terça-feira, 20 de agosto de 2013

Deleting Application Instances

Deleting Application Instances

OIM 11g R2

An application instance can be deleted in any one of the following ways:
  • Deleting the application instance from the Application Instances section of the Oracle Identity System Administration.
  • Deleting the IT resource, which is a constituent of the application instance.
When you delete an application instance by using any one these methods, the application instance is not hard-deleted from Oracle Identity Manager. The application instance is soft-deleted. This is because accounts provisioned as a result of the application instance might exist in the target system. Therefore, after deleting an application instance, you must run a scheduled job to achieve the following:
  • Unpublish the application instance from the entity publication
  • Unpublish the associated entitlements from the entity publication
  • Revoke, or hard-delete, or mark as deleted all the accounts for the application instance
To delete an application instance:
  1. In Oracle Identity System Administration, under Configuration, click Application Instances. The Application Instances page is displayed with a list of application instances that are published to your organization.
  2. Search and select the application instance that you want to delete.
  3. From the Actions menu, select Delete. Alternatively, click Delete on the toolbar. A message box is displayed asking for confirmation.
  4. Click Delete to confirm. The application instance is soft-deleted in Oracle Identity Manager.
    You can also delete an application instance by deleting the IT resource of the application instance. For information about deleting IT resources, see "Managing IT Resources" in the Oracle Fusion Middleware Developer's Guide for Oracle Identity Manager.
  5. Run the Application Instance Post Delete Processing Job scheduled job. This scheduled job can be run in any one of the following modes:
    • Revoke: This mode is used when the application instance is deleted, but the provisioned accounts in the target system still exist. Using the Revoke mode deletes the accounts from the target system.
    • Delete: This mode is used when the target system no longer exists, and there are no traces of the accounts in Oracle Identity Manager. Using the Delete mode hard-deletes the accounts from all provisioning tasks and targets, and subsequently from Oracle Identity Manager.
    • Decommission: This mode is used when the target system no longer exists and the provisioned accounts cannot be revoked from the target system. Using the Decommission mode changes the account status to Revoke without keeping the accounts in Oracle Identity Manager in provisioned state.
     
  6. Run the Catalog Synchronization Job scheduled job. This scheduled job identifies the soft-deleted application instances, and removes them from the catalog.