Deleting a User with IDXML


26/07/2008

Certain actions (such as creating or removing an LDAP entry) are only available via OAM’s ‘workflow’ engine. A freshly installed OAM system has no workflows configured, thus, no immediate mechanism to affect such actions.

To the newly initiated, discovering the create workflow mechanisms are relatively straightforward. But the delete, however, tends to throw people for a loop at first.

The trick is to create a ‘Deactivate User Workflow’. Exactly what this workflow does is up the user building the workflow. You’ll find, following the definition of the initial step, three similar action choices:

  • deactivate
  • disable
  • delete

If your goal is truly to whack the account, choose delete. Otherwise, a choice of disable will set the user account ObUserAccountControl flag to DEACTIVATED (with no human interaction required). By default, the Identity System ignores DEACTIVATED accounts in the user searchbase. The deactivate action accomplishes the same thing but it requires a human participant to actually push the button to confirm the action.

Lastly, if you want to access this ‘Delete User Workflow’ from IDXML you just need to keep in mind that it is a workflow you are calling. Pay close attention to:

  • function=”workflowDeactivateUserSave”
  • and the fact that you do provide the workflow DN in the call

Here is a complete request for calling a Deactivate User Workflow:

 

No Results