Managing Users Provisioning Data From Oracle Identity Manager to LDAP Identity Store

4-26 Oracle Fusion Middleware Users Guide for Oracle Identity Manager ■ Add role to a member ■ Add and Update role ■ Remove role from a member ■ Add role hierarchy ■ Remove role hierarchy

4.3.3 Reconciliation From LDAP Identity Store to Oracle Identity Manager

When changes in the identities are made directly in the LDAP identity store, the changes must be replicated to Oracle Identity Manager through authoritative source reconciliation. The identities include users and roles. Reconciling users from LDAP to Oracle Identity Manager works with the general configuration of reconciliation, which includes the scheduled tasks for reconciliation. The role reconciliation works only with the LDAP groups. Role reconciliation supports creation, updation, and deletion of roles. Role membership reconciliation supports creation and deletion of role memberships being driven from changes in an external LDAP directory. Without roles and users being present in Oracle Identity Manager, role membership reconciliation will fail. Therefore, configure the LDAP synchronization scheduled jobs to run in the following order: 1. Fusion Applications Role Category Seeding See Also: ■ Reconciliation Configuration on page 4-2 for detailed information about reconciliation ■ Managing Scheduled Tasks for information about scheduler and scheduled tasks in the Oracle Fusion Middleware Administrators Guide for Oracle Identity Manager. Note: Instead of using LDAP synchronization reconciliation jobs to reconcile users from LDAP to Oracle Identity Manager, if the Bulk Load utility is used, then subsequent operation on these users might fail if LDAP synchronization is enabled. To avoid this, all the users that are loaded in Oracle Identity Manager must be updated with correct GUID and DN values, and all these users in LDAP must be updated with an object class called orclIDXPerson. For detailed information about the Bulk Load utility, see Bulk Load Utility in the Oracle Fusion Middleware Developers Guide for Oracle Identity Manager. See Also: Chapter 12, Managing Roles