Linking Multiple Resource Accounts via Active Sync

Ok guys/gals the scenario is... We have one idm account linked to accounts on one resource, and we want to be able to link them up via Active Sync...We don't care about the attributes, just want to make sure that if a another account for a user is created outside of IDM we can grab it and link it. So far, I've seen that the active sync process will see the new account, correlate it to a user, but it will not link the user...And outside of doing a custom Process Rule workflow, I'm not seeing any other way to get the accounts to link via active sync. Is what we are trying to do a reconciliation thing only? Have I missed something?

Yes. You can add a field to your ActiveSync form to do this: Here is an example with AD:
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE Configuration PUBLIC 'waveset.dtd' 'waveset.dtd'>
<Configuration name="Sample ActiveDirectory ActiveSync Form" wstype="UserForm">
     <Extension>
          <Form name="Sample ActiveDirectory ActiveSync Form">
               <Field name="processType">
                    <Default>
                         <s>NONE</s>
                    </Default>
               </Field>
               <Field name="dispatcher">
                    <Expansion>
                         <cond>
                              <eq>
                                   <upcase>
                                        <ref>feedOp</ref>
                                   </upcase>
                                   <s>UPDATE</s>
                              </eq>
                              <block>
                                   <set name="update.selectAll">
                                        <s>false</s>
                                   </set>
                                   <dolist name="resObj">
                                        <ref>waveset.accounts</ref>
                                        <block>
                                             <set name="resName">
                                                  <get>
                                                       <split>
                                                            <ref>resObj</ref>
                                                            <s>:</s>
                                                       </split>
                                                       <i>1</i>
                                                  </get>
                                             </set>
                                             <set>
                                                  <concat>
                                                       <s>update.accounts[</s>
                                                       <ref>resName</ref>
                                                       <s>].selected</s>
                                                  </concat>
                                                  <s>false</s>
                                             </set>
                                             <cond>
                                                  <match>
                                                       <ref>resName</ref>
                                                       <ref>activeSync.resourceName</ref>
                                                  </match>
                                                  <cond>
                                                       <eq>
                                                            <ref>
                                                                 <concat>
                                                                      <s>waveset.accounts[</s>
                                                                      <ref>resName</ref>
                                                                      <s>].accountGUID</s>
                                                                 </concat>
                                                            </ref>
                                                            <ref>activeSync.objectGUID</ref>
                                                       </eq>
                                                       <set name="resourceName">
                                                            <ref>resName</ref>
                                                       </set>
                                                  </cond>
                                             </cond>
                                        </block>
                                   </dolist>
                                   <cond>
                                        <isnull>
                                             <ref>resourceName</ref>
                                        </isnull>
                                        <set name="processType">
                                             <s>LINK</s>
                                        </set>
                                        <set name="processType">
                                             <s>UPDATE</s>
                                        </set>
                                   </cond>
                              </block>
                         </cond>
                    </Expansion>
               </Field>
               <Field name="IAPI.cancel">
                    <Expansion>
                         <s>true</s>
                    </Expansion>
                    <Disable>
                         <eq>
                              <ref>processType</ref>
                              <s>LINK</s>
                         </eq>
                    </Disable>
               </Field>
               <Field name="doLinking">
                    <Expansion>
                         <block>
                              <append name="waveset.resources">
                                   <ref>activeSync.resourceName</ref>
                              </append>
                              <set>
                                   <concat>
                                        <s>waveset.accounts[</s>
                                        <ref>activeSync.resourceName</ref>
                                        <s>].accountId</s>
                                   </concat>
                                   <ref>activeSync.identity</ref>
                              </set>
                              <set>
                                   <concat>
                                        <s>waveset.accounts[</s>
                                        <ref>activeSync.resourceName</ref>
                                        <s>].sAMAccountName</s>
                                   </concat>
                                   <ref>
                                        <s>activeSync.sAMAccountName</s>
                                   </ref>
                              </set>
                              <set>
                                   <concat>
                                        <s>waveset.accounts[</s>
                                        <ref>activeSync.resourceName</ref>
                                        <s>].accountGUID</s>
                                   </concat>
                                   <ref>activeSync.objectGUID</ref>
                              </set>
                         </block>
                    </Expansion>
                    <Disable>
                         <neq>
                              <ref>processType</ref>
                              <s>LINK</s>
                         </neq>
                    </Disable>
               </Field>
          </Form>
     </Extension>
     <MemberObjectGroups>
          <ObjectRef type="ObjectGroup" id="#ID#Top" name="Top"/>
     </MemberObjectGroups>
</Configuration>

Similar Messages

  • Assigning Multiple Resource Accounts to IdM User Account in IdM 7.0

    Hi All -
    Has anyone tried assigning multiple resource accounts to a IdM User with IdM 7.0 by creating a Account type using Identity Rules. I tested it on Simulated Resource and it works fine. But for Active Directory, which has personal accounts and Admin accounts on different OU on AD, when I am trying to do the Bulk Upload. The bulk upload is able to do link up the Admin account on AD to user account. But then it tries to create an additional account as well even though the user that executed the Bulk action has a Blank form assigned. Has anyone been able to figure this out yet ? If yes, can you please provide some inputs on this ?

    Hi All -
    Has anyone tried assigning multiple resource accounts to a IdM User with IdM 7.0 by creating a Account type using Identity Rules. I tested it on Simulated Resource and it works fine. But for Active Directory, which has personal accounts and Admin accounts on different OU on AD, when I am trying to do the Bulk Upload. The bulk upload is able to do link up the Admin account on AD to user account. But then it tries to create an additional account as well even though the user that executed the Bulk action has a Blank form assigned. Has anyone been able to figure this out yet ? If yes, can you please provide some inputs on this ?

  • Hotmail via Active Sync on iOS 5.1

    Hi
    I've just set up a hand-me-down 3GS for my wife. I have set up a work email account for her successfully through Microsoft Exchange and then tried to set up Hotmail through the predefined setting - which I believe means through Exchange or Active Sync - and initially it was fine. All the folders synced and the iPhone downloaded the messages.
    However, since then, it won't download any new messages - it just sits and says it's checking but nothing happens. So I ended up deleting the account and re-installing it but now I just get an message saying "Cannot Get Mail - The Connection to the server failed".
    No amount of deleting the account and re-installing it works. No problems accessing Hotmail via the web. And I managed to send a simple text email from the Mail App on this phone to my own iPhone successfully.
    But I don't understand why it won't work now.
    Does anyone have any ideas? I've trawled the internet but can't find an answer.
    Thanks for any help.

    I have been getting the same problem for a couple of days now on my 4S (iOS 5.1).  Hotmail was working fine, now all of a sudden I get the "Cannot Get Mail - The Connection to the server failed" message. 
    Have tried to reset and restore the phone, delete items from my inbox, changed the sync days to no limit and anything else I have found suggested on the net.  Still no luck.
    If I delete my hotmail account from the iphone and add a different account (still hotmail) that works fine.  If I then delete that and try to put mine back on there the problem comes straight back!!!
    I am sure like you all, it is really starting to annoy me now!!  Anyone got any ideas??  Apple HELP!!!!

  • Create or link a resource-account

    Hi all,
    I create idm-users based on an hr-system, but don't assign them roles or resources during creation. Later, roles are assigned to those accounts which can imply resources.
    To keep it simple, there is a role "member in active directory" and when this role is assigned, a distinguished name shold be constructed and the resource account should be created.
    This is simple and works. :-)
    However, this process is slow and some admins just can't wait and they manually create an account in our active directory. They follow the same naming conventions, so when a role is assigned to the idm-account, SIM tries to create an account in the AD, finds one and links it. This is exactly what I want to happen.
    But: SIM assigns default values for the resouce account, e.g. default group memberships. Currently I can't detect that there are already values (since according to SIM the account doesn't exist yet) and customised group memberships are overwritten by SIM.
    That's BAD.
    Any suggestions how to handle this setup would be greatly appreciated.
    Yours,
    Patrick.

    HI,
    I dont mean to be rude or anything; but, it might be a good idea to tell those "admins" directly NOT to create accounts themselves!
    IDM's purpose, after all, is to manage situations like these. IDM is, and should be, the only "governing body";
    IDM is a complicated enough software, without having to create more problems for it. Which is exactly what your "admins" are doing by side-stepping IDM and creating accounts themselves in the Resource.

  • Calendar & Contacts do not Sync to iPhone via Active Sync

    I've been trying to figure this out for 3 days now. I have searched all over this site and the Internet in general and nothing I have found has fixed the issue.
    Basically, starting last week, my Push mail from Exchange started draining my battery from 100% - dead in about 8 - 10 hours. I turned off Push and my battery draining issues went away.
    On Monday while searching the net for assistance with the battery draining issue I saw a suggestion to delete the account from the iPhone and re-add it. I did this and all h*ll broke loose.
    Ever since adding the exchange server back in the following issues exist:
    1. No contacts will sync over from my Outlook Mailbox.
    2. No calendar entries will sync over from my Outlook Mailbox.
    3. Only a handful of existing mail messages synced over after adding it (doesn't matter what I set my number days/months to save).
    4. New mail seems to show up fine, but if I read it in Outlook it does not mark it as read on the iPhone and vice versa.
    5. If I get a new invite for a meeting it adds it to my calendar on the iPhone but I dont' get any of the options to accept/decline.
    I have tried everything I can think of an all of the suggestions that have been posted online. I've even gone as far as deleting/archiving EVERYTHING out of my mailbox, including contacts, calendar entries, tasks, all mail sent and received, you name it. Nothing I do gets Active Sync working the way it should.
    I've added and removed the exchange account to/from my iPhone so many times I can practically do it blindfolded. I even restored my iPhone to factory defaults and then restored a backup I had from before the problems started occurring.
    Other co-workers on the same Exchange server are not having these issues.
    Any ideas from anyone? I'm trying to see if I can get some assistance from our Exchange team but I don't know what if any help I will get as this is not a supported device on our network.
    One thing that I can't seem to do (probably the version of Exchange we are running) is get to the mobile devices section of the Outlook Web Access Client to delete the iPhone profile.
    FWIW, this is an original iPhone running 2.2.

    I have this exact same issue!
    I was on 2.0.1 running fine until late last week, noticed emails would not show up unless I had opened them in outlook. I thought I ran into a bug so I upgraded to 2.0.2. Now I can sync my email if outlook had them opened previously, but no calendar or contacts at all. I don't think my exchange admins will move me to another server, any other ideas?
    I love my iphone but if these features don't work I can't use it. I would appreciate any ideas.

  • Turn "Delete Resource Account" for Active Directory into rename/move/unlink

    My Windows sysad would like me to stop deleting Active Directory users; he's tired of cleaning up from dangling SIDs, and I don't particularly blame him. Instead, he would like the process of "deleting" an AD account to be more like:
    1. disable
    2. rename from cn=user to cn=user_999, where 999 is replaced with an incrementing number (jsmith_001, jsmith_002, etc.). (Or maybe he;d be Ok with jsmith_yyyymmddhhmmss...)
    3. move (probably in the same "rename" above) from ou=Employees to ou=4Delete.
    4. unlink account from user.
    We are assigning AD accounts through roles, and so the Delete Resource User (or Delete Resource Person?) task is invoked. Does anyone have a customized version of this task that differentiates between resource account types and handles the "disable/rename/move/unlink" AD account paradigm my sysad would like? -Les

    Hi,
    did you ever resolve this? If so, how did you work it out as we would like to do the same.
    Thanks.

  • Disable resource account via Workflow

    Hello I created a transition in the Update User workflow to disable a resource account if a field is indicated in the admin tabbed user form.
    This activity works but all resource accounts (email, AD) are being disabled. Only email needs to be disabled. How do I get the 'services' value to take effect?
    <Activity id='9' name='DisableAccountAccess'>
            <Action id='0' application='com.waveset.session.WorkflowServices'>
              <Argument name='op' value='disableUser'/>
              <Argument name='accountId' value='$(user.waveset.accountId)'/>
              <Argument name='doWaveset' value='false'/>
              <Argument name='services'>
                <list>
                  <s>emailResource</s>
                </list>
              </Argument>
            </Action>
            <Transition to='Notify'/>
          </Activity>also tried below code but have been unable to get it to work.
    <Activity id='9' name='DisableAccountAccess'>
            <Action id='0' application='com.waveset.session.WorkflowServices'>
              <Argument name='op' value='checkoutView'/>
              <Argument name='type' value='disable'/>
              <Argument name='id' value='$(user.waveset.accountId)'/>
              <Argument name='authorized' value='true'/>
              <Return from='WF_ACTION_ERROR' to='error'/>
              <Return from='view' to='disableAccView'/>
            </Action>
            <Action id='1'>
              <expression>
                <block>
                  <set name='disableAccView.resourceAccounts.currentResourceAccounts[emailResource].disabled'>
                    <Boolean>true</Boolean>
                  </set>
                  <set name='disableAccView.accounts[emailResource].disabled'>
                    <Boolean>true</Boolean>
                  </set>
                </block>
              </expression>
            </Action>
            <Action id='2' application='com.waveset.session.WorkflowServices'>
              <Argument name='op' value='checkinView'/>
              <Argument name='view' value='$(disableAccView)'/>
              <Argument name='authorized' value='true'/>
            </Action>
            <Transition to='Notify'/>
          </Activity>I would prefer to use the first method. Thank you in advance for your help

    After having a chance to actually look at the documentation I figured I'd add one more thing for those who happen to stumble across this in a search later. You are, of course, right. The services argument is what you need for disable user.
    For others reading this I should correct my previous posting. The "TargetResources" setting tends to be more of a form property rather than a workflow argument although it can be used with the checkoutView and checkinView workflow services. It is recommended by Sun, in the performance tuning guide, to keep views as small as necessary in order to speed things up.

  • Enabling right click for multiple user accounts via ARD

    Is there a way to enable secondary click on multiple user accounts at the same time using ARD? Is it possible to do this using a UNIX code? If so could someone give me an example of the code?
    Thanks in advance for any help.

    It should be something like:
    defaults write com.apple.driver.AppleHIDMouse Button2 2
    You'll need to get the exact domain name for your systems' mice; use
    defaults domains
    and look for the mouse driver entry.
    Regards.

  • HT1495 What do I do if none of my devices are being properly detected by iTunes when using multiple libraries (mostly via wifi sync)?

    Have a Windows 7 machine with terabytes of HDD space and 8 Gigs RAM. Two iTunes libraries (mine and my wife's with about 10% file overlap). Two iPhone 5s (iOS 6.0.2), 1 iPad 2 (iOS 6.0.1), 1 iPad 3 (iOS 5.1.1), and a jailbroken iPhone 3GS 32 GB that we've converted to an iPod essentially (iOS 3. something--not willing to update given the historically bad performance of the new iOS on the 3GS). Running iTunes 10 (also not willing to update to 11 after reading reviews).
    I get multiple errors in both libraries with lots of popup boxes saying devices cannot connect, be properly identified, or sync, etc. Disconnecting and reconnecting via cable is marginally better (more so with the 3GS less with the iPads).
    I'd like to be able to link certain devices to certain libaries (i.e. my iPhone5 and iPad3 with my library and my wife's iPhone5, iPad2, iPhone 3GS with her library). Instead it seems the wrong devices always show up or none at all.
    Any suggestions would be most welcome. I have a moderately high level of tech expertise, so if there are scripts or hacks to be written/run I wouldn't be shy about trying them. Also would consider an iTunes alternative given that Apple isn't interested in supporting users with massive music libraries who need powerful databases as opposed to the dumbed down stuff they are trying to push in 11.
    Thanks!
    PS also my home sharing doesn't work at all on any device, but that seems to be Apple standard
    tags: home_sharing ios windows7 working sync_itunes iphone5 ipad2 ipad3 iphone3gs multiple_libraries multiple_users multiple_devices sync itunes10 computer 10.5

    Latest problem now with iTunes is that I can't connect to the iTunes store or update art work. Freezes up. Clearly they nerfed old iTunes to make us upgrade to an inferior version. So frustrating.

  • Provision one OIM account to multiple resource accounts

    Hello everyone,
    We have a requirement to provision some OIM accounts more than once to the same target source. For example provision some user to two accounts in the target source, one normal account with the same user ID and another administrator account prefixed with "HS_". Is it possible?
    Thanks in advance

    It is possible as long as you check "allow multiple" in the resource object. Also, if you want to do auto-provisioning using Access Policy, you need to be on 9.1.0.2 BP12. Earlier release doesn't support provisioning to multiple instance of a same resource object using access policy.

  • How do I link multiple apple accounts?

    I have 3 apple ID's and 2 i tunes libraries...... I want to connect them so they are multi-funtional.???

    No such option exists - you can transfer content purchased/downloaded with one iTunes account to another iTunes account, and you can't merge multiple accounts. If any of the content includes DRM protection, that remains associated with the account that was used to download the content.

  • Multiple itunes accounts via one user on imac

    I have an iMac that has iTunes loaded and many of our devices are associated with one iTunes account.  I also have a business iTunes account with a separate contact list, music, etc.  Is it best to just setup a new user on my iMac and sync it there or is it possible to sync it under one user account?

    Is there any way Apple can remove the 90 day block, since I am legimiate owner of two accounts?
    Kento,
    I am afraid that your approach will not be viewed as legitimate.  The Terms and Conditions of the iTunes Japan Store state:
    "The iTunes Service is available to you only in Japan, its territories, and possessions. You agree not to use or attempt to use the iTunes Service from outside these locations. iTunes may use technologies to verify your compliance."
    The accepted way to do what you are doing is to have a single account, and change the country according to where you physically are.

  • Not receving emails via active sync unless outlook is running...

    testing my iPhone 3GS, running iOS4.01, trying to get my emails from an Exchange 2007 server. Everything was working fine until I was migrated to Exchange 2007. The funny thing is, if we disable TrendMicro ScanMail I can get my emails with outlook closed. If ScanMail is running, and outlook is open, no emails.
    We have a case open with TrendMicro, but no luck so far.
    Anybody else run into this?
    -Paul

    I have this exact same issue!
    I was on 2.0.1 running fine until late last week, noticed emails would not show up unless I had opened them in outlook. I thought I ran into a bug so I upgraded to 2.0.2. Now I can sync my email if outlook had them opened previously, but no calendar or contacts at all. I don't think my exchange admins will move me to another server, any other ideas?
    I love my iphone but if these features don't work I can't use it. I would appreciate any ideas.

  • Alerts not syncing via active sync exchange server

    I know others have posted about similar issues, but I have yet to see any solutions. The issue is that for any appointments I create in iCal, the Alerts do not sync to CalDAV calendar I have on my work's server. The appointments sync fine, but not the alerts. Will there be any upcoming software fix for this?

    ****.... return button..
    My iTouch has all the right settings from my IT department who uses a Exchange 2003 server.
    User name, password, server is right - at least we think it's right.
    Once I try to get Mail on my iTouch, it comes up with a "Cannot Get Mail - the connection to the server failed' error.
    I'm actually trying to sync my Entourage Calendar mostly. All setting are right under the preferences in Entourage for syncing. And my iCal on my computer creates a mirror image of my Entourage calendar.
    I can sync up the Calendar through iTunes, but don't really want to do this. Would rather have this happen WiFi.
    Is there anything I'm missing?
    I've reset my setting on my iTouch too. Done all that...read all the discussions, articles...
    The only level that it stops me at is getting mail. The odd thing was yesterday it sent a couple of test emails I created last week. ODD!
    Trying to get at least 75% of the capability out of this great technology.
    Thanks,
    Adam

  • Two accounts Exchange Active Sync on iphone

    I've one 3Gs Iphone OS 3.1.3.
    I use my iphone to work.
    I've 2 account Exchange by two enterprises and i want to receive and send mails by my iphone. One server is Exchange 2003 and the other is 2007.
    I proved to find one app on apps store it permits to me to receive and send mails.
    I bought OWA 2007 and OWA 2003 but they doesn't work!!!!!
    What may I do to have 2 accounts on my phone?
    Thanks GT

    No, both use Exchange Activesync so its only one possible. Even if two were possible, you only have one Calendar so the second couldn't have a calendar.
    You can set one as IMAP and use it without the calendar facility if their host supports that, and use the other as Exchange. Thats what I do.

Maybe you are looking for

  • Bad performance with brandnew system

    hello, i set up a completely new win7-64bit based on a fresh osx (snow-leopard update) on a fresh harddisk....and i have very bad 3d performance with only 3 (!!) programs installed. i am working with autodesk 3ds max and autocad and both run very slo

  • Connection test to database failed: could not connect to server

    I restarted one of my HPOV NNMi 9.23 servers this morning and NNMi is no longer loading.  I am seeing the following errors in the logs indicated: /var/opt/OV/log/nnm/public/nmsdbmgr.log 04/06/2015 09:28:05 AM Connection test to database failed: could

  • Magic Mouse on Windows XP PC

    Hi, I know this question has been asked before butI have still not found a solution that works for me. I have a Magic Mouse which I use on my Macbook but would also like to use on my work PC. I know there were drivers available at UneasySilence but t

  • White text on a white background when adding glossary definitions

    I inherited an existing IBA file so I'm not sure how the styles were defined (and I've never really played around with custom styles or layouts) but I was hoping it wouldn't matter.  The main color scheme is a dark background and light (white) text. 

  • Photoshop 5.0.2 upgrades / updates

    I currently own photoshop 5.0.2. What updates are available? Also, can I upgrade to a new version of Photoshop? If so, how and where?