Provisioning tutorial
Provisioning tutorial
Build a complete provisioning workflow: load HR data, connect Active Directory, identify accounts to create, generate credentials, and schedule the process.
Before you beginDirect link to Before you begin
This tutorial creates and updates Active Directory accounts. Complete it in a test environment or use a dedicated organizational unit and test records.
Build the workflowDirect link to Build the workflow
Complete the ten stages in order. Each stage builds on the configuration created in the previous one.
1. Add the CSV source systemDirect link to 1. Add the CSV source system
Add the HR500 CSV files as a NIM source system, collect the data, and set stable primary keys for its tables.
2. Add the Active Directory targetDirect link to 2. Add the Active Directory target
Configure an Active Directory system that NIM can use to create and update accounts.
3. Create the system relationDirect link to 3. Create the system relation
Relate the HR500 source records to Active Directory accounts so NIM can identify which records already match.
4. Find employees without accountsDirect link to 4. Find employees without accounts
Create a filter that selects source employees who do not yet have a matching Active Directory account.
5. Generate account namesDirect link to 5. Generate account names
Create a name generator for values such as sAMAccountName, userPrincipalName, and common name.
6. Generate initial passwordsDirect link to 6. Generate initial passwords
Create a password generator that produces an initial password for each new AD account.
7. Create the account mappingDirect link to 7. Create the account mapping
Map the selected HR500 attributes, generated names, and password into an Active Directory user-create operation.
8. Combine the work in a jobDirect link to 8. Combine the work in a job
Add the mapping to a NIM job so the provisioning action can run as one managed unit.
9. Schedule the provisioning jobDirect link to 9. Schedule the provisioning job
Create a scheduler task to run the job automatically and review the result.
10. Update existing accountsDirect link to 10. Update existing accounts
Add a second mapping to keep existing Active Directory accounts synchronized with HR500 data.