MSAMM
Back to course

Administering Cloud EPM: The Platform Beneath the Business Processes · Module 7 · Provisioning at Scale

What synchronization does and does not carry

Lesson 79 of 201 · 1 min

SCIM, at the level a platform administrator needs: a standard for synchronizing identity between systems. What gets synchronized: users and groups. What does not: application role assignments. Those remain yours, assigned to the synchronized groups. THIS IS THE CRITICAL DIVISION OF LABOUR AND IT IS FREQUENTLY MISUNDERSTOOD. The corporate directory owns WHO EXISTS and WHICH GROUPS THEY ARE IN. You own WHAT THOSE GROUPS CAN DO. A clean boundary — and it is the reason Module 6's group design matters so much. A badly designed group model does not just cost you effort now; it becomes a thing another team is maintaining on your behalf. Two synchronization directions are covered here: between identity domains, within or across cloud accounts — and from an external directory into the domain. And one scoping decision: all users and groups, or a filtered subset. That is Lesson 4, and the answer is usually filtered.

The full lesson is part of the course

The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.

Get the free lessons by email

We will email you a link to every free lesson in this course. No account needed, and one message only.

In this module: Module 7 · Provisioning at Scale

  1. 1Why manual provisioning fails
  2. 2What synchronization does and does not carry
  3. 3Synchronizing across identity domains
  4. 4Synchronizing specific users and groups
  5. 5Synchronizing from an external directory
  6. 6Groups for application-level role assignment
  7. 7Password policies
  8. 8Email notifications and password resets
  9. 9What breaks
  10. 10Lab: design the synchronization and test the leaver