This page is not public
Viewing of this page has been restricted to internal users only until there is sufficient content.
This topic provides instructions on how to provision users to a trusted identity provider from the WSO2 Identity Server, based on the user roles. In outbound provisioning, when the users are created, they are provisioned to the trusted identity provider. In role based provisioning, the user is provisioned when the user is added to a preconfigured role, and the user is deleted from the trusted identity provider, when the user is removed from the role.
Configuring an identity provider
- Download the WSO2 Identity Server and run it.
- Log in to the Management Console as an administrator.
- Navigate to the Main menu and access the Identity menu. Click Add under Identity Providers.See here for more information on this.
- Enter "role based provisioning" as the Identity Provider name for this scenario.
- Configure the Outbound Provisioning Connectors with SPML, SCIM or Salesforce connecter.
- Expand Role Configuration and add a role name (or set of roles as a comma separated list) in Identity Provider OutBound Provisioning Roles (here we have added role named provision). If you don't have roles already follow the instructions in here to add roles.
- Click Update to save changes.
Configuring outbound provisioning
- In the Main menu under the Identity section, click List under Service Providers. The list of service providers you added appears.
- Click the Resident Service Provider link.
Then expand the Outbound Provisioning Configuration section and add the created identity provider and select the connecter from the dropdown list.
If we enable Blocking, Identity Server will wait for the response from the Identity Provider to continue.
- Click Update.
Provisioning Users
- On the Main tab in the management console, click Add under Users and Roles in the Identity menu.
- Click Add New User. See Configuring Users for more information on this process.
- Provide a username and a password(with confirmation) and Click Next.
- Click Finish to create the user.
- User will not be provisioned to the identity provider.
- On the Main tab in the management console, click List under Users and Roles in the Identity menu.
- Click Users and then Assign Roles action of the newly created user. Enable "provision" role (any role added in Role Configuration of the identity provider) and click Finish.
- User will be provisioned to the identity provider.
- On the Main tab in the management console, click List under Users and Roles in the Identity menu.
- Click Users and then Assign Roles action of the newly created user. Disable "provision" role (any role added in Role Configuration section of the identity provider) and click Finish.
- User will be removed from the identity provider.