In this webinar we'll have a first short slide session where I would like to introduce the first steps methodology uh and then the major part will be live demo so you will see midpoint in action how we can apply the first steps methodology to deploy midpoint so let's start as I said there are few slides including some screenshots so you can get back to them when you will watch This from recording the live demo will be on Mido 4.8 and when we finish the live demo there will be some conclusion plus questions and that poll
all right so let's start with the introduction of First Steps methodology if you would like to to hear the real Basics why we have it what is it it is guide to Quick midpoint deployment of simple midpoint configuration ations that being said it is not limited just to simple midpoint configurations it can be also used with More complex environment as well then the only limitation would be uh the effort and time because of course it would be it would be more complicated it would take some more time but the methodology is not limited second very
important point is that uh whatever we do we want to do it safely if you remember from some previous webinar who already mentioned the first steps methodology and before that how to Deploy midpoint and so on the safety was always the crucial part so whatever we do we want to have safe deployment and we will use very heavily simulations feature and account marks this help us to this helps us to prevent unexpected changes or even deletes in Target systems and also we'll increase confidence in the solution even with low quality data what you will see
here will be just user interface of midpoint there will be No XML which if you are working with midpoint for some years might be even strange but whatever you will see here will be everything done in user interface and the main goal for the methodology and also for approximately one hour which I will do the live demonstration would be start start using midpoint by connecting your first source and first Target system so this is what you will see we started to work on First Steps Methodology last year and we had weekly sessions engineers and developers
moving forward forward with expectations requirements for deployment also gather from you or customers and uh midpoint was adapted and uh new features were implemented so that we can do that this in April this year Mido 4.7 was released which supported simulations and account marks and in October midpoint 4.8 long-term support was released which further enhanced everything we need for This first steps methodology for these first iterations so it was like uh uh Joint Forces developers and Engineering so that we could make it happen and actually we have created not just a methodology but also training
which also is called first steps and there will be session next week our first uh training delivery for training based on this methodology the whole methodology is basically about iterating three simple steps connect cleanup and Automate and these iterations are what what is helping us to to move forward in small steps and safely so as I mentioned before it is a simplified midpoint deployment methodology but it can be also used for more complicated setup let's see the next slide about this connect clean up and automate what we are doing actually there so in the connect
step we need to connect new system or systems to the solution this Could be Source system or this could be Target system we need to connect it to be able to read to show to display to preview the data to know what we are talking about then in the cleanup step in the cleanup step we are trying to improve data quality which for Source systems might be we would like to ignore certain data because the quality of this data is low or there are certain mistakes for Target systems we need to correlate the Existing accounts
and during that correlation we will see that there are some uncorr accounts there are some orphaned accounts there are data errors which we will detect during the simulations like midpoint would change something when we would do it for real so this all will be done in the cleanup step and finally the automate step in automate step we are going to speed up the processes especially what was done manually we would like to do it Automatically we want to improve the efficiency of the solution and we will cover onboarding data updates and offboarding so joiners movers
and levers the first phase is basically read only the connect and in the automate we are basically writing the data to the system if it is Target system the context of these steps connect clean up and automate is that we have basically three major stages or Milestones where we are starting with The methodology and with the identity program so there will be kickoff stage or kick of phas or kick of Milestone where you need to uh agree on the scope of the solution what you would like to do what would be the first systems to
go with uh who will be in the team you need to have budget and so on so this is the initialization then in assessment we are trying to do everything what we will cover here in this live demo we are trying to connect First Source and Target system so that we can bring some value as soon as possible and that will be done of course by connecting and Clinic of data and then we are going for automation for this First Source and first Target system and then we can continue with other systems and do the
cleanup and more Automation and so on of course we are going to the ultimate goal which is the governance we want to have all governance features that we can have This blue cloud or whatever it is is what we will cover here in the web webinar and not by coincidence also we are covering this part in the First Step training this is the list of the first steps steps from the methodology which we will follow so step one this is basically what is also covered in in that kickoff planning your deployment so this is something
which we will not do by implementation because we already Know we want to connect First Source and Target system but we will start with step two connect Source system in our case it will be ARR system which is able to export data as CSV file and we would like to connect this system first and preview data after that in the step three we would like to import The Source data so we can access the data and we would like to import it to midpoint we want to create users in midpoint when we do it For
real you will see that we will do it in iterations in improving the configuration in step four we are going to connect Target system in our case it will be active directory or Lup and uh you can connect it either by writing your resource from scratch or you could use a resource template you will preview data so what is there so that you know what you can expect and then we follow on step five Target system Integration where we we will correlate existing accounts to midpoint to midpoint users who represent the actual HR data which
we have already imported and here of course we will also see if and how many orphan accounts are there and we will prepare ourselves to to resolve them in Step six we will import the usernames in the methodology we assume that you would like to use some source of data with which could be for Usernames which could be for example active directory or it could be main authentication system or single sign solution whatever we are using or assuming that it will be either elab or active directory and uh users usually know these usern very well
we would like to use them in midpoint of course it is optional step if you want to use uh for example employee numbers as usernames there is no problem with that but I will show you also This after import the usernames we are ready to start the provisioning to Target system so we will prepare the target system uh resource for provisioning we will do the simulations to see what will happen in Target system if we would provision like this if we have our outbound mappings like that so we will not do any harm without showing
what would happen before that and uh ultimately we are coming to step eight automated integration so we Are able to import data from Source system we will uh tune up the provisioning to Target system so we will not destroy anything and we can turn on the automation between source of system data source of data midpoint and uh active directory of course this also means that we need to start generating midpond usernames on our own because we will no more import them from active directory and what we want to achieve here will be onboarding offboarding and
Modification automation so from ARR to act active directory uh step nine will not be covered here because of time constraints but is covered in the methodology and of course in the first steps training override incorrect data this is uh the way or there are ways how we can override incorrect data from HR System if needed so for example if there is some incorrect data and HR team is uh not able or not willing or whatever uh To fix it and you need to do something with this data you can override it from Mido but we
will not touch this because of time why First Steps methodology is concentrating so much on simulations because whatever you do the configuration is seldom correct for the first time not even the you would make some mistake but it could be that you will unexpectedly delete or modify data in Target systems if the configuration Is incorrect or if the target system data is inconsistent there could be some some uh old data or some different data which midpoint would overwrite and maybe it's okay maybe it's not okay so you need to know what will happen before it
actually happens for that we have simulations and incremental liing of new features is much much safer with simulations because we have always the advantage of time we know what would happen before it happens and we can do Something about it so this is why we want to use the simulations and fortunately thanks to midpoint starting midpoint 4.7 we can use them during this uh deployment following the methodology on this slide I'm trying to summarize what do you need to configure in midpoint if you would like to use simulations in midpoint so once again midpoint allows
to simulate actions using the simulations to show what would Be done without actually doing that actions will be only reported recorded in simulation results but not actually executed and we have three places which we need to configure one is life cycle of midpoint configuration items for example example life cycle of the resource or the object type or the mapping or the synchronization configuration item like unmatched reaction so this is life cycle which you configure on specific places of Configuration then execution mode if you would like to simulate then the task which you will use must
be executed in execute execution mode preview this is turning on the simulation and finally when you are running simulations in the task you must select so-called configuration to use which is either development or production that's configured in the task and it means this if you would like to run the task Simulation with development configuration you or the task will simulate everything which is in active or proposed life cycle state if you will run the simulation with production configuration then the simulation task will evaluate and simulate everything which is in active and deprecate life cycle States
other life cycle state are ignored like draft archived or anything else that we have so this is the key and you will see How we are using these three uh pieces of configuration how we combine it to run the simulations during this uh live demo to show you some screenshots and not just uh details about how to do something but show you how it looks this is a screenshot when we are importing user from HR System we can see that there will be new user created in the midpoint with username 10001 and there will be
eight attribute or properties added to this user if I Would click on that result I would see the details but these are screenshots from what you will see so you will see it at least once more here you can see how midpoint is setting up the attributes all in the simulation so nothing happened yet but the simulation can be used and is very much useful also when simulating what Target system would do so this is when we are connecting Target system for provisioning midpoint will show us that For example two accounts would be disabled and
five others would be renamed plus there are some other objects which are going to be to be modified so 10 of which seven are here so three other objects and uh we can then act accordingly we can check if this is a problem of the configuration or problem of data inconsistency you will see this in this live demo we are also heavily utilizing account marks this is second very Important feature next to simulations because we can Mark some accounts using these marks so that they are not processed by midpoint or they are just processed with
some limitation if you remember that we have protected accounts for years then this is protected account on steroids because we can have much more than just protected accounts these are default marks which we be using here presented on this dashboard again you will see This dashboard during the webinar and this is the list of for example protected account so that information is visible to administrator or operator of midpoint or anyone WX is here uh and it can also serve as a some kind of report to see if the let's say uh number of account with
do not touch flag do not touch U Mark is increasing instead of decreasing so that can be also used that way Okay to introduce the demo and uh after two or three slides we are going for it we have a demo which is based on an existing organization which has a source and Target systems provision manually so there is no existing IDM or by scripts tickets things like that we have one source system which is the demo HR application you might probably know it from our Evol demo this application is able to export the data
to CSV file so we are exporting the following uh data We have about 16 users which we will export the attribute which will be the key is employee number in mnam there are some other attributes but we will not need to take care at this moment then we have a Target system this target system is either active directory or Lup we are using Lup but we are pretending that it is active directory for example the distinguish name looks like is the the common standard inactive directory that we have the given name And family name here
so this uh fixes company is creating the CN part of this language name as given name plus family name but of course this must be unique so in case it is not they would add something to to the distinguish like number two for example uid or some account name if this would be real active directory is created again manually using the jsmith convention but of course must be unique as well so again the administrators Would add their number or something else to make it unique as you will see not all accounts in this elab bactive
directory are matching this convention there are some accounts which are not so it will be interesting to see what if at all midon will do to these accounts and this is for example one of them we have Alex Freeman he has uid a Freeman but we have user Gina which is Gina green this is uh by coincidence CEO of the company so we Cannot afford to just rename that account just without any consequences so let's see what midpoint will be able to do now I will switch to live demo so I will need to uh
switch to the other window and I already have our demo application so we have some users in the demo application we can already export them to CSV file we have the PHP Lup admin which is serving as our primary tool to show what we have in Lup so These are the accounts there and of course we have midpoint so our midpoint is basically empty meaning there is only administrator and the only resource is there active directory prepared so that we can save some time but we will go through that configuration but everything else will be
done here by us okay so we will create the new resource which will be used for HR for that I will use the new resource Wizard and I will create the resource from scratch it is a CSV system so let's use CSV file connector let's call for example the resource HR I will keep the life cycle State proposed because in this methodology we would like to simulate everything before going going to production so I will keep it this is the default in midpoint 4.8 I will provide the path to CSV file and we need to
provide the unique field In the CSV file which is amp n and we are basically done we have created our first resource we can preview the data so you can see we have exported the data to CSV file and mid mode is able to reach them that's fine so now we need to create at least one object type because otherwise the resource is unusable for midpoint again we will use midpoint user interface so let's call it for example HR Person we know it is account there will be no intent I will just mark it as
default through we don't need to do anything at this point and we know what we will create from this a bit later will be users I will not set up any archetype yet you will see it in a couple of minutes so I'm telling midpoint that this resource can be then used for creating users again what we can do is we can preview Data and now we will realize that oh but there are some accounts starting with 8,000 in in employee number which if I switch to the demo application are these last four and these
are actually some people who don't require any it account so I would like to completely ignore them in midpoint I don't want to import them I don't want to provide anything for them so chances are you will be able to influence how the CSV looks but if you can't or if you don't want to do That we can do it via midpoint so I will go to back to the configuration of the object type and I will configure so-called classification filter classification filter is a query I will I'm lazy so I will copy paste it
and I will basically consider everybody who has M type attribute equals FTE full-time employee I will consider them as my accounts which I would like to use everything else should be ignored which means these uh cleaners or gardeners Should not match that so I'm saving this and uh now I need to do something which is called uh reclassification of data which is in the standard resource user interface if I display all accounts which are on this resource and run this reclassify button on background there is a task created and it will reclassify my accounts when
this finishes which should be couple of seconds only because we have 16 16 users only this is the list of accounts which you already know from Older midpoints and you can see we have just 16 of them not 20 so these four accounts are now being ignored they are they are not considered to be uh to be standard accounts from this HR System okay so we have successfully ignored this what can we do we can configure our resource so we need for sure to have some synchronization policy situations and reactions so we for sure would
like for any unmatch to create a new user in midpoint that's at Focus and for anyone who is already linked we will run synchronized action we don't need anything else here because from this data we will never delete uh the HR data the CSV file will be never deleted nor any file of any entry and we have empty midpoint so we can afford this we can keep it simple now so I will have now simple synchronization settings and of course I need some mappings I would like to create users in midpoint right so I will
create four Mappings let's start with employee number employee number should be name of midpoint but later I will rename my user so I would like to keep employee number also in personal number attribute there we have first name in the CSV file which I will store in given name in midpoint and the surname which usually stored in family name on midpoint side so I'm just checking if I have not forgot anything we should be fine I will Save the mappings and now I will show you the simulation for the very first time I will start
for example with the first one and instead of the action which you probably know for years import I will use import preview import preview is running simulation import only for that particular account I will need to specify that this should be simulated task running with development um configuration because my resource is in Proposed configuration and in the other choice in production it would be not used so the simulation is running and I can see the result I can see that there will be new user created 1,1 with six attributes being pop it and of course
this is my G green that would be created in midpoint like this now I will show you that we are actually running always in iterations I have only created mappings for four attributes but I actually need More so I will get back and add two more mappings so I will go to mappings and add mapping for locality locality should be also stored in locality and I would like to have also life cycle populated so that we can have either enabled disabled or something else for that I will use a script and it will be stored
in the life cycle state so the script I have it handy so I don't need to type It the script is basically short groovy script where if the value from the status attribute is in I will return life cycle State active if the value is long-term leave I will return suspended and if the value is former employee I will return arived so this will set up the life cycle in midp point now I will save it and I can run the simulation for this particular HR entry once again still it's development configuration because that resource
it in propos Proposed state and you can see that we are now also setting the locality and the life cycle state so this is how uh we can add things still just doing the simulation nothing has been created in midpoint and we are able to improve it until we are satisfied so now we are satisfied I would like to import the data now so we have connected to the HR System now we would like to use that system to import actually data I will move the life cycle of the Resource to active state so now
everything which is in this resource is considered to be to be active the configuration and we need to import the data fortunately in 4.8 we have a very nice visard to create a new task right away from here so I will just click create task I know it is the import task so I will create this new task I don't need to specify any name it's generated automatically if I don't specify a value I don't need to specify Which kind of objects or intents or whatever that's inherited from the accounts page where I was I
will run just a single thread and now the import is running while the import is running I can go to the users and you can see that we have imported everybody from that file if I edit random user from here you can see the values are populated life cycle State including and these users of course have linked the HR projection the HR account So now we have done that and of course we have not imported this maintenance cleaners and gardeners because there is no username starting with 8,000 so they are really ignored by midpoint now
I would say that I would like to have my users displayed here under the persons because person is uh built-in archetype from midpoint 4.8 and I would like my users to be considered as persons okay so I will need to get back to the Resource once again to HR and I need to modify the configuration of my basic attributes where we specif ify that we would like to populate archetype like assign the archetype for this for these people uh why I'm doing that because later I will use this archetype as some kind of Birthright so
I will use it for provisioning so I will save the settings and we can rerun the Task and if if I go to midpoint persons you can see we have imported them the difference is they have they have now different icon if I edit any of these users you can see it is a person you can also see that full name is being filled for everybody who is person I will talk later why we have the full name populated but I like what I see so I'm satisfied with that that's the default behavior of person
archetype okay so let me see my notes now we have Connected the First Source system and we have imported in several iterations the data from there now of course starts the more serious work because we would like to work with the target system so we have the active directory or open El up which is simulating pretending to be active directory and I will first show you the configuration that we already have it there for example we already have the Synchronization situations and reactions these are typical situations and reactions for a Target system I would like
to uh emphasiz this for unmatched situation the reaction is delete resource object I wanted to show you something potentially dangerous and how midpoint will help you when you are using the simulations from bad things to happen so I will keep it like this you can see everything is in proposed so ready for Simulation also the whole object type and whole resource are in propose so I will need to make several mistakes in configuration to do some harm because everything is only configured for simulation except except of the synchronization we also have a correlation rule one
correlation rule is currently active the second will be added a bit later this this one is disabled the first correlation rule is Using smart correlation using the items if anyone of you have already seen that in older M points and basically we are correlating using the personal number in midpoint equals employee number in the in Lup so that will be the default correlation and we also have inbound mappings which are used during this correlation they are used only during the correlation this icon is saying Specifically that this last one is used for correlating amplo number
equals personal number the others will be used for the second correlation rule which we will need a bit later so let's try to run first reconciliation what will happen I have created three tasks already in advance so that I can do it a bit faster and I will run reconciliation reactive directory task which is in development simulation meaning it is simulation of Reconciliation running with development configuration that means only active and proposed configuration now everything is proposed so mainly we will see the proposed configuration I click to the statistics just like in any reconciliation task
we can see the states so we have 15 accounts that would be linked would be reconciliation is just simulated so there would be 15 accounts linked there would be five accounts Unmatched and there is one account already protected this is from the configuration of resource the old-fashioned protected accounts one of them is set there so this is the status of the reconciliation the Shadows were already created of course and let's see the simulation result now it starts to be interesting if this would be real real reconciliation you would be already deleting five accounts Because you
can see that M mode is going to delete five objects so I will go there first I will show you these modified objects 30 because that would be easier to understand you can see there are all users from midpoint for example this one and the modification which midpoint is about to do is adding the new projection to the list of projection so result of correlation that means the majority of the accounts would be linked and the projection list link Graphs would be updated if I go back to projection de activated so if I click there
I can see five objects would be deleted so Anna Lopez is a problem because this is our CFO of the company we cannot afford to delete her the problem is because she has incorrect uh employee number she will be not able to be correlated by the default employee number so what can we do we can make exception my exception would be that I will click here and set Account Mark correlate later from now on she will be ignored during the correlation and I can do something later I will not stop the whole show just to
resolve one user then we have mail service account this is clearly protected account so I will mark it as protected then we have secret admin secret admin is actually some kind of vector or hacker account which I would like to show how midpoint can do something so I will definitely not make Any exception for that I want to get rid of this account spam asassin account is protected account will be from now and there is test one to three nobody knows what it is we don't know if we can afford to delete the account so
let's mark it for example as do not touch we have different uh marks like protected and do not touch are behaving the same way but they could represent different meanings so I will mark this as do not touch for Now after I do this I can run the simulation once again so I will go back to the task run it again and now in the simulation result surprise surprise only one account is to be deleted which of course is the secret admin because all others including Anna Lopez have been marked as either protected or something
else using the shadow marks so midpoint will not do any Harm to these accounts secret admin is at this point disposable midpond will not do anything yet but very soon so it looks like our active directory resource is behaving quite well after what we have done we have set up the marks to represent exceptions and uh for everybody else midpoint is doing the linking just like we would like to do that so let's move this resource from proposed to the the active State and let's see what we can do now so I will Switch the
whole resource to active life cycle that's not enough I need to go to schema handling and do the same for the object type for accounts now I need to save it and edit again and uh when we talk about the synchronization settings I will simply activate all these actions except of unmatched to delete resource object I will not do it yet because maybe in five minutes somebody else will create some uh some Orphan account in active directory and then I would simply delete it without any warning warning so I will keep it for now like
this and temporarily I will be not enforcing in real production this uh Delete resource object but everything else should be okay now I can run the simulation once more this time this one production simulation what does it mean this means it is still a simulation it is still a simulation but running production Configuration that means active and deprecated configuration not proposed so what is proposed is completely ignored now this is as close to reality to real run of task as possible now if I check the simulation results I can see no problems with deletes because
that part which was deleting the the secret admin account is proposed state and that's not being evaluated now we are not doing any kind of bad modification just we are attempting to modify the link graphs Because we are doing the correlation that's fine so this is what I want now I can run the real reconciliation and correlate the existing accounts so I will simply run it and if I switch to persons you can see I will reload it you can see everybody except of this user has been correlated with their corresponding active directory account so
if I click any random user you can see she has two accounts including the Active directory of course Anna Lopez has one account because she has not she has not been correlated before we need to take care about her a bit later but we have moved moved forward significantly we have now correlated vast majority of all accounts from active directory and we have not stopped the whole show because of just one account which cannot be correlated so we are now at step import usernames if we have Correlated our accounts from active directory for sure we
can import the usernames for them so that we don't see the employee numbers here for that we need to go to resources and first we will modify the mapping which is currently creating the username so the inbound mapping for AGR resource which from employee number is populating name I will not yet remove this mapping but I will set its uh strength to weak that means it will be used only if there Is no other mapping populating the value and if the value is empty so this will be like a default login name if there is
nothing else because not everybody would need to have active directory accounts and I need to Al also modify the active directory and I need to add new mapping there so obviously this will be inbound mapping so let's add a new mapping we can have also name for that mapping uid attribute s is mapping name And we are going to simulate it so I will mark this Mark this mapping as a life cycle proposed that means it will not be used for anything but it will be used for simulation only if I run a simulation task
I can try this for any single account for example The First One Import preview in development because I would like to see what that uh proposed mapping will Do and I can see that simulation shows me that the user would be renamed if if I click on that specific user you can see name is going to be changed from 1010 to a Freeman looks good okay let's run a simulation for everybody so again I will just run the simulation task which is running with development configuration meaning everything which is in active and proposed and you
can see here that 15 users are going to be Renamed if I click the details you can see midpoint will do this that looks okay of course you might be like wondering why there is still this deactivation of course that's our old secret admin account which is not being processed in the real runs but during simulation because that piece of configuration is in proposed life cycle state in simulation where we are working With development configuration it is being processed therefore it is indicated here but what we care is that the username import looks to be
okay so what we can do is we can edit the inbound mapping for uid and we can move it to active State we would like to use it now if I run the real reconciliation my usernames should be already imported of Course except Anna Lopez she is not handled yet because she has has not been correlated yet but you can see everybody has been automatically renamed because we have evaluated that mapping so as the usernames were unique in in active directory they are uning also in midpoint and we already have these users usernames we are
not doing doing anything without with these usernames in this training but imagine that in the future we could allow these users to use Uh login from Windows and uh Windows password to authenticate to midpoint so therefore this could be this could be useful so now we have imported even the usernames one thing which we can do at this point is we can get rid of secret admin so that secret admin should not be there it is still popping in all of the results of uh of the simulated reconciliation let's handle such accounts and let's switch
also this part of configuration to production so if I Save this now midpoint will delete all unmatched accounts which are not marked so I will save the synchron ation settings again we can simulate first now using the production simulation task because nothing is in proposed everything is already in production but it will be simulated so we are simulating what will happen if everything is correct if I have not forgotten anything we should see and we are seeing only one deleting Deleted objects which of course is our secret admin which of course I can now run
the task for real without any simulation ah was already there run now and if I click here you can see the secret admin now I refresh secret admin is not there so midpoint has now authoritative setting to behave like this when you run reconciliation with active directory it will of course Remove all unmatched accounts which have not been previously marked to as for example protected or something else so we have now finished even the import phase uh sorry import um import of username phase one thing is still outstanding and that's Anna Lopez she has not
been correlated and now we have time to do that so okay let's do that we will go to the active directory resource I will first search so that we Can see her she's unmatched and she has Mark correlate later so for now she's completely ignored we will enable the other correlation rule which has been prepared exactly for this the other correlation rule is using given name family name and locality we are comparing one to one if all three match we will still say that this is just a 50% uh confidentiality because you might have users
with the same first names last names and locality it will be just A 50% match and I would like to have some human to approve who should be the owner so let's enable this correlation rule first then we need to unmark anal Lopez because she will not be handled by correlation anyway and now we can try to run the real reconciliation so reconciliation is running and you can see the situation has now changed to disputed if you have Worked already with midpoint then you know disputed situation is used when midpoint is not sure who should
be the owner in our particular case this is direct consequence of saying that we trust that rule only for 50% so we would like to have some human to to decide for that we need to do one more trick and add synchronization action for disputed so for disputed we will use create correlation Case and if I run the real reconciliation once again after it finishes in cases and my work items there will be a new work item waiting for me to approve if there will be email notification of course it will be sent now we
don't have that and it is hardcoded in this configuration of a webinar to midpoint administrator but there is not much Choice to to send it to anyone because we have not finished uh the whole configuration of me right so I will click on that work item it is just an ordinary work item somebody must do something but it is different from approving because now you can choose who should be the candidate which you would like to correlate with Anna Lopez we have just one such candidate we know that given name locality and family name match
with Anna Lopez the employee number is not matching or the personal number that's because of that uh error in let's say deliberate error in the alab data and we trust this only for 50% that's what I have configured in that correlation rule so now if I click correlate owner will be set so Anna Lopez should be now owning the account and you can see she has been correlated the account username has been used so user is also renamed everything loose Looks absolutely wonderful she has her active directory account of course if you'll be curious like
I am now you will still see that employee number in active directory or Elda is still two so incorrect value but never mind this will be fixed in a few minutes so we have successfully correlated everybody including previously uncorr SS from active directory to midpoint now we are at step seven enable provisioning to Target system so I go to Active directory resource and we will check what can we do about the mappings so inbound mappings are out of the question now we don't need to type all our outbound mappings because they have been originally created
it or copied from resource template and all these mappings are in draft life cycle state so they are completely ignored like if they are not there so I will Mark some of them and move them to Proposed state display name SN given name uid location family name I think these are all I can move all of them to propos by this and of course I need to save it I want to see how good are my outbound mappings and I will use a simulation for that before doing that there are still other mappings activation mappings
for enable and disable of the account so this is Also copied from the resource template from which this resource was originally created mapping which is setting state of account based on midpoint user status mapping which is disabling the account instead of deleting when the account should no more exist and mapping which is doing delay delete you will see these two when we get to uh the levers the offboarding so I will also move this configuration to propose so I will see what would happen If and last part of mappings are credential mappings we are not
using anything with passwords but there are already two mappings one for generating random password initial password because active directory account cannot be passwordless and password change mapping if you would like to change mapping from midpoint to active directory so I will also set these save these and now I can run the simulation again everything is in Propose so it will be the one which is running in development configuration Act and proposed and let's see what will be the results the results will be probably a bit familiar because this is uh what was also on the
screenshot in the presentation midpoint is not going to delete anything that's fine but there will be some modifications you can see it here five resource objects will be affected we have also further categories Like one of them will be deactivated two will be renamed so three of them will be something else will happen let's see all of them so Alex Freeman is being renamed let's see what are the details Alex is being renamed because actually he should be Alexander Freeman and not Alex this is a clear sign of uh somebody has created this account probably
manually and not based on the author authoritative data from maor System so midpoint is basically fixing the the things if you agree with that then we can simply leave it as it is we don't need to do anything and midpoint will rename this accounting active directory second is Alis Baker so what do we have there locality is being changed from wh Stone City to hot lava city again I can check this is Alis Baker Ellis baker has hot lava city in the ARR system so m is actually fixing things which were not consistent So data
was not consistent nothing will be done uh nothing bad will be done Anna Lopez so surprise surprise midpoint is going finally to change the incorrect employee number which was clear mistake clear typo to 102 and there are two more Jane Anderson Jane Anderson is going to be disabled I know why so I will show you of course if you would do it by yourself it would take a minute or so because Jane Anderson is in long-term leave State in HR that means she should have been disabled but for reasons I know she have she have
not been so midpond is doing again improvements is going to fix it to disable the account because she should have account disabled and uh last but not least Joseph simmer here we can see actually again mistake it should not be Joseph but Yosef like in check or German language So midpoint is fixing the the data all the data which midpoint is going to change in our particular case are good changes so I'm okay I can do this I can uh move all my mappings to production to active and everything will be okay but without running
simulation I would already do it I will already deactivate the account I will already rename it without knowing in advance so the simulation is helping us to to see what's going on before we actually do That so now I will go back to the resource and I will configure these mappings from proposed state to active because we would like to work with them so one 2 3 4 five five six 7 eight eight mappings are going to be used in active life cycle state so for real run as well other mappings I will keep in
draft I don't want to use them the same I will do for Activation so I would like to disable the accounts and enable if needed in this system and the same for the credentials okay so now our resource is ready ready to be used if you want you can again run again another simulation reconciliation with simulation with production simulation that means everything which is active and uh deprecated we are not using the deprecated life cycle here and You can see pretty much the same scenario five objects are going to be changed this is the laa
or Jane Jane Anderson so this everything looks okay we can run the real reconciliation if we run the real reconciliation which should be like a couple of seconds we can refresh the data in elap Alex Freeman will be renamed you can see it here anna Lopez should have employee number 10002 that's fixed yo Josef is now Yosef and Uh Jane Anderson is being disabled in this particular Lup we are using room number for that so sorry room number attribute is set so we have done what we should have done of course everything was audited if
I go to audit look viewer this is the task which I was running and everything the task has done so for example if I click on Jane Anderson here you can see that the account was disabled in active Directory and for example here is the Alex Freeman you can see the changes how midpoint done it so what was in the simulation of course was now done for real the last scenarios are related to automation we have imported data to midpoint we have correlated everybody we have marked some account as protected we have correlated uncorrelated users
we have imported Usernames we have prepared our re resource for targets provisioning now let's put it all together so we first need to resolve the usernames so the usernames mappings which are being used until now will be removed I will go to inbound mapping of HR resource and this is this mapping and let's move it to Archive life cycle I don't want to use it anymore I go to active directory Resource I have inbound mapping there as well mappings and I will move this to aiv as well there is now no mapping that would create
the username is in midpoint but person archetype comes also with object template person object template we can use that one and we will use that one to generate also the username this template contains also the full name generator which you have already seen that mapping is active that's built-in part of of a Midpoint this person object template if you are using person archetype and there is sorry second mapping which is generating the username that could be also useful as some account name so it's uh less than 20 characters let's activate this mapping for the person
object template and now we need to create some users in uh the demo application so I will create just two because of time Louis Kellahan and second will be somebody with uh duplicated or to be duplicated username so a baker we already have a baker let's see how midpoint will will work so I have created to users I need to export them and we will try and first simulate import to see these new accounts we need to reload data so midp will fetch the data and create Shadow objects and let's See what import preview will
tell us now I need to use simulated production because there is no more we can see user l k would be created we can see it even here this is the new username so that looks okay and what about the other one the 90001 again Sim at with simulated production a baker 2 so that looks wonderful this is what we wanted to have midpoint is iterating in case the username is already Taken so the last thing which we will do here is we will configure we will configure regular synchronization again using this visart reconciliation for
example like this I don't need to put the name but just just to show that we can interval let's have 30 seconds task will be executed right away and we should see L kah user has been created as well as aaker 2 as you can see they don't Have the account in active directory yet because we didn't say anything to to midpoint that it should create the accounts now comes the reason why we were using the archetype person we don't have any roles at this stage there would not be any roles we we cannot expect
it now but we have the archetype and archetype which we have already assigned to everybody can be used as a Birthright so we can put there default permissions Default accesses default things that everybody who is person should have so I will take it as it would as if it would would be a role and I will simply create inducement for resource account construction I want to create account in active directory it should be default account I could even put my user to groups sorry my account to groups but I don't want to do it I
don't want any extra mapping I just want to save it the arcab is Automatically saved and if we wait couple of seconds we should see these two users relatively soon you can see they have been provisioned so if I click to PHP up admin of course we have Luis kellahan and we have Andreas Baker so provisioning is working just like you would expect and the absolutely last thing to show is how mmod is handling the data Modifications and levers so I will modify Gina green for example let's change the locality for her I will disable
Martin Knight or I will put him to long-term leave so this should be disabled in midpoint and the Peter Hunter will leave the company so I will save all this we have reconciliation now so we will see it I will create a Query and we can see that something already happened so I will start with Hunter Hunter is former employee he's in life cycle aircraft this means he still has the account accounts but the user is disabled all his accounts should be disabled as well let's click on active directory account and you can see he
is disabled and there is a trigger which is visible here and of course also in the list of projections that in exactly 3 minutes after he was disabled because of This change he would be automatically deleted before it happens I have a dashboard where we will see it we have a dashboard where I can see all users who have any account with triggers so that's only our hunter second viget only the accounts with trigger so that's the the hunter account and users without ad accounts currently there is only administrator after a few minutes there will
be also Peter Hunter but let's get back to these Changes so we also changed Gina Gina has now locality hot lava city if I would check the user's history so this is the audit lock filtered for this user I can see that really we have changed the locality in Elda for active directory and we have also changed the locality on that user so midpoint has done what what we expected midpoint to do and what about the last one the night user night user is suspended so if somebody is in long-term leave it will Be set
as suspended and of course the active directory account is also disabled so in couple of minutes I will make it faster but we need it that three minutes to to go in a couple of minutes also this account will be deleted the trigger is at uh 13 so we need to wait a bit we need to wait one minute or at least 26 seconds after the the minute so still a few Seconds and I will make it faster I will not wait until the trigger scanner task which is default in midpoint which is to be
executed in 3 minutes it's running each 5 minutes I will make it faster by executing that immediately now if everything is correct I should be able to see on that dashboard with ad account notices there are no more account with triggers no more accounts and no more users with triggers and there are now two users Without active directory accounts one of them is of course our hunter hunter is archived has only one projection which is the ARR and of course if I refresh it this entry will disappear Peter Hunter is gone so this is actually
the end of my live presentation I will switch to the few slides which I have the conclusion you have now seen in one hour that we have demonstrated midpoint Deployment in iterations using First Steps methodology of course it was short and of course it was a bit fast but you have seen these steps like we were able to continue even if there were some issues we have used only user interface no XML was involved we have cleaned cleaned up the orphan accounts in active directory we have marked exceptions we have set the policy to detect
the orphan accounts in The future we have automated the provisioning from HR to active directory now limited to accounts we could also add uh group membership but we didn't have it for the time constraints we have corrected active directory data to correspond to HR data so data consistency is now improved and all the time we were using the simulations to make sure that there will be no unexpected changes no unexpected Deletes everything what happened was expected because we have run the simulations so midpoint was helping us very much to pre prevent any bad things from
happening if you ask what could be the next steps in this world of this project which we have been showing then it's up to you because you could continue with connecting other Target systems one by one connect clean up automate or you could continue with connecting other source system for Example for different population if there are completely different people who are not covered by this sorts of data connecting them should be quite quite simple or you could import active directory groups as roles and start managing them so also their membership through midpoint from midpoint if
you ask what should be your next steps so if you want to know more about how exactly we did it how this all works not just in one hour but to have Some time for that we have now training midpoint deployment first steps which is based on this methodology basically this webinar is taking the configuration and data from there in this training you will learn how to do all this plus the details why it is working like that and also more because not all scenarios were presented here so if you would like to attend the
first steps training of course contact aolone please that would be that would be very very very nice uh If you want to know even more there will be other webinars so two of them would be related to this resource wizard webinar which will be November 21st and simulations webinar which will be on December 7 also the others and there will be more webinars coming in 2024 and if that would be still not enough then you can meet us at at time un conference which will be at the end of January and start of February in
Copenhagen in Denmark we have there also Midpoint working group and one of the workshops that will be there will be first steps Workshop so you could have real hands on on on that you can see the agenda of course for for this uh uh unconference and if you would like to have some presentation of course you can contact us at marketing uh that would be everything from me