Previous Topic: How Users and Identity Policies Are SynchronizedNext Topic: Limit the Tasks that Trigger User Synchronization


Design Efficient Identity Policies

Use the following guidelines when you create identity policies:

Identity Policy Condition

Action on Apply Policy

Action on Remove Policy

where (Job Code = "100")

Make member of (provisioning role "Account Manager")

Remove member of (provisioning role "Account Manager")

Who are members of (provisioning role "Account Manager")

Make member of (group "Account Managers")

Remove member of (group "Account Managers")

When CA IdentityMinder evaluates this type of policy, it must evaluate and apply changes at least twice to ensure that both conditions are met. The recursion level, which is set for an entire CA IdentityMinder environment, must be greater than 1, which then causes additional evaluations for each identity policy set.