EmpowerID IBM Domino connector allows organizations to bring the user and group data in their IBM Domino system to EmpowerID, where it can be managed and synchronized with data in any connected back-end user directories. Once connected, you can manage this data from EmpowerID in the following ways:
Additionally, EmpowerID provides Provisioning policies or Resource Entitlements that allow you to automatically provision Domino accounts for any person within your organization based on your policy requirements. For more information on Resource Entitlements, see Configuring Provisioning Policies.
This topic demonstrates how to connect EmpowerID to IBM Domino and is divided into the following activities:
The wizard displays the Lotus Notes Server Configuration screen.
The wizard displays the IIS Settings screen. You use this screen to provide the service account identity and IIS information needed by EmpowerID to communicate with the Domino Web service.
After installing the EmpowerID Domino Web service, the next step is to connect EmpowerID to your IBM Domino Lotus directory.
https://192.168.15.99/LotusNotes/LotusNoteService.svc/v1
This opens the Account Store Details screen for the Domino connector. The use of this screen is discussed in the next section.
The Account Store Details screen contains three panes—the General pane, the Inventory pane, and the Group Membership Reconciliation pane—each with settings for configuring a different aspect of the Domino account store you just created. To view reference information about a particular pane, expand the drop-down for that pane.
This pane is used to set general configuration information for the Account Store.
Account Store Name - This is the name you gave to the account store when you created it. To change this name, click the Edit button, enter a new name in the Account StoreFriendly Name window that appears and then click OK to close the window.
Resource System Name - This is the name of the resource system EmpowerID created for the account store. To change this name, click the Edit button, enter a new name in the Resource System Friendly Name window that appears and click OK.
Resource System Type - This is the type associated with the resource system. In EmpowerID, resource systems contain objects specific to the type. For Domino, the resource system type is "Lotus Notes." This value should not be changed.
Maximum Accounts per Person - This specifies the maximum number of user accounts from this domain that an EmpowerID Person can have linked to them. This prevents the possibility of a runaway error caused by a wrongly configured Join rule. It is recommended that this value be set to 1 unless users will have more than 1 account and you wish them to be joined to the same person.
Icon - This is the image icon that represents this account store in the EmpowerID user interfaces.
Enable Pass-Through Authentication - This allows domain authentication to be used for logging in to EmpowerID. Unless Simple Search is enabled, the domain\username format needs to be used.
Enable Simple Username Search for Pass-Through Authentication - Simple search works in conjunction with pass-through authentication to allow users to log in without specifying a domain name. When this is enabled, EmpowerID first checks to see if the user name entered exists within its Identity Warehouse and if so attempts to authenticate as that user. If a matching logon name exists but the login fails, EmpowerID then searches through all Accounts Stores where simple username search is enabled to find the correct user name and password combination. To enable this function, click the Enable Simple Username Search button to the left of the line and toggle it so that the green check is visible.
Allow Password Sync - Enables or disables the synchronization of password changes to user accounts in the domain based on password changes for the owning person object or another account owned by the person. This setting does not prevent password changes by users running the reset user account password workflows. To enable this function, click the Allow Password Sync button to the left of the line and toggle it so that the green check is visible.
Allow Person Provisioning - Allows or disallows EmpowerID Persons to be created from the user records discovered during inventory.
Enable Attribute Flow - Allows or disallows attribute changes to flow between EmpowerID and the account store.
This pane is used to enable or disable inventory of the Account Store as well as to set the run schedule for the EmpowerID Inventory Job.
Inventory Schedule - This is the time span that occurs before EmpowerID performs a complete inventory of the resource system. The default value is 10 minutes. You can change this at any time by clicking the Edit button.
Enable Inventory - This allows EmpowerID to inventory the Account Store. The Inventory Job must be enabled for inventory to occur. This is discussed further in the below section.
Inventory Provision Request Workflow - This is the request workflow that is initiated when new accounts are discovered via the inventory feature. If you set this workflow, the
Allow Automatic Person Provision and Allow Automatic Join Provision flags described below are ignored. You can enable this feature by clicking the Edit button.
Allow Automatic Person Provision on Inventory - This allows EmpowerID to provision EmpowerID people for new accounts discovered during the inventory process if they meet the Provision Rule specified by the Custom_Account_InventoryInboxGetAccountsToProvision SQL stored procedure. This setting is discussed further in the below section.
Allow Automatic Person Join on Inventory - This allows EmpowerID to join newly discovered accounts to people during the inventory process if they meet the Join Rule as specified by the Custom_Account_InventoryInboxJoinBulk SQL stored procedure. This setting is discussed further in the below section.
RBAC-Assign Initial Group Membership On First Inventory - This setting pertains to Active Directory account stores only.
Re-Inventory - Enabling this option re-inventories all changes.
This pane is used to enable or disable and schedule group membership reconciliation for the domain. When this function is enabled, EmpowerID dynamically manages the membership of the Account Store's groups, adding and removing users to and from groups based upon policy-based assignment rules.
Membership Schedule - This is the time span that occurs before EmpowerID runs the Group Membership Reconciliation Job. The default value is 10 minutes. You can change this at any time by clicking the Edit button.
Enable this Functionality - Enables and disables group membership reconciliation on the Account Store.
For a greater discussion of these points within the context of connecting EmpowerID to an account store, see Connecting EmpowerID to Active Directory.
In our example, we have set the Attribute Flow Rules to Bidrectional for all attributes except the Email / InernetAddress and EmployeeID / employeeNumber attributes, which are set to Account Store Changes Only.