Provision a RO several times with one user using Access Policies

Hello,
we need to provision several Unix machines and for this purpose, we use one only resource object (SSH User). Additionallyl, we created an access policy for every machine:
- Access Policy Unix Server 1
- Access Policy Unix Server 2
- Access Policy Unix Server N
We created the following group in OIM: SSH Group.
We set the policies in such a way that whenever a user is added to the SSH Group, the SSH User RO is provisioned with the user for every machine. We created several access policies, because the parameters of the form are different for every machine.
The problem is that when a user is added to the SSH Group, the SSH User resource object is provisioned only once. It is provisioned by the access policy with the highest priority. We would like that the SSH User RO was provisioned by every access policy. That is, the user should have the SSH User RO provisioned N times, after adding it to the SSH Group.
Is there any way to achieve this without creating a resource object for every Unix Machine? We need to provision more than 300 Unix machines and this would require a lot of time...
Thank you for your help

There are other options. You could create a child table to hold the IT Resource information, assuming all parent data is the same for every system. Then on the insert/delete to child table entries, you can provision and de-provision from that target. On disable/enable you would need to search through the child table and perform the action against all instances. The same for the other update tasks.
This is the limitation of access policies. They manage a single resource object target instance. You could also code a generic resource that has child table entries. When an insert happens, you can use the APIs to provision and instance of the specific target with the provided details. Then you could create access policies to add entries to the child table, and each would provision the appropriate object, and deprovision too.
Takes some custom code, but it's doable. Just remember though that they are all still the same resource object, so reporting would show them all, as well as attestation, as a single instance, with multiple provisioned to each user.
Another option is to duplicate the work flow using find and replace in the XML and generate a unique workflow for each instance.
-Kevin

Similar Messages

  • I tried to upgrade the ios on the phone and I was asked for my icloud user and password. I don't remember these exactly and I tried several times with different options but unsuccessfully. I also forget my email used to configurate the phone.

    How i said on the question. I tried to upgrade the ios on the phone and I was asked for my icloud user and password. I don’t remember these exactly and I tried several times with different options but unsuccessfully. I also forget my email used to configurate the phone. I have the phone box and the bill. I sent you an email with my problem and attachments with the box informations, the bill and the reset request. What to do? You said to me:
    Your request comes from an unrecognized email domain. Apple accepts email requests only from email domains for Apple-authorized carriers.
    Please re-submit your request using your official carrier domain.
    but this email is authorized, what to do??
                                                                                                              respectfully, Beba

    If you have forgotten then these links are the only way to resolve
    http://www.apple.com/support/appleid/
    As long as you have owned the iPhone from new and your Apple id is the one used to activate when new
    OR have you recently purchased the iPhone secondhand ?

  • Locking a JSP Page i.e allowing only one user to access it at a time

    Hi,
    I have web application where multiple users can log in at the same time.
    I have a JSP where a user is presented with a list of executable items.It is quite possible that at the same time more that one user tries to execute the same item.I want to disable this. i.e at a time only one user should be able to execute the item.
    Currently what i can think of is putting an extra column in the database...saying that this item is locked and you cannot access it until unlocked.But then this would involve a round trip to database.I want to avoid it, and do some coding in java code itself.
    But i dont know how to proceed.
    Any Help......

    sorry for the misdirection :(
    yes..try using the synchronizing for the run process for of the item in the action class.
    I shall try to provide you with the code changes, if can you please provide the back end code doing the job u said

  • Problem opening pdf's with one user

    Hello,
    We deployed adobe reader X on a terminal server 2008 with about 10 users, which login directly via an rdp session (no broker).
    With one user, we have the problem that when she tries to open a pdf (either directly, in a browser, from outlook, whichever),
    then the adobe reader program appears in the taskbar and then the program is gone. We tried the following things
    - Kill the adobe reader process
    - Repair adobe reader using the software install tool
    - Downgrade to adobe reader 9.4.1 by uninstalling X and installing 9.4.1 (a version which is used extensively without problems at another customer)
    - Delete the terminal server roaming profile and create a new one in active directory on the domain controller.
    Other users have no problem with this and a testuser with the same rights (copy function in AD) does not have this issue.
    Every time we apply one of the above solutions, it works for 15 minutes and then we are back to the original symptoms.
    The adobe reader process seems to be still active after you close a document and after it stops working.
    Does anyone have a clue on how to fix this permanently?

    This is a problem (bug) with the built-in PDF Viewer (pdfjs) that currently doesn't handle this link properly.
    *http://starkhealth.org/enviro/GRADE%20A%20FOOD%20EXCELLENCE%20AWARD.pdf
    I've seen issues like this before, but can't find a bug about this issue.

  • Error accessing the UWL only with one user

    Hi,
    We have a problem only with one user, when the user access the UWL get the following error:
    Runtime error in the portal
    Exception in processing request, send the ID of exception to your portal ADMINISTRATION
    ID exception 10:54_21/10/11_0037_8766350
    The other user does not have problems accessing the mailbox.
    The user is assigned the role of the mailbox correctly.
    Any idea what may be the problem?
    Thanks and regards

    Hello,
    The best way to see what these issues are is to check the trace for when the run time error has occured:
    Log on to the portal, recreate the runtime error.  Then follow:
    1596214 How to find the latest default trace from right after
    reproducing an issue.  Please ensure that you have reproduced the
    issue with a user that is experiencing the issue that you have reported.  When you find the most recent default trace file, copy and paste the numbers from the portal screen and do a ctrl + F with the trace file opened and paste in the runtime error.  Now you should be able to see what is causing this issue.
    Then when you get this information, please paste or attach the file here that contains the runtime error for the user.  From this we should be able to figure out why the user is getting this.
    Also as an admin user, try clearing this users personalizations on the Universal Worklist first.
    Please clear all personalizations with the affected user and retest.
    Here is the help link to show you how to clear the personalizations:
    http://help.sap.com/saphelp_nw70/helpdata/EN/29
    /441f6f09364bcab17f94490555bee4/content.htm
    If clearing the personalizations does not help this user, please attach the trace file showing the runtime error. 
    Beth Maben
    EP - Senior Support Consultant II
    AGS Primary Support
    Global Support Centre Ireland
    Please see the UWL Wiki @
    https://www.sdn.sap.com/irj/scn/wiki?path=/display/bpx/uwl+faq  ***

  • Every time I create an account with iCloud then try to open it I get wrong ID or password. Even when I enter my birth date I am told it is incorrect. I have done this several times with the same results.

    Every time I create an account with iCloud then try to open it I get an error message: wrong ID or password. Also when I enter my birth date I am told it is incorrect. I have done this several times with the same results.

    Oldcameraman
    Please do not duplicate a thread. The threads are answered as soon as possible. We are not Adobe. Just user to user.
    I have answered your most recent of the duplicates
    Premier Elements 13 Organizer Works. Editor doesn't. Log in doesn't work
    It is uncertain just how far we can go to help you since you do not appear to have Premiere Elements any
    longer.Seems you demanded a refund from Adobe Chat, got it, and now are left with a non purchased program which I
    am not sure can be used.
    Duplicates tend to confuse the person asking the question as well as those attempting to reply. As I suggested in the
    above mentioned thread, try to sort out your situation with Adobe via its Adobe Chat.
    ATR

  • Garageband unexpectedly quits on launch with one user

    Strange happenings with Garageband since upgrading to Lion (Lion upgrade might be a co-incidence). Garageband works fine with one user but doesn't launch with another user - it unexpectedly quits every time on launch. Have tried repairing permissions and re-installing Garageband. Not sure what else to do. I can't find any Garageband prefs to dump. I guess something in this user's setup is conflicting, But what? Any ideas?

    I think you need to reinstall the OS to fix that one.
    This file
    Library not loaded: /usr/lib/libutil.dylib
      Referenced from: /usr/lib/libCoreStorage.dylib
      Reason: malformed mach-o image: load command #0 length (4294967295) would exceed sizeofcmds (4294967295) in /usr/lib/libutil1.0.dylib
    is damaged and it's part of CoreStorage, an OS level element.
    http://support.apple.com/kb/PH10763

  • HT1212 unable to disable ipod, tried to restore several times with no luck

    unable to disable ipod after entering incorrect passcode multiple times (says try again in 22,000,000 min). have tried to restore on itunes several time with no luck.

    Disabled
    Place the iOS device in Recovery Mode and then connect to your computer and restore via iTunes. The iPod will be erased.
    iOS: Wrong passcode results in red disabled screen                         
    If recovery mode does not work try DFU mode.                        
    How to put iPod touch / iPhone into DFU mode « Karthik's scribblings        
    Also try
    Place the iPod in recovery mode using one of these programs:
    For PC
    RecBoot: Easy Way to Put iPhone into Recovery Mode
    If necessary:
    Download QTMLClient.dll & iTunesMobileDevice.dll for RecBoot
    and                                           
    RecBoot tip
    For MAC or PC       
    The Firmware Umbrella - TinyUmbrella
    For how to restore:
    iTunes: Restoring iOS software
    To restore from backup see:
    iOS: How to back up     
    If you restore from iCloud backup the apps will be automatically downloaded. If you restore from iTunes backup the apps and music have to be in the iTunes library since synced media like apps and music are not included in the backup of the iOS device that iTunes makes.
    You can redownload most iTunes purchases by:
      Downloading past purchases from the App Store, iBookstore, and iTunes Store

  • HT1206 Lots of info about one user using multiple computers. What about multiple users with separate Apple IDs using same computer? Having problems getting my wifes new iPhone talking to her apple account on the computer we share (2 users)

    Lots of info about one user using multiple computers. What about multiple users with separate Apple IDs using same computer? Having problems getting my wifes new iPhone talking to her apple account on the computer we share (2 users)

    You need to create a user account for your wife (or yourself depending on who has the current user account). When syncing, each of you should sign in as a separate user, login to iTunes and then sync. I had this problem when my sister got an iPhone. When we did her initial sync, everything on my iPhone showed up on hers. Apple gave me this solution.

  • HT204053 I did not know my kids had set up an Itunes account for me with one user name and password.  then i got an i phone and set it up with a different email address and new password.  how can i get my accounts to merge so i can have all of my music on

    I did not know my kids had set up an Itunes account for me with one user name and password.  then i got an i phone and set it up with a different email address and new password.  how can i get my accounts to merge so i can have all of my music on my iphone

    Quote: "You cannot merge two or more Apple IDs into a single one. You can, however, use one Apple ID for iCloud services and another Apple ID for store purchases (including iTunes in the Cloud and iTunes Match). See “Using one Apple ID for iCloud and a different Apple ID for Store Purchases” above for details." See also Apple ID & iCloud FAQ: http://support.apple.com/kb/HT4895?viewlocale=en_US&locale=en_US
    You can set up your iCloud account on your iOS device under: "Settings > iCloud" and a other account for store purchases under "Settings > iTunes & App Stores". Unfortunately merging accounts is not possible but you could transfer all of your music manually via iTunes from your Mac or PC.

  • My iPad no longer recognizes my Zagg keyboard.  Turned it off and on several times.  One suggestion in manual is a dead battery.  Where is a battery on a Zagg case?  The iPad battery is fully charged.

    My iPad 4 no longer recognizes my Zagg keyboard.  Turned it off and on several times.  One suggestion in manual is a dead battery.  Where is a battery on a Zagg case?  The iPad battery is fully charged and Bluetooth is on and the Zaggkeys PROfolio is listed but says NOT CONNECTED.  What else should I try?

    Well, you shoud tap the line where it says not connected, and it should prompt you to enter something.  Regarding Zagg products, http://www.zagg.com/keyboard-cases/index.php?gclid=CIPgv7O_oL0CFQ8OOgodvnoA1w&ef _id=Uo5AsQAABFW6AX3n:20140320063435:s
    is the link to Zagg's website.

  • I created a 2nd library for my husbands music and now I can't find my original library. I did hold down the shift key to open itunes but is still comes up with the new library. What am I doing wrong? I tried several times with no luck. Thank you.

    I just got an Ipod Classic recently and downloaded Itunes. Got my music on my Ipod. My husband just got an Ipod Touch. I followed the directions on how to create a 2nd library and was able to load his music onto his Ipod. My problem is now I can not find my original library. I did what the directions said about holding down the shift key while opening Itunes and it still goes to the 2nd library that I created. How do i get my original library to come up? I tried several times with the same results. Please let me know what I need to do to be able to get into either library. Thank You.

    Does the original library file still exist on the computer?  Hopefully when creating the new library it was done in a seperate folder as I do not believe iTunes allows for two library files in the same location.

  • IPhone 5c was powered off; when turned back on screen only shows in black and white.  Have tried several times with no success. Any suggestions?

    I purchased the iPhone 5c about 4 months ago.  I turned it off briefly last night and when I turned it back on, the screen wallpaper and app icons are now in black and white.  I have tried turning it off and on again several times with no success; screen still shows only black and white.  All other functions of phone/text work correctly. Any suggestions on what to try?

    Hello Teri,
    You may have greyscale turned on. Try going to Settings > General > Accessibility and toggle that off and it should go back to color. Check out the page below for more information. 
    Invert Colors and Grayscale
    http://help.apple.com/iphone/8/#/iph3e2e1fb0
    Regards,
    -Norm G. 

  • Firefox will not open after installation. i have tried to install several times with the same results. installation sends a list to firefox each time. need help. willard lee

    will not open after installation. i have tried to install several times with the same results. installation sends a list to firefox each time. need help. willard lee

    Can you attach a screenshot or link to the instructions you are following?
    You are on the 3.6 release and Firefox 7.0.1 is out. You can download and install the latest release from http://www.mozilla.org/en-US/firefox/new/ if you would like to update now. The 3.6 version will be maintained for a while longer, but you should update when you can.

  • Can not sync iPhone 4 since upgrading to latest software release.  Keep getting a message that required file can not be found.  I've tried restoring several times.  I am using  Mac PC with the latest software release.

    My iPhone 4 will not sync since upgrading to latest software release.  I keep getting the error message "required file cannot be found".  I've tried restoring several times with no success.  I am using a MacPro notebook with the latest software release.

    My iPhone 4 will not sync since upgrading to latest software release.  I keep getting the error message "required file cannot be found".  I've tried restoring several times with no success.  I am using a MacPro notebook with the latest software release.

Maybe you are looking for