We would like to see which Active Directory accounts are not managed by HelloID Provisioning and if these accounts are enabled/disabled. This helps to clean up the current Active Directory state.
  • Import accounts + accounts access (enable/disable) state from Active Directory
  • Match the state from Active Directory (network state) against HelloID Provisioning entitlement state (based on account entitlement reference)
  • Report is renewed each month
Based on a mismatch (unmanaged by HelloID provisioning) the following data is shown per mismatch:
  • Show Active Directory user
  • Show System (We only support Active Directory but you could have multiple Active Directories)
  • Show the person if available we do a check based on correlation value (When a person is shown this could mean that the scope of the Business Rules assigning the account entitlement is not correct)
  • Show business rules assigning the account (access) entitlement from the Active Directory system
  • Show Description of the scenario as described down below
Scenario's:
  • Unmanaged account: The account exists in Active Directory but no corresponding state can be found in HelloID
  • Missing account: An account entitlement exists but no corresponding accounts exist in Active Directory
  • Mistakenly enabled account: An account in Active Directory exists with a corresponding account entitlement in HelloID but the account is enabled but no corresponding account access entitlement exists
  • Mistakenly disabled account: An account in Active Directory exists with a corresponding account entitlement in HelloID but the account is disabled although it has a corresponding account access entitlement
This feature needs the Governance module license.