User Application Role and Resource Provisioning Requests

Hi I'm using User application with IDM 4.7.
I would like to create a workflow in order to allow a manager to approve or revoque a Provisioning Request for roles and resources.
I noticed that under the UA/Entitlements in designer there is a series of templates of workflows.
But these workflows are only simulated by an PRD in AD and not by the Request page where users can normally request roles.
I've tried to solve this problem by adjusting the options of the role created in role catalog and require an approval from a manager.
But what is really weird is that once the user requests the role it is provisioned immediately without approval.
Is it normal to have such response? I think i must be missing something in the process.
What is the right way of doing this?
Parents
  • vkhoury;2491067 wrote:
    Hi I'm using User application with IDM 4.7.
    I would like to create a workflow in order to allow a manager to approve or revoque a Provisioning Request for roles and resources.
    I noticed that under the UA/Entitlements in designer there is a series of templates of workflows.
    But these workflows are only simulated by an PRD in AD and not by the Request page where users can normally request roles.
    I've tried to solve this problem by adjusting the options of the role created in role catalog and require an approval from a manager.
    But what is really weird is that once the user requests the role it is provisioned immediately without approval.
    Is it normal to have such response? I think i must be missing something in the process.
    What is the right way of doing this?


    I realized that once a user request a role the request remains in pending state for about 24 hours before appearing in the task section of the user responsible of provisioning the role.
    However, I don't know why it's taking that much time and if tif this can be configured or not.
  • vkhoury <vkhoury@no-mx.forums.microfocus.com> wrote:
    >

    vkhoury;2491067 Wrote:
    >
    >> I've tried to solve this problem by adjusting the options of the role

    > created in role catalog and require an approval from a manager.
    >> But what is really weird is that once the user requests the role it is

    > provisioned immediately without approval.
    >> Is it normal to have such response? I think i must be missing something

    > in the process.
    >> What is the right way of doing this?

    >


    You can use the default rope approval PRD as a template and customise it to
    your hearts content.

    > I realized that once a user request a role the request remains in

    pending state for about 24 hours before appearing in the task section of
    the user responsible of provisioning the role.
    > However, I don't know why it's taking that much time and if tif this can

    be configured or not.

    It shouldnâ€Tmt take so long. Sounds like it is waiting a timeout of some
    sort.

    Also keep in mind that users assigned to a role via an indirect mechanism
    (group to role, container to role, role to role) skip any defined approval
    workflow. This is by design.

Reply
  • vkhoury <vkhoury@no-mx.forums.microfocus.com> wrote:
    >

    vkhoury;2491067 Wrote:
    >
    >> I've tried to solve this problem by adjusting the options of the role

    > created in role catalog and require an approval from a manager.
    >> But what is really weird is that once the user requests the role it is

    > provisioned immediately without approval.
    >> Is it normal to have such response? I think i must be missing something

    > in the process.
    >> What is the right way of doing this?

    >


    You can use the default rope approval PRD as a template and customise it to
    your hearts content.

    > I realized that once a user request a role the request remains in

    pending state for about 24 hours before appearing in the task section of
    the user responsible of provisioning the role.
    > However, I don't know why it's taking that much time and if tif this can

    be configured or not.

    It shouldnâ€Tmt take so long. Sounds like it is waiting a timeout of some
    sort.

    Also keep in mind that users assigned to a role via an indirect mechanism
    (group to role, container to role, role to role) skip any defined approval
    workflow. This is by design.

Children
No Data