What's New in Oracle Identity Manager Connector for Microsoft Active Directory User Management?

This chapter provides an overview of the updates made to the software and documentation for release 11.1.1.6.0 of the Microsoft Active Directory User Management connector.

The updates discussed in this chapter are divided into the following categories:

  • Software Updates

    This section describes updates made to the connector software. This section also points out the sections of this guide that have been changed in response to each software update.

  • Documentation-Specific Updates

    This section describes major changes made to this guide. For example, the relocation of a section from the second chapter to the third chapter is a documentation-specific update. These changes are not related to software updates.

Software Updates

The following section discusses software updates:

Software Updates in Release 11.1.1.6.0

The following are the software updates in release 11.1.1.6.0:

Support for Adding Dynamic Auxiliary Object Classes

The connector provides support for adding dynamic auxiliary object classes. In addition, you can add the attributes of these dynamic auxiliary object classes for reconciliation and provisioning.

See Adding Dynamic Auxiliary Object Classes and Their Attributes to Users for more information.

Support for Adding the Group Name (pre-Windows 2000) Attribute

During group provisioning, by default, the value that you specify for the Group Name field on the OIM process form, is entered as the value of the Group Name and Group Name (pre-Windows 2000) attributes of the target system. If you want to specify different values for the Group Name and Group Name (pre-Windows 2000) attributes in the target system, then you must create the Group Name (pre-Windows 2000) field on the OIM process form.

See Adding the Group Name (pre-Windows 2000) Attribute for more information.

Support for Provisioning Groups of the Security Group - Universal Group Type

The connector provides support for provisioning groups of the type Security Group - Universal. See Configuring the Connector for Provisioning Groups of the Security Group - Universal Group Type for more information.

Support for Provisioning and Reconciling Custom Object Categories

If you are using AD LDS as the target system, then add custom object categories for provisioning and reconciliation. See Configuring the Connector for Provisioning and Reconciling Custom Object Categories for more information.

Software Updates in Release 11.1.1.5.0

The following are the software updates in release 11.1.1.5.0:

Support for New Target Systems

From this release onward, the connector adds support for the following as target systems:

  • Microsoft Active Directory installed on Microsoft Windows Server 2012

  • Microsoft Active Directory Lightweight Directory Services installed on Microsoft Windows Server 2012

These target systems are mentioned in Certified Components for Microsoft Active Directory User Management Connector.

Support for Connector Server

The Microsoft Active Directory User Management connector is written using Microsoft .NET. A .NET environment is required for the execution of this connector code. Therefore, it is mandatory for this connector to be deployed on the .NET Connector Server shipped along with the connector package. The Microsoft Active Directory User Management connector operates in the context of a .NET Connector Framework, which in turn requires an application to execute. Therefore, by default, Oracle provides the .NET Connector Server to run the Microsoft Active Directory User Management connector.

Connector Server is a component provided by ICF. By using one or more connector servers, the connector architecture permits your application to communicate with externally-deployed bundles. In other words, a connector server enables remote execution of an Oracle Identity Manager connector.

See the following sections for more information:

Deployment Using Connector Server

This release of the connector can be deployed using the Connector Server, which is included with the ICF. See Installing Microsoft Active Directory User Management Connector in Oracle Identity Manager for more information.

Connection Pooling

A connection pool is a cache of objects that represent physical connections to the target. Oracle Identity Manager connectors can use these connections to communicate with target systems. At run time, the application requests a connection from the pool. If a connection is available, then the connector uses it and then returns it to the pool. A connection returned to the pool can again be requested for and used by the connector for another operation. By enabling the reuse of connections, the connection pool helps reduce connection creation overheads like network latency, memory allocation, and authentication.

One connection pool is created for each IT resource. For example, if you have three IT resources for three installations of the target system, then three connection pools will be created, one for each target system installation.

See Setting Up the Lookup Definition for Connection Pooling for more information.

Support for Connector Operations Across Domains

The connector supports reconciliation and provisioning operations across domains. This means that, for example, you can assign a user in one domain to a group in another domain. You can also reconcile a user record even if the user and the user's manager belong to different domains.

See Enabling Reconciliation and Provisioning Operations Across Multiple Domains for more information.

Support for Connector Operations on User-Defined Object Classes

The connector can be configured to reconcile from and provision to user-defined object classes and their attributes. By default, the target system uses the user object class. The connector can be configured to accommodate user-defined object classes that you define on the target system.

See Configuring the Connector for User-Defined Object Classes for more information.

Support for Addition of New Terminal Profile Fields

Depending upon your requirement, you can add new terminal profile fields for reconciliation and provisioning. See Adding Terminal Services Fields for Reconciliation and Provisioning for more information.

Support for Scripting Languages

The connector supports any scripting language that has a script executor in the ICF. Currently, there are two script executor implementations: a Windows shell script executor (batch scripts) and a Boo script executor. Although Visual Basic scripts are not directly supported, a Visual Basic script can be called using a shell script.

See Action Scripts for more information.

Support for High-Availability Configuration of the Target System

The connector can be configured for compatibility with high-availability target system environments. It can read information about backup target system hosts from the BDCHostNames parameter of the Active Directory IT resource and apply this information when it is unable to connect to the primary host.

See Table 2–1 of Configuring the IT Resource for Microsoft AD and AD LDS for more information.

Documentation-Specific Updates

The following section discusses documentation-specific updates:

Documentation-Specific Updates in Release 11.1.1.6.0

The following documentation-specific update has been made in revision "28" of release 11.1.1.6.0:

An additional step has been added to Adding a New Field on the Process Form to run the Form Upgrade Job.

The following documentation-specific update has been made in revision "27" of release 11.1.1.6.0:

A Note about configuring the .NET Connector Server has been added to Installing Microsoft Active Directory User Management Connector in Oracle Identity Manager.

The following documentation-specific update has been made in revision "26" of release 11.1.1.6.0:

Information about configuring the system to install and runn the Connector Server has been modified in Frequently Asked Questions.

The following documentation-specific update has been made in revision "25" of release 11.1.1.6.0:

Descriptions for “Incremental Recon Attribute” and "Latest Token" parameters of table Table 3-3 and Table 3-4 have been updated.

The following documentation-specific update has been made in revision "24" of release 11.1.1.6.0:

The “Oracle Identity Governance or Oracle Identity Manager” row of the table in Certified Components for Microsoft Active Directory User Management Connector has been updated to include support for Oracle Identity Governance release 12c PS4 (12.2.1.4.0).

The following documentation-specific updates have been made in revision "23" of release 11.1.1.6.0:
The following documentation-specific updates have been made in revision "22" of release 11.1.1.6.0:

The following documentation-specific updates have been made in revision "21" of release 11.1.1.6.0:

The "Oracle Identity Manager" row of the table in Certified Components for Microsoft Active Directory User Management Connector has been renamed as "Oracle Identity Governance or Oracle Identity Manager" and also updated for Oracle Identity Governance 12c (12.2.1.3.0) certification.

The following documentation-specific updates have been made in revision "20" of release 11.1.1.6.0:

The following documentation-specific update has been made in revision "19" of release 11.1.1.6.0:

All contents of Section 2.1.1.1, "Files and Directories On the Installation Media" have been moved to Appendix B, "Files and Directories on the Installation Media".

The following documentation-specific update has been made in revision "18" of release 11.1.1.6.0:

The "Connector Server" row of the table in Certified Components for Microsoft Active Directory User Management Connector has been updated.

The following documentation-specific update has been made in revision "17" of release 11.1.1.6.0:

A "Note" regarding the user account to be used while running the .NET Connector Server has been added to Installing and Configuring the Connector Server.

The following documentation-specific update has been made in revision "16" of release 11.1.1.6.0:

The "Microsoft .NET framework" row has been added to the table in Certified Components for Microsoft Active Directory User Management Connector.

The following documentation-specific updates have been made in revision "15" of release 11.1.1.6.0:

  • The following guideline has been removed from Guidelines on Configuring Reconciliation as the connector no longer uses the said format to delete users in Oracle Identity Manager:

  • Chapter 7, “Known Issues and Workarounds” has been removed.

The following documentation-specific updates have been made in revision "14" of release 11.1.1.6.0:

The following documentation-specific updates have been made in revision "13" of release 11.1.1.6.0:

The following documentation-specific update has been made in revision "12" of release 11.1.1.6.0:

A "Note" has been added at the beginning of Extending the Functionality of the Microsoft Active Directory User Management Connector.

The following documentation-specific update has been made in revision "11" of release 11.1.1.6.0:

Troubleshooting the Microsoft Active Directory User Management Connector has been updated.

The following documentation-specific updates have been made in revision "10" of release 11.1.1.6.0:

The following documentation-specific updates have been made in the revision "9" of release 11.1.1.6.0:

The following documentation-specific updates have been made in the revision "8" of release 11.1.1.6.0:

The following documentation-specific updates have been made in earlier revisions of release 11.1.1.6.0:

Documentation-Specific Updates in Release 11.1.1.5.0

The following are the documentation-specific updates in release 11.1.1.5.0: