Identity feed management

As administrator, you need to take a number of initial steps to take employee data from one or more human resources repositories. You use the data to populate ISIM registry with an equivalent set of users. An identity is the subset of profile data that uniquely represents a person in one or more repositories, and additional information related to the person. For example, an identity might be represented by unique combination of the first, last, full name, and employee number of a person. The data might also contain additional information such as phone numbers, manager, and email address. A data source can be a customer's user repository or a file, a directory, or a custom source. Use IBM Security Identity Manager to add a number of users to the system by reading a data source, such as a user repository, directory, file, or custom source. The process of adding users based on a user data repository is called an identity feed, or HR feed.

Reconciliation for an identity feed is the process of synchronizing the data between the data source and IBM Security Identity Manager. The initial reconciliation populates IBM Security Identity Manager with new users, including their profile data. A subsequent reconciliation both creates new users and also updates the user profile of any existing users that are found. registry. We need to anticipate the effect of missing information in the user record. For example, the record that we feed into ISIM might not have an email address for the user.

The user does not receive a password for a new account in an email and must call the help desk, or contact the manager.


Common sources for identity feeds

ISIM supplies the following service types to handle many of the most common sources for identity feeds:

We can populate initial content and subsequent changes to the content of the people registry from these sources"

For more information about providing customized identity feeds, see the information about IBM Security Directory Integrator integration in ISIM extensions directory.


Enabling workflow for identity feeds

Regardless of the method used, ISIM Server can be configured to call the workflow engine for identity feed records. Enabling the workflow engine results in enforcement of all applicable provisioning policies for incoming identities. The configuration results in slower feed performance. Persons are automatically enrolled in any applicable dynamic roles even if the workflow engine is not enabled for an identity feed. For initial loads, consider importing identities into the system and then enabling applicable provisioning policies to improve identity feed performance.

See:

Parent topic: Configure