Hi All,
We have a requirement from one of our ISC customers who is keen to put some threshold driven controls over bulk provisioning activities. For e.g.
Detect the following activity and stop processing it any further (Alert & Avoid):
- HR source tries to update more than 10 attributes for a user
- More than 10 AD account create requests initiated by the system within ‘X’ minutes
- More than 10 AD account delete requests initiated by the system within ‘X’ minutes
- Identify and avoid removal of licensed group memberships from AD account for a user
We have looked through at Workflows, APIs, Search, Before Provisioning Rule, Tags etc. methods to identify possible solutions. #4 can be achieved relatively easily. However, I am looking at more feasible solution options for #1-3.
We are looking at anything and everything from what can be developed within ISC. Trying to avoid bespoke & bulky solutions.
Appreciate if anyone has encountered such requirements before and has some good recommendations to solve them.
Thanks
Sonal