17.3 Reflecting Permissions and Assignments from Applications Not Connected to Identity Manager

Identity Governance can collect account and permission data from application sources that do not have role and resource objects in Identity Manager. The Access Review driver serves as the proxy for the application sources. For more information, see Reflecting Application Permissions in Identity Manager.

NOTE:The driver needs both a system account and a workflow in the User Application to create resources. For more information, see the NetIQ Identity Manager Driver for Access Review Installation and Configuration Guide.

  1. Log in to Identity Governance as a Global Administrator.

  2. Add the Identity Manager information to Identity Governance.

    1. Select Administration, then expand the Identity Manager system connection information section.

    2. Provide the Identity Manager URL. For example: http://myserver:8180/IDMProv.

    3. Add the administrator user name and password for your Identity Manager system. For example, admin or cn=uadmin,ou=sa,o=data.

    4. Select Test Connection. Ensure that you have a valid connection before proceeding.

  3. Under Catalog, select Applications.

  4. Select an application that you want to integrate with Identity Manager.

  5. Select the icon for Edit application.

  6. Under Identity Manager Synchronization, select Reflect permissions and assignments as resources in Identity Manager.

  7. Specify the provisioning workflow that you want Identity Manager to use.

  8. For Identity Manager Resource Owner, specify the user account in Identity Manager that can grant permissions for the application. For example, the application owner.

    In Identity Governance, the name for this user is the concatenation of the account GivenName and Surname attributes. For more information about this account, see the NetIQ Identity Manager Driver for Access Review Installation and Configuration Guide.

  9. For each application, repeat Step 4 through Step 8.