4.4 Migrating Identities

When you first run the driver, you might have identities in the Identity Vault that you want to provision to the connected system, or vice versa. Identity Manager provides a built-in migration feature to help you accomplish this.

4.4.1 Migrating Identities from the Identity Vault to the Connected System

  1. In Identity Console, click the Identity Manager Drivers module from the landing page.

  2. Click the specific driver to perform your migration.

  3. Click the Data Transformation and Synchronization tab.

  4. Click Migrate From IDVault tab.

  5. Click the Add icon. A browse and search dialog box that allows you to select objects is displayed.

  6. Select the objects you want to migrate, then click OK.

To view the results of the migration, click View the Driver Status Log. For details about the log, see The Status Log.

If a user has a Distribution Password, the Distribution Password is migrated to the connected system as the user’s password. Otherwise, no password is migrated. For information about Universal Passwords and Distribution Passwords, see the appropriate version of the Password Management Administration Guide at the NetIQ Documentation Web site.

4.4.2 Migrating Identities from the Connected System to the Identity Vault

  1. In Identity Console, click the Identity Manager Drivers module from the landing page.

  2. Click the specific driver to perform your migration.

  3. Click Migrate Into IDVault tab.

  4. Use the Edit Migration Criteria icon.

  5. Specify your search criteria:

    1. Select class User or class Group.

      IMPORTANT:Identity Manager imports objects by class in the order specified in the list. Migrate users before you migrate groups so that the users can be added to the newly created groups.

    2. Select the attributes to be used as search criteria for objects of the selected class, then click OK.

      The eDirectory attributes map to RACF attributes as specified by the driver schema: CN maps to DirXML-RACF-userid, etc. For the default mappings, see Table 1-2, Default Filter and Schema Mapping.

    3. Specify values for the selected attributes, then click OK.

  6. Click the Migrate Into IDVault icon.

To view the results of the migration, click View the Driver Status Log. For details about the log, see The Status Log.

Because local passwords cannot be retrieved from RACF, they cannot be submitted to the Metadirectory engine until they are changed. The password change exit routine captures password changes.

4.4.3 Synchronizing the Driver

To generate events for associated objects that have changed since the driver’s last processing, in Identity Console:

  1. In Identity Console, click the Identity Manager Drivers module from the landing page.

  2. Click the specific driver to perform your synchronization.

  3. Click the Data Transformation and Synchronization tab.

  4. Click the Synchronize tab.

  5. Select to Examine all objects or Use a starting date/time, and click the Synchronize icon.