{"id":2202,"date":"2012-10-18T21:15:32","date_gmt":"2012-10-18T21:15:32","guid":{"rendered":"https:\/\/www.wapshere.com\/missmiis\/?p=2202"},"modified":"2022-08-21T16:07:38","modified_gmt":"2022-08-21T16:07:38","slug":"fim-best-practice-handle-deprovisioning-with-care","status":"publish","type":"post","link":"https:\/\/www.wapshere.com\/missmiis\/fim-best-practice-handle-deprovisioning-with-care","title":{"rendered":"FIM Best Practice: Handle deprovisioning with care"},"content":{"rendered":"<p>I have two personal rules I always follow when implementing disabling and deprovisioning:<\/p>\n<ol>\n<li><strong><em>Never make decisions on an absence of data,<\/em><\/strong> and<\/li>\n<li><strong><em>Never make destructive changes straight away.<\/em><\/strong><\/li>\n<\/ol>\n<p><!--more--><\/p>\n<p><strong>Never make decisions on an absence of data<\/strong><\/p>\n<p>A common scenario has HR offering a list of all &#8220;current employees&#8221; meaning that when someone leaves they disappear from the list. We are then expected to take this as a sign to start disabling and even deleting objects. This is a great way to set yourself up for disaster.<\/p>\n<p>Items disappear off lists for all sorts of reasons. Here are some real examples I know of:<\/p>\n<ul>\n<li>A SQL replication error cropped the user list and hundreds of accounts were disabled,<\/li>\n<li>HR changed the way they handled contractors and thousands of contractor accounts got disabled,<\/li>\n<li>AD accounts were moved to a different OU, putting them outside FIM&#8217;s scope, and causing it to disable accounts in another system.<\/li>\n<\/ul>\n<p>All of these problems would not have happened if we only made decisions on <em>actual data, <\/em>rather than an absence of data. So make sure you still have access to information about people after they&#8217;ve left.<\/p>\n<p><strong>Never make destructive changes straight away<\/strong><\/p>\n<p>We should always allow for errors: perhaps a person&#8217;s contract was extended but their new end date has not been updated yet. FIM can&#8217;t know about the extended contract and can only work on the end date supplied so the correct thing is for it to disable that person&#8217;s access. Once the problem is noticed and the source data corrected we then want FIM to put everything back the way it was with no intervention.<\/p>\n<p>Often IT administrators follow manual process which involve destructive actions like removing group memberships, detaching mailboxes and deleting accounts. I always insist that FIM only make reversible changes in the first instance, such as disabling login, and then proceed to destructive changes only after a suitable grace period has passed.<\/p>\n<p><strong>Do we always need to import people who have gone?<\/strong><\/p>\n<p>We don&#8217;t need to know about people who have left for ever. My general rule is this: as long as I am maintaining a connection to a target account I want a link to the source object. Once all target accounts have been cleared away then we don&#8217;t need to see the source object any more.<\/p>\n<p><strong>More on Deprovisioning<\/strong><\/p>\n<p>I once wrote an article on <a href=\"https:\/\/www.wapshere.com\/missmiis\/account-deprovisioning-scenarios\">ILM Deprovisioning<\/a>. It is all still relevant to FIM, and the code is the same if you&#8217;re using classic.<\/p>\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I have two personal rules I always follow when implementing disabling and deprovisioning: Never make decisions on an absence of data, and Never make destructive changes straight away.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"footnotes":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false,"jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":[]},"categories":[55,42],"tags":[],"class_list":["post-2202","post","type-post","status-publish","format-standard","hentry","category-best-practice","category-fim-2010"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/pkp1o-zw","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/posts\/2202","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/comments?post=2202"}],"version-history":[{"count":14,"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/posts\/2202\/revisions"}],"predecessor-version":[{"id":3279,"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/posts\/2202\/revisions\/3279"}],"wp:attachment":[{"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/media?parent=2202"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/categories?post=2202"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/tags?post=2202"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}