Solved

Is deleting the IAM User the right approach when AD changes?

  • 14 December 2023
  • 2 replies
  • 70 views

Userlevel 6
Badge +18

In IFS Cloud we use SSO and have a business unit that just changed their Active Directory information as part of a renaming.  Once the AD domain name changed, users were no longer able to log in to IFS using the new domain name.

Looking at the User Details screen in IFS we can see that although the Directory ID and email for the user were updated to the new AD values, the IAM User account associated to each user did not change.  This value does not appear to be changeable.

When we delete the IAM User and the user logs in again using their new domain details it then works, and a new correct IAM User account is automatically created and associated with the User.  The new IAM User account is then included in the User Details screen.

Is this the correct approach to align/fix IAM accounts for users after a domain name change in AD? 

Or is there something else that should be done instead (or in addition)?

 

Thanks in advance,

Nick

icon

Best answer by Aswin Shadhujan 15 December 2023, 16:02

View original

2 replies

Userlevel 3
Badge +9

Hi @NickPorter ,

 

Yes, deleting the IAM user is the correct approach when you do any changes in the IDP configuration.

 

Thank you,

Aswin.

Userlevel 6
Badge +18

Thanks @Aswin Shadhujan .  Are there any other steps we need to take from an IFS user perspective, or is this all that is needed?

Thanks

Nick

Reply