Initiates a request to the Roles Based Provisioning Module (RBPM) to revoke the specified role (in the Role DN field) from the specified user (in the Authorized User DN field). This field is only available if the Identity Manager server version is set to 3.6 or later. If a policy containing this action encounters an error, Designer generates the error as the local variable error.do-remove-role.
Specify the name of the role to revoke, in LDAP format. Supports variable expansion.
Specify the URL of the User Application server hosting the Roles Based Provisioning module. Supports variable expansion.
Specify the name of the user authorized to request the role assignment, in LDAP format. Supports variable expansion.
Specify the number of milliseconds you want Identity Manager to try to establish a connection to the User Application server before timing out. The default value is 0.
Specify the authorized user password. You can enter a clear text password (not recommended) or use the Argument Builder to specify a Named Password.
Select the target object type. This object can be the current object, or can be specified by a DN or an association.
Select the DN or association as the target object.
(Optional) Specify additional argument strings for the Role assignment request. You can enter the strings manually, or select the Edit the Strings icon to open the Named String Builder and specify the strings.
The Remove Role action supports the following string arguments
String Name |
Description |
---|---|
description |
A description of the reason for the request used for auditing and (if necessary) approval purposes. Default: Request generated by policy. |
effective-time |
The time (in CTIME format) the role assignment should become effective. Default: now |