Managing user accounts

The Accounts tab displays all application accounts associated with a user across connected systems.

About this task

Each account represents a provisioned identity in a target application, managed through IBM® Verify. You can use this tab to review the current state of a user's accounts, identify any compliance discrepancies, and take action where remediation is required. Accounts are created when IBM Verify provisions a user to a connected application based on the application configuration.

Procedure

  1. Select Directory > Users & groups.
    Ensure that the Users tab is the active tab.
  2. If the user is not displayed on the page, use the search function to find the user.
  3. Select the User details icon.
  4. On the user's page, select the Accounts tab.
    The Accounts tab displays all accounts associated with the user in a tabular format. The following describes the details on this tab:
    Application
    The name of the connected application that the account belongs to.
    Account username
    The username assigned to the user in the target application.
    Account status
    The current provisioning state of the account in the target application.
    Status Description
    Active The account is fully operational and the user can access the application with full privileges.
    Disabled The account gets disabled on deprovisioning operation failure.
    Not provisioned When the provisioning request has failed.
    Suspended The accounts that are disabled on target application.
    Provisioning When the provisioning operation is in progress. After the operation completes, the account is Active and compliant.
    Deprovisioning When the deprovision operation is in progress. After the operation completes, the account is either Suspended or removed.
    Suspending When the account suspension is in progress.
    Restoring When the account restore operation is in progress.
    Compliance status
    Indicates whether the account's attributes and permissions in the target application match the expected values defined in the application's attribute mapping configuration.
    Status Description
    Compliant The account attributes and permissions match between the identity source and target system with no discrepancies. The discrepancy is checked on the basis of the attribute mapping defined in the application configuration.
    Non-compliant The account has attribute, permission or status differences between the identity source and target system that require remediation.
    Note:
    • For all accounts, you can Suspend or Restore them as needed.
    • For non-compliant accounts, click Remediation options from the Summary panel to select the appropriate option to remediate the account.
    Date created
    The date on which the account was provisioned to the target application.