0 votes

Hi,

We've got a business case where we want the initiator of an account creation process to have the manager of the account 'hard-set' as *their* manager (as part of a 'break glass' procedure where a normally non-permissioned user can create an account, but we force their manager to be 'made aware' and be responsible for the account etc).

The issue I have is that I cannot auto-insert the attribute in the correct (DN) format in the data input form; I can insert initiator-ManagerUserName, Fullname etc, but not initiator-ManagerDN, as it's not an available attribute.

Is there a clever way for me to achieve this, or can you add this attribute to the list of those available in a future release?

by (1.6k points)

1 Answer

0 votes
by (216k points)

Hello,

As far as we understand, you want the initiator's manager to also become the manager of the new user. Are we getting you right? If so, it can be easily done with the help of a PowerShell script run a Business Rule. The Rule will be triggered after creating a new user.

Also, we've added your suggestion to our TODO list. Thanks!

0

Yep - this is our workaround.

It's made slightly harder by the fact that we have made the Manager field mandatory, so we first insert the initiator and then change it with a business rule as you suggest.

0

Hello,

Starting from the Adaxes 2014.1 released today, you can use the %adm-InitiatorManagerDN% value reference that is resolved into the distinguished name (DN) of the manager of the operation initiator. Find the latest build here.

Upgrade Instructions.

For a complete list of new features and improvements, see What's New.

Related questions

0 votes
1 answer

Hello, I want to include in a sent email notification after removing a member from a group the active directory user property "company" and "co" of a user. How can I achieve this? I can not select a property %adm-membercompany% nor %adm-memberco"

asked Jun 7 by fabian.p (380 points)
0 votes
1 answer

Hello, I would like to ensure that before a computer object is moved in Adaxes, the user must enter a ticket number, and after the input, the PC is moved to ... prompts the user to enter a ticket number before the move/delete operation? Kind regards, Fabian

asked Mar 20 by fabian.p (380 points)
0 votes
1 answer

I'm in the process of creating a Web interface for requesting IT accounts. Upon submission, I want to run a Powershell script that will create an item in a Sharepoint task list.

asked May 14, 2021 by sandramnc (870 points)
0 votes
1 answer

Is it possible to create a business unit and have it auto populate with group owners in a specific OU. I've tried a few scripts to get propertie adm-managedbylist but none have worked so far.

asked 6 days ago by C27 (20 points)
0 votes
1 answer

I am trying to have a scheduled job that will hide groups that are empty and I can not seem to figure out how to do it.

asked Aug 20, 2021 by hgletifer (1.3k points)
3,549 questions
3,240 answers
8,232 comments
547,814 users