IBM Verify

 View Only

 "Users Endpoint Filter Query" adapter parameter

Nicola Montibelli's profile image
Nicola Montibelli posted 06/01/26 04:22 PM

Hi to all,

I am using the latest version of the connector, "IBM Security Verify Governance Adapter v 10.0.18 for Microsoft Azure AD" in IBM SVG 10.0.2, and in order to limit the scope to a specific subset of accounts (and groups), I am using the connector parameter "Users Endpoint Filter Query" with the following value:
endswith(userPrincipalName,'@mydomain1.com')

 

The synchronization works correctly for ADD/MODIFY events, but it does not seem to work for DELETE events.

 

Is this an intended limitation?
Franz Wolfhagen's profile image
Franz Wolfhagen

You should raise a case and get an answer that way.

That said - I do not really understand the use case - how should a filter like this apply to a delete - when you have applied the filter I would assume you have only accounts/groups that matches that filter - so what is your expectation ? 

Nicola Montibelli's profile image
Nicola Montibelli

@Franz Wolfhagen

the use case is this: I have a unique azure tenant with different "suffix domain", with the filter I can manage separately different "suffix domain" with dedicated "enforced rule".

By the way, I restarted from the baseline configuration in test env and I found that delete "events" is not propagated in any case. I opened a case to IBM because it's very strange.