Replacing a noncompliant attribute with a compliant attribute

An administrator can create a global enforcement policy to resolve disallowed noncompliant accounts on the services. The global enforcement policy can deprovision accounts that are not granted by any applicable provisioning policy entitlement. Disallowed accounts can be exempt from being removed at the remote service if they meet the criteria of exemption accounts. Criteria are defined in the exemption handler.

For more information about how to define exemption accounts in the exemption handler, see Policy enforcement actions in the Policy enforcement topic.. The administrator can override the exemption handler that you defined or created.

To replace a noncompliant attribute on an account with a compliant attribute...

  1. From the navigation tree, select Configure System > Configure Global Policy Enforcement.

  2. On the Configure Global Policy Enforcement page, select Correct and then Submit in the Enforcement Action section. Changing the global policy enforcement action for the system can cause a re-evaluation of account compliance and a modification of account data. Furthermore, selecting Correct might cause account deprovisioning unless the account is exempt, which is account deletion, if an account is not granted by any provisioning policy entitlement.

  3. On the Confirmation page, select a time and date to schedule this operation. After selecting this option, we can select the calendar and clock icons to customize scheduled date and time.

    • Select Immediate and then Submit if to run the request immediately. The current date and time are displayed.

    • Select Effective date and then Submit if to run the request at a date and time that we customized.

  4. On the Success page, click Close.

Parent topic: Configure a global enforcement policy