This content has been marked as final. Show 3 replies
have you restarted after marking Allow Multiple Instance to false in the AD Resource Object. restart it and check if works else go with below workaround
Write a custom Unconditional Adapter adapter. check if Ad account already provisioned to this user and return string like "Provisioned" and "Not Provisioned". you can get help of OIM API to check if a AD account exist for user or not. No attach Create User task at the "Provisioned" response of your custom task. and send mail on the "Not Provisioned" response .
Mark Create user task as conditional.
Thanks for your inputs. Restarting the servers doesn't solve the issue and user can still have multiple account on reconciliation. But i can't direct provision an AD account to an user that already have one so i guess reconciliation doesn't take into account this option.
The adapter can partially solve the problem.
For example if on reconciliation, 2 AD account match 1 oim user (for example an user that is still not in our scope), the first one detected will be linked to the account and the second one will send the notification.
We would like in that case that no links is created and a notification is send to an Admin. This can be done when one AD Account match 2 OIM Account but can we have the same behavior for 2 AD account matching 1 OIM user ?
Thanks for your help