Bhold attestation setup if FIM POrtal is already used for Group Membership

Background - We had a FIM 2010 deployment in production deployment. Few
months ago, we upgraded it to FIM R2. There are already about 4000 Criteria based Groups and Request Based Groups at FIM portal. FIM portal is used as an authoritative source for group membership.
Problem Statement -  The requirement is to attest the existing and
ongoing Request Based group membership of users using BHold User Attestation module. We want to continue FIM portal (not Bhold UI) as the end user interface for requesting the group membership.
Hence, for metaverse' group object's member attribute, FIM Portal should have higher precedence than Bhold MA.
From available documentation of Bhold, I understand that BHold is more suitable in cases where FIM Portal is not already the Group Membership deciding system. However, in our already existing
deployment, both group membership is given by FIM portal. In fact this should be the case with all the FIM deployments before Bhold’ s release.
Please suggest on how to attest the group memberships.
Mayank Vaish

I would not expect to have to attest group membership where that membership is controlled programmatically. The idea of Attestation is for a responsible person to attest and confirm that the membership of a given group/role/permission is correct (and remove
users who don't need that permission). As long as someone responsible has attested that the rules that govern the automatic group membership are appropriate for the permission controlled by that group, then another round of attestation via BHOLD would seem
like overkill.
However, in the case where membership of FIM groups is managed via FIM's approval mechanism then there may well be a case for BHOLD attestation. It will depend on the business's audit requirements and how well the FIM logs are being maintained, and
also the sensitivity/importance of the permission being managed by the group. If it is not possible to prove who approved membership of what group - and to confirm that that membership is still appropriate - then regular attestation may still be required,
in which case BHOLD is an easier way of doing it than trying to build your own or do it manually.
Cheers,
Dave

Similar Messages

  • Cannot start family sharing: Apple id is already used for shared purchases

    I'm trying to set-up family sharing on multiple devices, but I'm informed that my mac.com address is "already used for shared purchases" and "accounts can only be part of one Family at a time" with a dialogue box of "OK". We are only one family, and all devices were recently under my iTunes/Apple account. How do I change that so that I can set up family sharing? I have an 11 year old itching for her own phone and want to be able to share, but also to manually approve purchases (which I think is the point of family sharing, especially with someone under 13.)

    I FIGURED THIS ONE OUT!!!  What happened was initially I had set up a Family Sharing account under my wife's old iCloud login (old email address) .  I had set her up as the administrator of the account.  We used MY credit card info to handle any purchases made.
    Some time later we decided to share MY iCloud account rather than having separate accounts (thus, same email for iCloud login).  While switching her out of her old iCloud login over to sharing my login, it never crossed my mind that I had used her old iCloud login to set up Family Sharing.  Since her old iCloud login was set up as the administrator of the account, all I had to do was sign into iCloud with her old email address and password that she had used before.  Once logged in, I went to Family Sharing and chose an option to stop Family Sharing.  As soon as I did that, I re-logged in with the new shared iCloud account and was able to immediately set up Family Sharing.  Phew!!!
    Hope this helps

  • Controlling area already used for org. unit problem

    Hi people,
    can you please help me with one problem, my customer is upgrading SAP HR from 4.6 to 6.0 and now we are testing QAS system.
    When I create new or. unit in PPOME, I have Cost-centre inherited from the org.unit above, but when I want to put another Cost-centre it gives me the next error "Controlling area HR01 already used for organizational unit XXXXXXXX".
    The same procedure worksin PRD system which is on version 4. 6. Could you please help me what is wrong because i am not able to change cost centre in the QAS system.
    Thank you.
    Romano
    Edited by: Romano Cinotti on Oct 13, 2009 11:25 AM

    Hi,
    To which object u are going to change the cost center i.e, position, job, org.unit.
    If you are changing the cost center to position, If it is not allowing to change the cost center then u have to check the parameters:
    May be u already assigned cost center
    May be u already assigned cost center to ur org, unit, which u assigned to ur position. If u already assigned diffrent cost center to ur org.unit, you may not change the cost center to ur position or job.
    Regards
    Devi.

  • Repository A2 is already used for document area DATAARCH (Data Archiving].

    Dear ALL,
    Actually I am getting probelem Photo configuration in back end.
    I am using Transaction SM31 maitaining the table TOAAR_C, here I am getting probelem  'Content Repository Identification' (A2), here i am getting below error.
    Repository A2 is already used for document area DATAARCH (Data Archiving].
    Please look in to issue.
    Regards,
    venkat

    Jürgen - your answer was very helpful and I'm sure I'm now in the right direction!
    However I still have an issue:
    When the write job is finished and before deleting and storage, the archive file is not accessible - and then I am not able to continue with deletion and storage.
    An example:
    Filename: RMM_EKKO11180104855_CLL
    Logical path: ARCHIVE_GLOBAL_PATH_WITH_ARCHIVE_LINK
    Physical file name: E:SAPContRepZ5RMM_EKKO11180104855_CLL
    E:SAPContRepZ5 is the root of the content repository and should according to the documentation contain the file during the delete phase and until final storage in the repository. But there is no file there.
    In the log of the write job there are the following entries:
    Job started
    Step 001 started (program RM06EW70, variant Z_DEMO_7, user ID CLL)
    Reading purchasing documents
    Archiving session 000913 is being created
    Path:
    Name for new archive file: RMM_EKKO11180104855_CLL
    1 of 1 purchasing documents processed
    Job finished
    I am a little concern about that no path is written to the job log - could maybe mean something.
    Any ideas?
    Thanks,
    Claus.

  • Mac os x mountain lion The volume is already used for Time Machine backups

    Hey
    I downloaded the Mac OS X Mountain Lion and then I clicked on the hard disk and then was "The volume is already used for Time Machine backups.
    Can you help me please

    Well, this isn't a download window, it's an installer window. You need to select one of your hard drive volumes on which to install Lion.
    Your computer's main drive apparently has been used by you for TM backups which is a first class "no no." See: OS X v10.6, OS X Lion- Cannot install Mac OS X v10.6 or later on a volume used by Time Machine for backups.

  • ACE Error - NCOALink Parameter Error, Customer ID already used for customer

    ACE Error - NCOALink Parameter Error, Customer ID already used for customer "[customer name]", list "[list name]"
    Received this error and not sure if its due to the Customer/List ID & List Name combination or some thing else.  Any ideas?
    Also, is there a document that explains ACE errors.
    Thank you!

    Greetings cbeaure,
    For something like this I normally suggest logging an incident with Support at service.sap.com . 
    However I thought it might be heplful to answer your questions and provide you with the example you would have located by using the Knowledgebase search when logging the issue with the Support team.
    During the process of logging an issue to Support on the SAP Service Marketplace, you would be prompted for a search in the Knowledgebase. By entering in the error you received, you would have seen the following:
    Cause:
    This error will occur when either the List Name or Company Name was changed, but the PAF ID (specifically the Customer\List ID) has not changed.
    Resolution:
    The software has verification in place that requires a unique NCOALink PAF ID for the combined parts of the List Name and Company Name. This meets the Licensee's requirement, as described by the USPS in the Limited Service Provider and Full Service Provider Performance Requirements:
    "Licensee will assign each NCOALink customer file, list, or database a unique NCOALink PAF ID. This ID will be used by the software to verify that the customer has a valid, active PAF on file with Licensee. This ID will also be used to provide a relationship between Licensee's service log and PAF information files. The format of the ID will be an eighteen character alphanumeric field consisting of four sub-parts.  The Licensee will ensure that each of their customers has a unique and never duplicated PAF ID. The software must not allow duplicate IDs. The ID shall be assigned by Licensee upon execution of the Processing Acknowledgement Form and be used throughout the system as prescribed."
    (Continued on next post, end part 1)

  • Do we require 2 FIM Licence if installing FIM portal on 2 servers for HA

    Hi,
    We are installing FIM portal on 2 windows servers for achieving HA.
    Please help by sharing will it cost us two FIM Licence to do that.
    Thanks,
    Varun

    On Tue, 18 Feb 2014 15:57:20 +0000, var9287 wrote:
    We are installing FIM portal on 2 windows servers for achieving HA.
    Please help by sharing will it cost us two FIM Licence to do that.
    Yes. A server license is required for any server on which FIM is installed.
    http://download.microsoft.com/download/5/4/8/548C1F3D-0816-48D5-8454-2AE1F18DD01E/Forefront%20Identity%20Manager%202010%20R2%20Licensing%20Datasheet.pdf
    Paul Adare - FIM CM MVP
    Niklaus Wirth has lamented that, whereas Europeans pronounce his name
    correctly, Americans invariably mangle it into "Nick-les Worth". Which is
    to say that Europeans call him by name, but Americans call him by value.

  • TREX on Portal-Server also used for search/index for SAP Records Management

    Hi all,
    can a installation of the TREX on the Portal-Server (or as separate Server) used for Portal Index/search and also in parallel for searching of Content in an SAP Records Management (means full text research of records/ dossier in the SAP RM) ? Some ideas, tips or settings to keep in mind ?
    THX
    mario

    Hi Neil,
    We have exactly the same problem. We installed a new SAP E-Commerce system on Microsoft Windws 2008 R2 with TREX Version 7.10.43.00. The TREX connection is okay. Also the catalogue replication works without any problems. The SAP support means it is a permission problem on the IIS. The problem isnu2019t solved yet and the message to the SAP support is in process.
    What is your effect with this link?
    http://localhost:<TREXNAMESERVER>/TREXHttpServer/
    Default:
    http://localhost:<30305>/TREXHttpServer/
    Kind regards,
    Roland

  • Application to iBooks problem: iTunes account already used for apps

    Hi,
    I work at a publishing company, where we have an iTunes Connect account we use to sell apps to the appstore. I'm trying to use this same account to distribute iBooks as well. So I go to the application portal at https://itunesconnect.apple.com/WebObjects/iTunesConnect.woa/wo/7.0.0.9.7.3.1
    where it says you can submit multiple different media type using the same accoutn as long as you apply seperately for each. I choose Books from the dropdown, then fill in my First/Last name, AppleID, and password, check the box to agree, and then I get the following error:
    "The iTunes Store account entered has already applied to distribute Apps on the iTunes Store. To continue with this application, you must enter a different iTunes account."
    I don't understand this as it seems to contradict the other information about being able to sell multiple media types with one account. Am I supposed to make a new AppleID? A new iTunes account? What do I need to do to sell iBooks?
    please help!
    many thanks

    I have registered with iBooks, but will also need to sign up to sell Apps really soon. Posts in the thread confuse me a lot, since they are mixed to the point of being mutally exclusive.
    So do I really need a separate TIN/EIN and company or what?
    I mean Apple is quite specific that I'll need another Apple ID for every time of content
    "If you currently have an iTunes Connect account to sell another media type, you cannot create a second iTunes Connect account with the same Apple ID. You’ll need to set up a new Apple ID and use it to complete a separate book application."
    But - really will Apple  flag a mistake for using same legal address, company name and etc?
    Still hope @sfomel is right and/or I'll be lucky not to face all the above mentioned problems.
    Will definitely post here to tell how it went. In the mean time I suggest using that e-mail [email protected]
    I did hear back from them.

  • HT201335 I want to hook up an Apple TV device to my TV but only have one HDMI connection that's already used  for my HD cable box. Can I connect the Apple TV device to my TV that has  s video, PC in and  component jacks unused ?

    I want to hook up Apple TV but my One HDMI Jack on my TV is already connected to my HD cable box. My TV has jacks for s video, component, and PC in jacks.
    Can I use one of them to connect to Apple TV with some type of cable to my newer I-pad ?

    Here are the Apple TV outputs.
    What other outputs does your HD cable box have?
    Apple TV (2nd and 3rd generation): Guide to ports and connectors
    http://support.apple.com/kb/HT5713
     Cheers, Tom

  • HT5621 Trying to change the email on my apple ID but get error message that the email I want to change to is already used for notifications. What do I do?

    Hi,
    I'm trying to change email address on my Apple ID since the email registered for the account has been hacked and I can't access it anymore. The email I want to change to is connected to another Apple ID I created about 4 years ago, though I successfully changed the email on that account as well. So the email I would like to use for my main Apple ID shouldn't be "locked" anymore.
    Though, when trying to change the email on my Apple ID I get an error message (in Swedish, so this is a direct translate from google): "This e-mail address is your email address for notification. It can not be used as the Apple ID or primary email. Choose a different address."
    I'm not really sure what this means or how I can fix this. The email address is connected to my Ipad and Iphone for the email app, can that have anything to do with it?
    If it makes any difference, I updated both my Ipad3 and Iphone4 to ios 7 today. I'm trying to change from my Macbook air though.
    Please advise, would really appreciate a reply ASAP.

    caek1 wrote:
    Hi,
    I'm trying to change email address on my Apple ID since the email registered for the account has been hacked and I can't access it anymore. The email I want to change to is connected to another Apple ID I created about 4 years ago, though I successfully changed the email on that account as well. So the email I would like to use for my main Apple ID shouldn't be "locked" anymore.
    Though, when trying to change the email on my Apple ID I get an error message (in Swedish, so this is a direct translate from google): "This e-mail address is your email address for notification. It can not be used as the Apple ID or primary email. Choose a different address."
    I'm not really sure what this means or how I can fix this.
    It means exactly what it says... The email Address is in Use. You cannot re-use it.
    Apple ID Support  >  http://www.apple.com/support/appleid/

  • I'm planning to give this iPad to my brother in which I already used for a period of time,what should I do to make the settings like a brand new?

    should I delete my apple account.if yes.if ever I got my new iPad can I still retrieve all my stored files.

    Settings/General/Reset/Erase all Contents and Settings
    Then your brother can set it up as a new iPad.
    If you do this, you will lose non-iTunes-purchased music, photos, documents, saved progression of games, saved settings on other apps, etc. unless they are backed up somewhere else such as on a computer or through iCloud. After all, you are erasing all content and settings. It won't affect your iCloud stuff such as apps and music you bought through iTunes; you can re-download all that through iTunes. You can also redownload iCloud mail from the iCloud server.

  • How to tell which serial number was already used for CS5.5 Web?

    I have a 2 copies of CS 5.5 Web Premium at work.  I need to reinstall them on 2 laptops and 2 PCs.  Each copy has been used before on the laptops, but the hard drives on the laptops crashed and will need to be reinstalled.  Will this cause any issues?  Thanks in Advance!
    -Tim

    Contact Customer Service:
    Contact Customer Care
    Pick a topic like Creative Suite. Then pick a question. Choose the "Still Need Help" option and you should see Web Chat.

  • Combinding Resources in the FIM Portal Navigation Bar

    We have two different OUs for computers in our AD that have the same attributes. Server and Workstation, there is no attribute that indicates if the computer is a server or a workstation. My solution was to create two different MAs, AD Server MA and Workstation
    MA and corresponding Metaversa objects and FIM schema objects. All good so far, I sync the appropriate computer objects from each ou into their corresponding FIM schema objects.  I have created FIM Portal Navigation Bar Resources for each
    that show the Servers and Workstations correctly.  My question is this,  I would like a Nav Bar resource - Computers - that combine both of these resources, and then under Computers have Servers and Workstations - is this possible?
    Computers
          Servers
          Workstations
    Thanks in advance

    Hello,
    thats quite easy to do.
    Simple create a "Search Scope" that includes both Computer types.
    Use this search scope as the Navigation Bar URL, the easiest way to get the URL (which contains the GUID of the Search Scope) is to add "Global" to the Search Scope Keyword, after that you can use the Search scope from the FrontPage of the Portal
    for a search. In IE you should then see the URL for this Search scope an can use this in the NavBar Res.
    The article ManuJ mentioned above will help you with that, here is the link:
    https://technet.microsoft.com/en-us/library/ff393653%28v=ws.10%29.aspx?f=255&MSPPError=-2147217396
    -Peter
    Peter Stapf - ExpertCircle GmbH - My blog:
    JustIDM.wordpress.com

  • Linking of Public URLS to FIM PORTAL & Registration Portal & Reset Portal

    As we all Know we have 3 Portal
    We have
    1) FIM Portal on port-80 :
        Internal URL- http://<appserver name>/IdentityManagement/default.aspx
    2) FIM Password Registration Portal- Port 8080
        Internal URL- http://<appserver name>:8080/default.aspx 
    3) FIM Password Reset Portal- Port 8081
         Internal URL- http://<appserver name>:8081/default.aspx 
    I want these URLs to connect to Public Urls
    1) fimportal.com
    2) fimregportal.com
    3) fimresportal.com
    I have tried for FIM PORTAL- Alternate MAPPING USING DNS -- but it's goin to TEAM SITE and then we provide Credentials >> then All SITE CONTENT >> then Microsoft Forefront Identity
    Then we have the portal.
    We want whenever user browse "fimportal.com" >> goes to http://<appserver name>:8080/default.aspx  url >> ask for credentials >> Fim Portal.
    Please suggest.

    FIM Password Registration Portal :
    Open the 8080 Port.
    Add a “A” Record for http://<appserver name>:8080/default.aspx in
    DNS and pointing it to Public IP.
    FIM Password Reset Portal :
    Open the 8081 Port.
    Add a “A” Record for  http://<appserver name>:8081/default.aspx  in
    DNS and pointing it to Public IP.
    FIM Portal:
    We can Redirect to the FIM Portal.

Maybe you are looking for

  • CUP Provisions user to SAP successfully but gives "Auto-Provisioning" error

    Hi All, I'm getting an "auto-provisioning" error in CUP when a "Change Account" workflow is approved. The strange thing is, CUP does successfully provision the change to the SAP backend. Yet, the "New Account" provisions successfully without the erro

  • Hope someone may be able to help

    Helo everyone  i was wondering if someone could help me out with this problem that i,m having, my specs are in my sig, ok i install the win xp 64 beta, then i install all the motherboard drivers for the 64 edition, but when it comes to installing my

  • Wage Type  is not valid for allowance grouping

    Gurus     When i am Executing PC00_M40_TERM and entered Details then in very next screen it is with error    ''Wage Type  is not valid for allowance grouping '' The Issue is showing generic and No specific Wage type shown in error. ABAP Team also Deb

  • V$license and concurrent managers

    Are concurrent managers considered part of session limits in terms of licensing. In other words, do they count as sessions towards license limits? Thanks.

  • How can I publish a book

    How can I publish a book in I book store please help