out of band sync was a great idea, however it doesn't seem that we can take advantage of it where we need it most, and that is for user password changes needing to be quickly synched across the IDM environment.
The problem is with it turned on, with a user create event, the password is sent ahead of the actual user creation, to which there is no object to set the change on, and since it is then "optimized" out of the actual create event going through the normal cache, the user create fails in some target systems like Active Directory, or any system where password is a requirement for a user creation.
We could really take advantage of priority sync for user password changes, except this nuance does not allow us to turn in on.
by: Mark M. | over a year ago | Other
Comments
I rather consider this a bug, please report it at https://bugzilla.netiq.com/enter_bug.cgi?classification=Identity%20Manager
This is not a bug. We can discuss priority for this but it is an enhancement request.