12.07.2015 Views

CA Identity Manager Implementation Guide - CA Technologies

CA Identity Manager Implementation Guide - CA Technologies

CA Identity Manager Implementation Guide - CA Technologies

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Guide</strong>lines for Group Member\Administrator Optimizations■Enable scoped searches in role relationship tabsYou can configure each role tab to include searches that allow administratorsto specify criteria for new roles to assign to a user. Role searches limit thenumber of member and admin policy rules that <strong>Identity</strong> <strong>Manager</strong> mustevaluate to determine which roles an administrator can assign to a user.■Set task synchronization optionsFor each <strong>Identity</strong> <strong>Manager</strong> task, you can specify a user synchronizationoption, which synchronizes users with identity policies, and a provisioningaccount synchronization option, which synchronizes users with provisionedaccounts. The options enable you to synchronize users when a taskcompletes, or when an event completes.To eliminate evaluation and processing time, set the synchronization tooccur when a task completes, instead of when events complete.<strong>Guide</strong>lines for Group Member\Administrator OptimizationsTo improve performance of searches for group members and administrators,consider the following:■Define well-known attributes in the directory configuration file(directory.xml), which describes the user store structure and contents to<strong>Identity</strong> <strong>Manager</strong>.A well-known attribute is an attribute that has a special meaning in <strong>Identity</strong><strong>Manager</strong>.To improve group member\administrator searches, define the followingwell-known attributes for the user object:%MEMBER_OF%Identifies an attribute on the user object that stores a list of groupswhere the user is a member.When defined, this attribute can prevent <strong>Identity</strong> <strong>Manager</strong> fromsearching all of the members in all of the groups in the user store. Groupsearches can significantly affect performance in very large groups.%ADMINISTRATOR_OF%Identifies an attribute on the user object that stores a list of groupswhere the user is an administrator.Like the %MEMBER_OF% attribute, this well-known attribute caneliminate lengthy group searches.■Specify the Group Type in the directory configuration file<strong>Identity</strong> <strong>Manager</strong> supports three types of groups: standard groups, nestedgroups, and dynamic groups.Chapter 6: Optimizing <strong>Identity</strong> <strong>Manager</strong> 83

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!