Click Advanced. Click the System Management tab Click the arrow for the Search Scheduled Jobs to list all the schedulers. Select LDAP User Create and Update Full Reconciliation. Click Run Now to run the job. Updating the Username Generation Policy for Act

14-22 Oracle Fusion Middleware Enterprise Deployment Guide for Oracle Identity Management 11. Change the username to weblogic_idm and set the password to the accounts password.

12. Click OK.

13. Run the reconciliation process to enable the Oracle WebLogic Server administrator, weblogic_idm, to be visible in the OIM Console. Follow these steps: a. Log in to Oracle Identity Manager at: https:sso.mycompany.com:443oim as the user xelsysadm. b. If prompted, set up challenge questions. This happens on your first login to Oracle Identity Manager.

c. Click Advanced.

d. Click the System Management tab

e. Click the arrow for the Search Scheduled Jobs to list all the schedulers.

f. Select LDAP User Create and Update Full Reconciliation.

g. Click Run Now to run the job.

h. Go to the Administration page and perform a search to verify that the user is visible in the Oracle Identity Manager console.

14. Select Administration.

15. Click Advanced Search–Roles

16. Search for the Administrators role.

17. Click the Administrators Role.

18. Click Open.

19. Click the Member tab.

20. Click Assign.

21. Type weblogic_idm in the Search box and Click -.

22. Select weblogic_idm from the list of available users.

23. Click to move to Selected Users.

24. Click Save.

25. Restart Oracle Identity Manager managed server.

14.14 Updating the Username Generation Policy for Active Directory

If your back end directory is Active Directory, you must update Oracle Identity Manager so that it only allows user names with a maximum of 20 characters. This is a limitation of Active Directory. Update the username generation policy from DefaultComboPolicy to FirstnameLastnamepolicyforAD as follows. 1. Log in to the OIM Console at: https:sso.mycompany.com:443oim

2. Click Advanced on the top of the right pane.

3. Click Search System properties.

4. On the navigation bar in the left pane, search on Username Generation.

Extending the Domain with Oracle Identity Manager 14-23

5. Click Default Policy for Username Generation.

6. In the Value field, update the entry from

oracle.iam.identity.usermgmt.impl.plugins.DefaultComboPolicy to oracle.iam.identity.usermgmt.impl.plugins.FirstNameLastNamePo licyForAD.

7. Click Save.

14.15 Update Oracle Identity Manager JMS Queues

Update Oracle Identity Manager JMS queues as follows: 1. Log in to the WebLogic console as the administrative user.

2. Select Services - Messaging - JMS Modules from the Domain Structure menu.

3. Click OIMJMSModule.

4. Click Lock Edit.

5. For each of the queues, click the queue then click the Delivery Failure tab and

change Redelivery Limit value from -1 to 1, then click Save. 6. Make sure you have performed Steps 4 and 5 for all the queues under OIMJMSModule .

7. Click Activate Changes.

8. Restart Oracle Identity Manager servers as described in Section 20.1, Starting and Stopping Oracle Identity Management Components.

14.16 Tuning Oracle Platform Security