user is commented in log.properties. Can not change that .
Just need to analyze, why this user was left out.
Regards
Don -
OIM 11g - User Not enabled After the job "enable user after start date"
Hi,
I have a future hired user in OIM whose start date is set in OIM. The status of the user in OIM is 'Disabled Until Start Date'.
After the start date has passed and the scheduled job 'enable user after start date' is run, I see that the user is still in the status 'Disabled Until Start Date'. I re-run the scheduled job 'enable user after start date', this time manually, still the state of the user remains unchanged.
Please help in troubleshooting as to find out the root cause of the issue and a workaround/solution, if possible.
This issue is intermittent and has happened with quite a number of user. Any pointer would be helpful.
Regards,
Sudipto S.I agree with Nayan.
One alternative approach can be to write your own custom scheduler which can overcome the limitation of OOTB scheduled job 'enable user after start date'. Let the OOTB job get executed first. After it, your custom scheduler should fire a simple SQL Query:
SELECT USR_KEY, USR_STATUS FROM USR WHERE (USR_START_DATE > SYSDATE -1) AND USR_STATUS='Disabled Until Start Date';
//Means those users who are supposed to get enabled today and are still not yet enabled and are in 'Disabled Until Start Date'. May be 2-3 user keys at max will come...
As you said it happens only intermittently and not for all users... So, let the OOTB scheduled job take care of most of such users... And after it has finished, if any user still remains in 'Disabled Until Start Date', your custom scheduler should enable it via using tcUserOperationsIntf.enableUser(userKey);
Using API is always better than database update... Because APIs trigger downstream provisioning workflows as well and not just updates OIM Database...
Keeping your constraints in mind, I think it is the correct answer. -
Process Chain running even after end date
Hi,
We are scheduling month end PC to run every 2 hours and also we have given end date for today evening.but process chain runs even after end date for every 2 hours.so we have to manually remove it from scheduling.
Any method how can PC stop on its own after end date .
Any help highly APPRECIATED
Thanks
Nilesh PathakThere might be multiple release jobs for thie process chain.
So check the same. Right click on process chain --> Display scheduled jobs --> Here all the jobs logs of the chain will be available.. So check the same here...
As you have descheduled it now.. probably you may not be having it as the first release job might be moved to Schedule status as soon as the END date has reached and then second one might have gone when you have removed the chain from Schduling..
Anyway check the same.. and also check in SM37 whether any other user has triggered it manually today or not? -
PARAMETER_EXCEPTION: Start date is after end date
WORKLOAD ANALYSIS (PORTAL ACTIVITY REPORTING) : PARAMETER_EXCEPTION: Start date is after end date.
Hello,
We get the above exception when we analyzed the extractor framework logs for EP Workload analysis extractor.
Can someone please advice.
Thanks
Srikanth MHi Nacho,
Could you please check if the Solution Manager time format for the user used for the Workload analysis is same as that of the monitored system. This error was caused in our landscape as the format in the monitored system was having a dd.mm.yyyy and that of the user in solman was mm.dd.yyyy. You can check the same in the transaction SU01 --> Change/Display --> Defaults tab --> Date format.
Thanks,
Lijin Xavier -
we have a long list of disabled/deleted users in AD
Somehow, they are still appeared as active user in Sharepoint Online.
How do we get rid of those list?
Hope you can advice. Thanks.SharePoint does not remove users from SharePoint permissions just because they were deleted/disabled in AD. This is to maintain referential integrity. In fact, when you delete a user from SharePoint, that user remains in the SharePoint content database,
just marked as deleted.
They do not have access to SharePoint given their account is deleted/disabled. But as far as automatically managing this, I'm not aware of a tool. On-prem there is Metalogix ControlPoint which does a great job of this, I haven't explored the O365 options.
Trevor Seward
Follow or contact me at...
  
This post is my own opinion and does not necessarily reflect the opinion or view of Microsoft, its employees, or other MVPs. -
I've been searching for over a week high and low now trying to find a way to do this via PS.
We'd like to lockout certain users (we can put them in a group/OU) 30 days after their first successful log in - the one requiring
password change by them.
And we'd like to disable it REGARDLESS of their activity.
All the tips and scripts I've found look for 'inactivity', date created etc.
Only parameters I need are 30 days AFTER the first log in. Accounts might be created 60 days before actual use, but still need to be disabled 30 days after their first successful log in.
Any tips would be GREATLY appreciated!I don't think you're going to get the kind of solution you want via scripting. As jrv noted, usually this kind of issue is managed by using account expiration and password expiration. If that won't work for you, then I would recommend looking into supported
third party tools that can help you get where you need to go.
-- Bill Stewart [Bill_Stewart]
As Bill points out you need to look into third party tools. If there is any legitimate legal or industry need for this then there wil be third party tools. Having worked in medical software systems \I can tell you there is not. There are
old systems that use now-obsolete mechanisms that do things similar to what you are asking. They are no longer usable.
I think if you sat down with those asking you to do this and had them get the actual industry and government rules on the table you would see that this is not what they are asking you to do. It aslo doesn't make much sense from a technical standpoint.
Just set the password expiration. That is what it is designed for. To force reauth just set the account so the user cannot set the password. Use the reauth web page to allow the user to set a new password. Use the corporate disclaimer
or a desktop link to notify users what to do when the password expires.
¯\_(ツ)_/¯ -
Urgent -- User responsiblity end dates
Hi,
Needed some clarification about end dating some responsibilities.
I am given this huge excel mentioning around 1000's of users of various responsibilities which we need to end date.
In case all the users under a responsibilty are to be end dated the entire responsibilty can be end dated.
Going manually is very difficult so wanted to confirm the tables that apps affects while doing the same through front end.
How much i know they are fnd_user ,fnd_user_resp_groups
and fnd_responsibility.
Would be a great help if somebody can confirm this ASAP as this is quite urgent.
Regards,
NeelamNeelam,
Do you want to end date or want to end date users after a specific time period?
Both of then can be end dated either manually or using a custom package( Create a custom packege, register the same with Apps and run the same)
Hope this will be of help.. do let me know in case of further help..
Thanks
Yogi
[email protected]
Needed some clarification about end dating some responsibilities.
I am given this huge excel mentioning around 1000's of users of various responsibilities which we need to end date.
In case all the users under a responsibilty are to be end dated the entire responsibilty can be end dated.
Going manually is very difficult so wanted to confirm the tables that apps affects while doing the same through front end.
How much i know they are fnd_user ,fnd_user_resp_groups
and fnd_responsibility.
Would be a great help if somebody can confirm this ASAP as this is quite urgent. -
Hi,
This close date of tis beta exam http://education.oracle.com/pls/web_prod-plq-dad/db_pages.getpage?page_id=41&p_org_id=&lang=&p_exam_id=1Z0_151 is May 19. So after this and until the release date of production exam, WHAT will hapen with this Forms exam? Can it be scheduled after May 19 (as beta), when normally the exam is in POST BETA REVIEW stare, so if i log in on Pearson account, can i still see 1Z1-151? So it can no longer be scheduled ~10 weeks, until the production exam will be released?
Thanks!
Edited by: Roger22 on 03.05.2012 14:49Access to a beta exam ends on the beta end date. From that date until the exam is in production, some exams are not available for registration at all. However, some exams will open for pre-registration. Which means that if the 151 beta exam ends on May 19, you can register for the production exam on May 20, but the appointment date will be a date in the future. You will be able to register for a future exam date starting May 20, but you will not be able to TAKE any exam between May 19 and the future start date of the production exam.
You will not be able to register for a BETA exam after the beta end date.
Regards,
Brandye Barrington
Certification Forum Moderator -
Error U9KP7Q94 when logged in with the deleted user after its recreation...
Hi All,
How to get default screen for the deleted user when we recreate the same user with same name?
i have deleted the user for ex. 'XYZ' (from the catalog user group managemet) and when again i am trying to browse the obiee with the same user i.e. XYZ (after passing the authentication using some LDAP) then i am getting the error like 'Error U9KP7Q94'.
can anyone help me in this..
thanks
Edited by: user10946827 on Apr 26, 2009 4:32 AMI don't really see your problem. Do you have any error message ?
You may have may be a security problem.
Have you see in the catalog manager if you have the right / grant for the user on the report.
You can log as administrator / go to the catalog manager / shared folder / catalog root / users /
- on your user / in the items properties, set the owner ship to the administrator
- go to the security icon of the directory user
- give the access to the administrator
and then you have access to the directory
To see the grant of each file, you must do the same manipulation (become the owner, change the security, ...)
Success
Nico -
Hello Gurus,
I required a script which will check the END_DATE of the responsibilities assigned of a particular user.
Also how can I extend the END_DATE of the assigned responsibility from backend.
Please suggest.
Thanks-
Pokhraj DasHello Gurus,
I ran the below sql to check the end of any responsibilities.
=================
select a.USER_NAME, a.EMPLOYEE_ID, b.RESPONSIBILITY_ID, c.RESPONSIBILITY_NAME, b.START_DATE, b.END_DATE from apps.FND_USER a, apps.FND_USER_RESP_GROUPS b, apps.FND_RESPONSIBILITY_VL c where a.USER_ID=b.USER_ID and b.RESPONSIBILITY_ID=c.RESPONSIBILITY_ID
and user_name = UPPER('&user_name');
===========
From the above query NO END_DATE is showing so far/
But when I am checking from FROENT_END it is showing the responsibility end date as 10-Sep-2013.
Please help to fix the issue.
Regards-
Pokhraj Das -
Automatically deny access to users after expiry date
Hi All,
Is there any feature in SQL Server that automatically revert back all permissions of a user after certain days(Expiry date).
My company has a policy that all users permissions should be reverted back after every 60 days from request. After 60 days the users should request again for the access.
I am planning to automate this. Any input is appreciated
Thanks,Hi,
Never don't use the Agent job for security missions.
The Agent may skip a mission for one reason or another (eg problems related to the clock as set the system clock into the future and skip the scheduled time). That may lead to the fact that he is not scheduled to run that mission next. The Agent scheduled
his next mission A executable each time he execute the mission A. Moreover there are several known bug which include stopping the Agent as randomly stops when you schedule the job to run past midnight (There is a fix fro this), etc. The basic idea that
I want to say is NEVER use the Agent schedule for security mission.
http://support.microsoft.com/kb/2598903
as I mention in preview post I think that a trigger on logon is fit for this case (links are on my preview down)
[Personal Site] [Blog] [Facebook] -
Delete User assigned to a task
Hi experts,
I would like to delete a user assigned to a task using the Administration area in guided procedures tab of the portal.
So I go to : Guided procedures TAB --> Administration --> Maintain Processes --> Running process list --> Change Authorization --> New User Assignments
But unlike this document:
https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/173dceea-0c01-0010-0698-819d627fed79
on page 7,
the "Remove User" button is not present.
Can someone explain why?
Is this an error of the document or is it possible to remove a user assigned to a task?
Thanks,
LucaThank you very much for your answer Sudhir.
Now I know why the button is not present in my portal.
Luca -
OIM 11g Modify User Profile for Updating End Date
Hi Gurus!
We have an OIM implementation where users may request the creation of other users by means of a Create User request template. In this template we set the End Date to be 3 months after the request date.
In order for the requester to extend the period of a user's OIM user account (along with its provisioned resources) we customized a Modify User Profile by displaying the End Date field and automatically populate it again to 3 months after the request date. Also we developed a custom event handler to enable the user when it is disabled and the End Date is updated to a future date.
This Modify User Profile is working great when the user is still enabled (the End Date is still in the future), however, when the End Date has passed (and the user is Disabled) the requester is not able to see the user when selecting the Modify User Profile request template.
Is there a way to allow requesters to also see disabled users in the Modify User Profile request template?
Thank you in advance.
Regards,Hi Kevin,
thanks for your reply!
But, in this case, when the user is already disabled due to his End Date, how can a requester, through the Self Service TAB, enable it?
The Enable User request template does not work since when trying to enable the user, OIM sees the End Date is already passed and the DataSet validation throws an exception.
The only way I saw was providing a Modify User Profile Request template to change the End Date and developing a custom event handler to enable the user upon the extension of the End Date...
How can, in this situation, a requester enable the user and extend its End Date?
Thank you!
Regards, -
Need to add number of days to users end date.
Hi,
I have a code where we are adding number of days(30) to current date and then updating user's end date in IDM DB.
Now we have a requirement where we need to add number of days(30) to existing end date of user instead of adding to current date.
*public String incrementDate(int daysToAdd)
// Start date
log.info("NotifyLastDayOfService::incrementDate(): Enter");
SimpleDateFormat sdf = new SimpleDateFormat("yyyy-MM-dd 00:00:00");
Calendar c = Calendar.getInstance();
c.add(Calendar.DATE, daysToAdd); // number of days to add
String newDate = sdf.format(c.getTime());
log.info("NotifyLastDayOfService::incrementDate(): Exit");
return newDate;
Have any body implemented this scenario?
Please suggest.
Thanks,
Kalpana.Hi Nayan,
Here is the code:
System.out.println("----inside increment date method-----");
HashMap<String, String> hm = new HashMap<String, String>();
HashMap<String,Date> modifyMap=new HashMap<String,Date>();
SimpleDateFormat sdf = new SimpleDateFormat("yyyy-MM-dd 00:00:00");
tcResultSet usrList = null;
String enddate = null;
hm.put("Users.Key",usrKey );
try {
usrList = this.usrIntf.findUsers(hm);
usrList.goToRow(0);
Date endDate =usrList.getDate("Users.End Date");
System.out.println("-----users end date-----"+endDate);
String userEndDate=sdf.format(endDate);
System.out.println("-----String value of users end date-----"+userEndDate);
Calendar cal=null;
System.out.println("-----Calender date-----"+cal);
cal.setTime(endDate);
System.out.println("-----end date-----"+endDate);
cal.add(Calendar.DATE, Integer.parseInt(daysToAdd)); // number of days to add
Date newEnddate = cal.getTime();
System.out.println("-----new end date-----"+newEnddate);
//usrList.setEndDate(Edate);
modifyMap.put(userEndDate,newEnddate);
usrIntf.updateUser(usrList, modifyMap);
System.out.println("updated user's end date in OIM DB");
//System.out.println("-----updated user's end date in OIM DB-----");
logger.info("NotifyLastDayOfService::incrementDate(): Exit");
System.out.println("-----new date-----");
} catch (tcAPIException e) {
logger.error("Error in finding end date for user" + e);
} catch (tcColumnNotFoundException e) {
logger.error("Error in finding end date for user" + e);
In th log file, I can see that the code is not executing this line:
cal.setTime(endDate);
end date is of type Date and stores users end date from DB. Please help in resolving this issue.
Thakns,
Kalpana.
Maybe you are looking for
-
I can't add a entry in a shared calendar on iCal (Mountain Lion) but on iPhone it is ok
My Partner is sharing her business calendar with me. (view and edit) In the past I was able to add calendar enties on my MacBook, iPhone and iPad. Since a couple of days, I can do this only on the iPhone & iPad but not on the Macbook Pro. (Mountain L
-
I have a problem to connect with FaceTime. I am using OS X 10.9.1 on a Mac PowerBook which is 4 weeks old. I can connect on iPhone but not from my computer. Does anyone have a similar problem???
-
My iPad 2 has no " software update " when I go to settings/general. How can I get iOS 5 in this case ? Thank you. <E-mail Edited by Host>
-
Where is my music library in iTunes 11?
Just upgraded to iTunes 11. Music lib used to be on left side of screen w/ all individual playlists. Now it's gone. Only have playlists and purchases. Where is it and how do I put it back in that left side list w the others? Thanks!
-
Artists, songs, albums, almost every category isnt showing
I have a 30gb white ipod video and just recently I noticed that some of my artists arent showing, then upon further investigation i foud some songs arent there, when they are shown as there in iTunes. very weird. so I have about 3000 songs, and of th