Quantcast
Channel: Forum Microsoft Identity Manager
Viewing all articles
Browse latest Browse all 1783

Adding member to a group (excluding the owner by not going into approval process)

$
0
0
Hi everyone;

We have the following policy:
Requestors: All People
Operation: Add a value to a multivalued attribute
Permissions: Granted
Target Resource Definition before Request: All groups
Target Resource Definition after Request: All groups
Resource Attributes: Manually-managed Membership
Authorization Workflow: Requestors manager --> group owner approval

What i want to do is when the owner of the group request to add member to his group, no workflow is triggered.

What i did is creating another MPR with the following details:
Requestors (Relative to resource): Owner
Operation: Add a value to a multivalued attribute
Permissions: Granted
Target Resource Definition before Request: All groups
Target Resource Definition after Request: All groups
Resource Attributes: Manually-managed Membership
No workflow is attached

After creating the MPR when the owner request to add a member, it still trigger the workflow.

I understand that this is normal and the owner is a member of the All people Set, but is there a way to exclude him from the approval??

Thanks in advance
Eihab Isaac

Viewing all articles
Browse latest Browse all 1783

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>