When the SU01 user group (under User System Details tab) is mapped to populate a field value from the LDAP directory, the field is not populated in the request form and is then not provisioned. Note that when the same LDAP directory field is mapped to a field under the User Details tab (i.e. Function or Department), the field is populated in the request form and provisioned in the target system as expected. However, when we map the same LDAP directory field to user group (SU01 Logon Data), it is not populated/updated in the request form and not provisioned, but rather populates with the current target system user group value.
GRC Access Control 10.1
- Access request
KBA , GRC-SAC-ARQ , Access Request , Problem
