Provisioning Policies

Provisioning Policies are used to define application object attributes that must be managed due to a Lifecycle Manager request. With a provisioning policy in place, when a role or entitlement is requested the user must input specified criteria into a generated form before the request can be completed. A policy can be attached to an IdentityIQ application object or role and is used as part of the provisioning process.

IdentityIQ includes the following types of provisioning policies:

  • Create

  • Update

  • Delete

  • Enable Account

  • Disable Account

  • Unlock Account

  • Change Password

  • CreateGroup - This is CreateRole for MEDITECH

  • UpdateGroup - This is UpdateRole for MEDITECH

Click an existing provisioning policy or click Add Policy to create a new one using the Provisioning Policy Editor or to reference an existing policy. Only one of each policy type is supported.

Use the Application Dependencies drop-down list to create the list of applications where this application is dependent for provisioning. If no account is detected on an application where this application is dependent, an account request is added to the provisioning plan and the provision policy for this application is processed as expected.

The Provisioning Policy Editor panel contains the following information:

Use the Edit Provisioning Policy Fields panel to customize the look and function of the form fields generated from the provisioning policy: