# What is Cymmetri?

<figure><img src="/files/82epK41fc1jy3DlRkhyB" alt=""><figcaption></figcaption></figure>

## What is Cymmetri?

Cymmetri is a **Converged Identity & Access Management Platform** and a well-trusted platform acting as an advisor and an end-to-end partner for Security-aware teams looking to deploy Identity and Access Management Solutions across their organization.&#x20;

We offer an industry-standard product backed by a strong team that always aims to innovate our solutions to cater to a wide variety of enterprise needs.


# Release Notes


# 3.1.0

**Version: cloud\_3.1.0 product release**

**Date:** 02 May 2024

## **New Features**

1. Add Welcome Guide when no nodes added
2. Amaya Operations cards messages updated
3. Tooltip DX enhancements
4. Add confirmation dialogue when request method is missing
5. File Upload Validations based on filename length and file size
   * File validation applied on User Bulk Imports, Group Assignments, Application Assignments, Role Imports, Upload metadata SSO.
   * Branding Image upload applied image size validation and image name length valdation.
   * Validation also applied on self service User avatar upload, application icon upload.
6. Cymmetri Verify App issuer format is changed now so there wont be duplicate record creation from now onwards, earlier we did not take into account of the environment but now we are considering that as well

## Fixes

1. Deprovision Via scheduler when threshold value is set:- Past date user is also getting deprovisioned when rule is applied on status ﻿
2. ﻿Application-Role-One role mandatory, validation should be present at least one active ﻿
3. ﻿Node name without spaces overlap ﻿
4. ﻿Amaya- Not able to drag down node which is at the top most corner ﻿
5. Campaign - Campaign action reminder email time calculation wrong ﻿
6. ﻿Campaign- Campaign is getting aborted and summary is showing blank when campaign for local group is executed. ﻿
7. ﻿Custom attribute - When custom attribute filter is applied in users, showing no users found ﻿
8. ﻿Workflow- Preference config box is not visible while deprovisioning application ﻿
9. ﻿Self service app: While setting up secret question authentication in mobile app, user need to click twice on question field. ﻿
10. User activity Ascending Descending not working ﻿
11. ﻿Amaya Connector Recon- Showing duplicate role remarks, but in duplicate field showing 0 records ﻿
12. ﻿Identity Hub- Groups- After editing groups when on application / activity page user is redirected to users page by default
13. ﻿My workspace> Create new tags- showing older suggestion as soon as clicked on new tag field ﻿
14. AD Application - View attribute is empty ﻿
15. Tenant registration | Pressing tab key glitches UI ﻿
16. Missing error code mapping ﻿
17. ﻿Grade Workflow- When workflow preference config is set to visible, and workflow is applied for user creation, then popup box is showing user list but in pending showing unknown instead of user list
18. ﻿Amaya- When the back button is clicked, a save/discard popup box will appear. However, clicking anywhere on the page directly navigates the user away from the operation page. ﻿
19. ﻿Amaya- Save/Discard popup box should not be shown when user is trying to go back without saving any changes ﻿
20. ﻿Mobile app- Secret question- Field is showing required even when data is present in field ﻿
21. ﻿Cymmetri Verify app- Password recovery should be provided for Exported TOTP user files in case user forgets the password ﻿
22. ﻿login via Authenticator-identity provider is inactive then also user able to login. ﻿
23. ﻿syslog-configuration- UDP test, for invalid IP also giving success. ﻿
24. ﻿Unable to have TOTP account for same username on different environments ﻿

## Known Bugs

1. Manager notification: receiving user name required manager name
2. Workflow initiated for form but form is getting updated without workflow approval.
3. In application setting if show to user flag off then also application show in recent application.
4. Unable to identify application properties data type where value is empty


# 3.1.2

**Version: cloud\_3.1.2 product release**

**Date:** 13 June 2024

#### New Features

1. The workflow self-approval module was updated to support custom attributes (type: user type and Converter Type: String ) as condition parameters.
2. Teams config module updated to support custom attribute (type: user type and Converter Type: String ) as condition parameter.
3. On behalf module updated to support the custom attribute (type: user type and Converter Type: String ) as a condition parameter.
4. Auth Rule module updated to support custom attribute (type: user type and Converter Type: String ) as condition parameter.
5. Quick Setup - Setup applications using pre-defined operations
6. Import-Export App Configuration - Transfer configurations of applications smoothly between tenants, simplifying the setup for users by ensuring all configurations, including user configurations, server configurations, and policy maps, are accurately migrated.
7. Removal of Deprovision Rule Exclusion Applications Field:\
   a) Manual Execute Deprovisioning \
   b) Deprovisioning via Scheduler \
   c) Update Threshold Delete Config \
   d) Deprovision Rule Updation \
   e) Backward Compatibility \
   f) Suspend or Resume User \
   g) Impact on UI
8. Access review reject process updated, on rejection workflow support added.
9. SAML Single Logout
10. The new screen will show loading on UI till tenant creation is completed once OTP is verified
11. Interchanged position of login ID and email on add/edit user for better UX.
12. Add support for the page number field for pagination in Amaya
13. 360 Recon
14. Lotus Notes Connector
15. Application Policy Map (Active Directory) samAccountName is compulsory for Create only flag in User as well as Group (AD application new bundle - When SAMaccount name is set to false in Group policy map, members are not assigned in group when recon Pull is executed for both exist=Update).
16. Added Warning information and warning popups (Only UI changes no impact on backend functionality):\
    a. Creation of user manually. \
    b. Updating of user manually. \
    c. Bulk upload CSV (creation of user) \
    d. Manager assignment \
    e. Policy map creation and updation \
    f. Reconciliation Pull operation \
    g. Reconciliation push operation \
    h. Selfservice ➝ Teams: \
    i. Creation of user \
    ii. Updation of user
17. Removal of Email validation from the backend

#### Fixes

1. The user info page crashed while the user edit fails
2. Import/Export of App Configuration
3. Amaya- Detailed description of failed/executed logs should be shown
4. AD application new bundle- The group link attribute in the db is empty, and users are not getting updated in the group
5. AD policy map- Spaces should be trimmed automatically if included while creating a policy attribute
6. Tenant creation not working
7. New tenant Registration- Showing subscription end for tenant which is not even registered completely
8. Secret question configuration- Admin user should be able to delete secret questions when not in use
9. Secret Question- When a question is already in use and the user trying to delete a question then it should not display a successful delete message.
10. Secret question- Displaying removal validation message when editing a question
11. User> Activity- Add a cross (x) button to clear the selection
12. Onbehalf Config - If the Description is kept blank, no error message is getting displayed on the screen while saving.
13. Team Config - If the Description is kept blank, no error message is getting displayed on the screen while saving.
14. On Behalf config- When the view button is clicked, the user is still able to check or uncheck the boxes.
15. Custom attribute- Even when a custom attribute is disabled from the configuration, it remains visible in the policy map selected dropdown menu
16. Users - View User- Custom attribute fields text UI is breaking
17. Custom Attribute- Require text change in success message to " Custom Attribute activated successfully"
18. Edit User - After deactivating the already assigned custom attribute, in edit user, the system is showing info XYZz" attribute is inactive for the active custom attribute also.
19. Identity Hub- When clicking on edit info from the user menu action, the user account edit page should open instead of the user display page.
20. CTRL+K: When any feature/module is already opened and the user presses the ctrl +k button from the keyboard then the search filter modal is opened at the back
21. Delegation - Delegator and Delegatee consent should not get updated if the user has already set some other consent.
22. Users> Group- Rename the label from 'Delete' to 'Unassign'.
23. Audit- Logs for deprovisioned users are getting repeated.
24. Custom Field- Policy Map- Date is not showing in the correct format
25. Mobile app- When clicking on the user name for the first time after killing the app, the keyboard is hidden
26. Custom Attribute-Provision- When a custom attribute with special characters is created and applied in a provision rule (for user creation), the provision rule fails to trigger after the user is created.
27. Global search (Ctrl+K) - even if characters are not matching still shows suggestions
28. User setting- An error message should be shown when any action is performed and when landing/refreshing the settings page
29. Cymmetri Selfservice App - Need to change the message showing in the popup screen while TOTP is getting authenticated.
30. Mozilla Browser specific- User getting stuck when password-less Webauthn is On
31. Application - SSO - While clicking on Preview assertion, getting the error "processing please wait"
32. Product menu getting hidden on workflow page: a. Menu action- Displaying an error message when a user already has one role assigned and tries to assign a menu action.
33. The user info page crashed while the user edit fails
34. Import/Export- Showing error message when importing the file into a new tenant (AD specific)
35. Custom Attribute-Provision- When a custom attribute with special characters is created and applied in a provision rule (for user creation), the provision rule fails to trigger after the user is created.
36. Quick setup- Data is not getting reset after closing the policy mapping popup box, but getting reset when clicking on the "I'll do later button"
37. Add Page Number support for Amaya.
38. Application - SSO While saving the same config in two applications, while clicking on Edit SP config, a popup showing do you want to continue editing the SP configuration? but only the continue button is given
39. Application - SSO - While saving the configuration in a new application, the save button loader is loading continuously
40. 360 recon-Hide runnow button from detail view
41. 360 recon dashboard filter-add dropdown for break type
42. 360 recon dashboard-label change account overdue to account overdue in the target (also add some info on i icon what is this)
43. 360 recon-Already running recon need to handle, disable the play button, or show a message
44. 360 dashboard-make label consistent
45. 360 recon dashboard-action details showing blank
46. 360 Degree recon-For execution showing error
47. 360 Degree Recon- History some time loading some time not
48. Recon 360 recon- A validation message for missing data is not required as it already shows no data found on the page when recon is not executed at all
49. 360 recon dashboard-action details showing blank
50. 360 dashboard-Search not working on break type
51. 360dashboard-loginid filter not working
52. 360 recon detail data showing mismatch
53. 360 recon execute audit log not present
54. 360 recon dashboard-on 2nd run details getting repeated
55. Amaya Azure- Showing route issue error message
56. Import Application- UI for the name is not proper
57. Import/Export- Recon is not working for AD's new application bundle
58. Teams config - while removing the condition in Group condition, shows the error " Please try again"
59. On Behalf config - while removing the condition in Group condition, shows the error " Please try again"
60. Teams Config - If the condition is kept blank and save is clicked, getting the error " Please try again"
61. On behalf config- If the condition is kept blank and save is clicked, getting the error " Please try again"
62. Import/Export Application- Convertor field types in the policy map are not getting imported
63. Import/Export - When any application configuration is imported into a new tenant, the user should be redirected to the application provisioning page after the upload
64. Import application- Showing an error message when importing an Amaya-based application if the exported application was without the policy map checked
65. Amaya- Policy Map Password attribute datatype identified as password instead of string
66. Amaya- Rename all operations(Test, Search, Sync, etc....) in sentence case
67. Workflow- Even after updating Grade as the 2nd level approver in the workflow, the 1st level approver is still being set at level 2
68. Workflow- After updating the user list as the 2nd level approver in the workflow, the 1st level approver is still being set at level 2
69. Workflow- When the level 3 approver is updated in the workflow, a 'Workflow Not in Range' error message is displayed.
70. Workflow- Even after updating the reporting manager as the 2nd level approver in the workflow, the 1st level approver is still being set at level 2
71. Workflow- When workflow over workflow is applied 2nd level approver is not getting updated
72. 360 recon should consider full sync
73. 360 recon fails then that 360 recon should be abort
74. Amaya Felicity Role assignment- Taking time to provide an error message
75. Deprovision- Exclusion Application- Application going in pending deletion state when that particular application is added in exclusion application while manually deleting a user from the Identity hub
76. 360 Recon sync with bulk data showing heap size issue
77. AD new application- User list is not getting displayed showing urersrvc unknown error.
78. My workspace> Inbox- When workflow assignment is reassigned by admin, then the previous approver should not be able to accept or reject the request if the page is already open in the previous approver account.
79. Inbox - Workflow Request for setup for application - Need to enhance the details as per user interface.
80. Error in the server log-authsrvc , No impact on the functional flow
81. After the campaign workflow triggered on revoked, even though the campaign had ended and the workflow was approved, applications were still getting unassigned.
82. Campaign - Reviewer can approve self review request
83. The campaign not getting end, for tenant 2711
84. Workflow TAT- Workflow is getting aborted when grade is set at second level approver and set TAT time is over
85. Workflow TAT- Workflow is getting aborted when 2 level approver is set and set TAT time is over
86. Workflow TAT- Workflow is getting aborted when workflow approver is assigned to the user list
87. Workflow TAT- Showing error when the user is not present and TAT is over
88. Workflow TAT- Showing unauthorized error when TAT is over and operation is getting aborted
89. Recon pull- with both existing links, audit detail not showing
90. Workflow rule configuration-on edit workflow, previously selected role getting save
91. AD new bundle- Managed View- View should be proper while separating multiple OU in proxy addresses
92. AD new bundle- Manager and account expiry is not visible in the Managed view
93. AD new bundle- managed view- Value is not displayed in a proper format in **Name** in managed view
94. AD new bundle- Managed View- Showing different Start time/created time
95. In the User creation workflow, L1 - User List approved, L2 - reporting manager after TAT is expired, the request is not getting auto reject.
96. Pending Workflow List - If the approver is User list and Grade then it should display in Current Assign in the pending list
97. User Workflow - If the reporting manager is set as 2 level approver, the reporting manager is showing as Unknown
98. Policy Map- When the attribute is searched via the search button and that attribute is deleted then other attributes are not loaded
99. Profile Picture- After clicking once on the upload button, that button should be disabled
100. PAM-Server access not getting terminated even after time ends (Related to HA environment only)
101. User - Assign Application - Workflow initiated - Workflow Approvals page displays User list in Grade type
102. Pending Workflow -If the L1 approver is User List, then while clicking on the info icon, the popup does not show the user list. Also, it is " Grade List Details"
103. PAM-Server access not getting terminated even after time ends (Related to HA environment only)
104. Workflow Rule - Workflow is initiated when the group is set as an approver, the group is not visible on the popup screen
105. AD new bundle>Group- When the "Sam account name" update checkbox is unchecked and the user attempts to update the description, the description does not get updated in the AD
106. deployment\_analytics\_1 Service CPU utilization is 100%
107. Import/ Export- When a file is exported from a different env (Dev) and imported to QA env, then credentials are also imported along
108. Security Bug Fixes:- E2E request/response payload encryption for all APIs of authservice (as of now, planning to rollout for all the services in the next phase)

#### Known Bugs

1. Manager notification: receiving user name required manager name
2. Unable to identify application properties data type where value is empty
3. Amaya || Create user operation fails due to an invalid password
4. In forgot password/password breach condition-asking disabled MFA factor also
5. Amaya-Autofill policy map, When the value is not present to the user at the time of application then Amaya passes "$." to the target
6. Campaign - Reviewer can approve self review request
7. After the campaign workflow was triggered on revoked, even though the campaign had ended and the workflow was approved, applications were still getting unassigned.
8. Remote Group- AD Application- When users are removed from a remote group in Cymmetri, those members should also be removed from the group in the Active Directory
9. Amaya- Client ID should be visible in encrypted form
10. Provision Rule - While creating and configuring the custom attribute as "New ", the system is not initiating the rule.
11. AD new bundle- When an AD application is assigned to a remote group, the application is highlighted in the background while assigning but disappears as soon as the application popup box is closed
12. Reports- When the report is scheduled, Scheduler history shows content not found and the execution status is aborted.
13. AD Application- When the Ad test provision fails, and the user tries to delete the application from a user account, then the application should gointon a fail deletion state
14. Audit- Taking time to load audit logs
15. AD Application- Showing error when inserting start date in AD
16. In the application setting to user flags off then the also application shows in the recent application.
17. User lock- When a user account is active, and the same account is logged in through another browser, and by any means, the account gets locked, the first session should get terminated.
18. Branding- When show Unlock link from branding is kept as No, and the admin user account gets locked, then the user is not able to unlock the account from the login page
19. Application- When a user is adding /removing a role then it is not getting reflected without refreshing
20. group push-not taking user in AD at the time of update
21. Passwordless- WebAuthn; Showing not allowed error
22. Delegation-On behalf: when login by the delegate and the on-behalf condition is not satisfied still shows the on-behalf toggle button and gets removed when refreshed
23. AD Application- Group name should not accept space while creating or updating group name
24. Audit- Audi log should show log when the user is not getting any records in Recon history but showing task executed


# 3.1.7

**Version: cloud\_3.1.7 product release**

**Date:** 30 September 2024

#### New Features

1. CISO Dashboard service deployment remains the same as the last release since the sprint release for the same is mid-next week. (EoM - September 2024)
2. Reconciliation Enhancement a. Reconciliation Job Notifications b. Reconciliation Job Dashboard c. Handling of Partial Job Failures d. Reconciliation Filters
3. Email Configuration Update \
   a) Mail Username and Password fields no longer require validation, allowing them to be empty. This is because some email servers do not require authentication.\
   b) Other fields, such as Mail Port, Mail Host, and Mail Sender, still require validation to ensure proper email functionality

#### Fixes

1. Form logic-When TAT is executed then in the detail show the message "Form Logic Workflow Rejected by system"
2. Assign Application- The application page not getting refreshed automatically after deleting/assigning applications.
3. Amaya Policy Mapping- The search button should be present.
4. Amaya || Validation prevents the usage of variables in the URL
5. FormLogic || Step 2 of form || Form config JSON should be mandatory
6. Amaya- The present header key disappeared when saving the value
7. Quick setup policy mapping- When any fields are not filled and an error is shown, the user should be taken to the error field
8. Amaya>Policy Mapping- Showing repeated validation message on UI when clicking on the reset button
9. Amaya- When the JSON body type is changed from raw to any other format, the previous type is cleared, but the response is not being updated accordingly
10. Amaya- After 3-4 attempts of clicking the validate/save button, the validation message is no longer being displayed.
11. Form logic-form detail-Need to provide rule link.
12. Staging Users - Version History - Change the text "Update Version" to "Updated Version"
13. Form logic-When TAT is executed then in the detail show the message "Form Logic Workflow Rejected by system"
14. Onboarding- The page is being skipped when the "Create User" popup box is clicked outside of it.
15. Audit log- UI layout is getting distorted for long role name
16. Application role- The Role page layout is getting distorted when a role with a long name is created
17. Application Role- When a role with a long name, including spaces, is created, the UI (specifically the Cancel and Save buttons) is affected while unassigning the role from a user account.
18. Application Role- UI is getting impacted.
19. Selfservice mobile app-inbox-User detail not showing.
20. CSV Bulk Import- When a bulk file is imported via CSV, attribute fields take time to load
21. Amaya Policy Mapping- The search button should be present.
22. Workflow || Additional Form Info || Readonly text-based form submissions
23. Policy map- Empty values are getting saved in the policy mapping
24. Amaya- When the JSON body type is changed from raw to any other format, the previous type is cleared, but the response is not being updated accordingly
25. UI new user walkthrough- Sentence correction needed
26. UI new user walkthrough- Description should be changed
27. Quick setup policy mapping- When any fields are not filled and an error is shown, the user should be taken to the error field
28. Amaya- After 3-4 attempts of clicking the validate/save button, the validation message is no longer being displayed.
29. Form logic-Form table-sorting not working
30. Form logic-Pre and post hook should be nonmandatory
31. Form logic-User submissions-Provide date filter
32. Form logic-on all screen search only works for the exact case, expected should work for matching cases.
33. Partner portal-add user-country list not loading.
34. CSV Bulk Import- When a bulk file is imported via CSV, attribute fields are taking time to load.
35. Form details UI is different in Pending and Completed Workflow than showing in the selfservice inbox section.
36. Form logic-Selfservice app-My Requests-form detail not showing
37. Skip Password Expiry- Session expires when the refresh button is clicked having skip password expiry enabled
38. FormLogic || Unable to save rule after changing condition

#### Known Bugs

1. Manager notification: receiving user name required manager name
2. In the application setting if to user flag is off then the also application shows in the recent application.
3. Unable to identify application properties data type where value is empty
4. Amaya || Create user operation fails due to an invalid password
5. Reports- Records are displayed after 11min approximately
6. Deprovision Rule executed via Scheduler - Workflow is not getting initiated for the set of users based on status/end date
7. Workflow List - Getting error " Contact system administrator" on technova tenant
8. FormLogic || Step 2 of form || Form config JSON should be mandatory
9. Recon - Abort sync state - System is getting auto abort and failure log showing nothing and
10. Recon Dashboard History> Search field- A Placeholder should be added specifying search is applicable for only the application name, also No data found should be shown and pagination should get clear when the page is empty
11. Recon Failure sync status - Showing "Reconciliation In Progress" in fail status
12. Application Recon History- Slider should be added at the bottom
13. Recon Dashboard history- Users/groups are getting created in Cymmetri even when the process is aborted from the dashboard


# 3.1.15

**Version: cloud\_3.1.15 product release**

**Date:** 09 February 2025

## New Features

**1. User Management**

* **User Threshold**
  * General configuration for the threshold updated.
  * UI changes for:
    * Creation, updation, and deletion of users.
    * Retry staging users from the staging dashboard.
    * Archive for user threshold
    * Updated Email Title and Template.
  * Notifications for user threshold:
    * Notification field made mandatory.
    * Org Admin set as default notifier (not supported for old tenants).
    * Notification Field in User Threshold Config for delete users
  * Staging dashboard:
    * Updates to the staging dashboard view and error messages.
    * Display names shown during threshold delete operations.
  * Manual “Move to Archive” button added for staging users.
  * Failure handling for moving staging users to archive, including audit log display.
* **User Directory Search**
  * Quick search updated to support:
    * Employee ID, email, mobile, first name, last name, middle name, display name, login.
  * Dropped support for: grade, userType, department, designation, custom attributes.
* **Email Validation**
  * Removal of Email validation from backend

**2. Workflow**

* **Custom Attributes in Workflow Rule Events**
  * Supported events:
    * User Creation
    * Application Provisioning, Deprovisioning, and Update
* **Pending Workflow Enhancements**
  * Reassign user functionality added to the inner page.
  * Requester and requestedFor columns added.
* **UI/ UX Changes**
  * The inbox title within the workflow setup event now displays the workflow name.
  * The Pending Workflow List now includes 'Requester' and 'Requested For' columns for display.
  * User details section in Inbox Requests will now include assigned application details
  * Workflow Inbox will now include start date and end date filters.
* **User Delete Workflow**
  * Workflow and rule configuration support added.
* **Workflow assignee escalation:**
  * If the workflow-task assignee is the same as target-user/requester then assign task to assignee's reporting-manager. Application level configuration support provided, default is disabled.
* **Default Workflow Rule**
  * A workflow rule that is configured without any conditions, It triggers when no other rule matches. Supported events include:
    * User Creation, Application Provisioning, Application Deprovisioning, Workflow Setup, Application Role, Decommission Device, Application Update, Access Review Reject, User Delete, Form Logic Workflow, Exception Application, Movers

**3. UI/UX Enhancements**

* Warning added || Application Config Import Modal || Auto 'Create Only' for User Principal policy mappings
* Amaya || Add support for JSON body validation through validate button
* Inconsistent button placement across certain modules has been rectified by aligning them to a standardized position below.
* Onboarding Walkthrough for new users.
* Audit log comparison for oldObject and newObject when they are in detailed format
* QR code zoom feature added to FIDO, TOTP, and push authenticator scanners.
* Improved runtime error handling with a sitewide error page.
* Enhanced build performance by 46%.

**4. Identity Governance**

* **RecommendationEngine**
  * Enables seamless integration and management of application and role recommendations.
  * Supports generation of personalized application and role suggestions.
  * Supports the automatic synchronisation of data from various sources, ensuring that recommendations are always based on the user behaviour.
  * All recommendation engine configurations, data synchronisation are stored and can be easily retrieved and updated as needed.
  * Campaign and workflow integration for approvals and recommendations.
  * Scheduler history provided with container status.
  * **Campaign**: Recommendation details shown on assignment approver action in campaign for campaign assign.
  * **Inbox:** Recommendation on application assignment workflow request in inbox for approver.
* **Role Based Forms**
  * Per role form request was introduced which enabled to invoke a new form for every new role requested by the end user
* **Improved Campaign Visibility & Control**
  * Includes notifications for Managers, internal users, and external emails, along with downloadable campaign reports.
* The ability to extend running campaigns provided and Initial planned end dates visible in tooltip after the campaign gets extended
* Save as Draft feature is provided in approvers view, where approver can select and approve multiple requests as draft and then save all of them as one.
* **Recommendation Scheduler History:** Provides information on whether the recommendation engine is configured, along with the scheduler history, including its status (running or completed) and the number of records processed.
* **Recommendation Engine Scheduler:** It tells you about the running container for the particular tenant on the version page
* Highlighted the SOD Rule (name) being violated during the recommendation to the user

**5. Mover Process**

* Gradual rollout across phases:
  * Phase 1: UI configuration without backend integration.
  * Phase 2:
    * UI performance optimisation, made new UI designs and implementation to boost the performance by reducing API call compare to earlier UI proposed
    * Default scheduler (No execution)
    * Added calculation for applicationToSkip, applicationToRemove and applicationToAdd (backend only).
    * Refactor existing Cymmetri user update API (backend) .
      * Manual Update
      * Reconciliation -Both exist update
      * Teams -User update
      * Delegation -> Teams -> User Update
      * Manager assign Import
      * Manager Link Import
      * Manager gets a link while the user imports using csv.
      * Also manager assignment from UI
    * Refactor existing deprovision and provision rule execution
    * If mover configuration is active then only calculations will perform for application to remove.
  * Phase 3: Dashboard for deprovisioned apps
  * Phase 4: Deprovision Scheduler, Workflow, Dashboard Enhancements, and Notifications.

**6. Application Management**

* **Reconciliation**
  * 360 Degree Reconciliation:
    * Compare tab for comparing source and target applications.
    * Generate and download csv reports.
  * Reconciliation Dashboard Enhancements:
    * Reconciliation Filters,
    * Partial job failure handling, and
    * Reconciliation job notification configs.
    * Removed global-level and added application-level recon notification configuration.
    * Added a new recon failure notification template.
  * Reconciliation Activity Log - Show previous and next 10 minutes activity log for each reconciled entity (user/group)
  * 360 degree recon support for Simple LDAP Application
* **Exceptional Applications**
  * Configuration Side
    * Schema, Masters, and Template with application mapping
    * Quick Setup
  * Self-service Side
    * List Exception Applications
    * Request Exception Application functionality
  * Workflow integration and dashboard for exception requests.
  * Exception workflow configuration and invocation of the workflow for exception application access requests.
* **Bulk Application Un-assignment**
  * Bulk Application Un-assignment allows administrators to remove access to applications and roles from multiple users simultaneously using a CSV file.
* **On Demand Access**
  * On Demand Access Request offers the capability to define on-demand roles, allowing administrators to enable access dynamically.
* **Global Apps**
  * Global Apps allows the user to configure applications that are applicable to all the users which are not available via On Demand or Exceptional Applications Configuration
* Role description is provided under the role name whenever an application is requested.
* **Role Management**
  * Parent and child role support added in CSV imports and manual role creation.
* Application ➝ Assignments ➝ User assign ➝ Failure/Pending assignment user list Integration

#### **7. Data Logger** <a href="#wwk0nfqrmvr" id="wwk0nfqrmvr"></a>

* Data logger service version information added.
* Optimized the data-logging framework for better performance.
* Full sync support adde&#x64;*(this step is an optional step and required only if any of the below conditions match)*,
  * Tenant audit database is not present, or
  * Tenant audit database is corrupt so fresh setup is required.

#### **8. Tenant Registration** <a href="#sdc2t0fhwvf4" id="sdc2t0fhwvf4"></a>

* Optimized the tenant registration database creation process.
* **Tenant Registration Process Resumption:** If the tenant registration process is interrupted, it can be seamlessly resumed and completed using the existing account configuration. The registration process can be resumed from the following stages:
  * Pending OTP Verification
  * Incomplete Credential Setup

#### **9. SSO (Single Sign-On) and TOTP Config** <a href="#gfxqxcw6ip1i" id="gfxqxcw6ip1i"></a>

* **External IDP SSO:** Added support to log in to Cymmetri as an external identity provider for IDP-initiated SSO.
* **SAML IDP SSO:** Added support to send IDP-initiated (Cymmetri) SSO response to Cymmetri as a service provider.

#### **10. MFA (Multi-Factor Authentication)** <a href="#id-8rg3u0kacyl2" id="id-8rg3u0kacyl2"></a>

* **TOTP Config:**
  * Look-ahead window: Added support for 0 as an option inside the dropdown.
* **SDK Integration:**
  * Implementing SDK integration for mobile push notifications to resolve issues with the existing legacy API of:
    * Fido Based Notifications and
    * Normal Push Based Notifications

#### **11. Form Logic** <a href="#snut7vxnpw70" id="snut7vxnpw70"></a>

* The Form Logic functionality enables you to store custom data using flexible, administrator-defined forms.
* It empowers you to create forms tailored to your specific data collection requirements, providing a versatile solution for various data management need&#x73;**.**
* Form Logic webhook sample request schema and sample script updated for user details.

#### **12. SkipPasswordExpiry** <a href="#csdo5w7u07uc" id="csdo5w7u07uc"></a>

* Skip Password Expiry has been added to the PasswordChangeRule.
* This option allows administrators to exempt specific users or groups from the regular password expiration process.
* When enabled for a user, they will not receive any warnings or notifications regarding password expiry, and they will not be required to change their passwords due to expiration.

#### **13. Connector** <a href="#oalb2ud302ne" id="oalb2ud302ne"></a>

#### **Active Directory and SimpleAD Connector** <a href="#id-1vhl0hz0ma2z" id="id-1vhl0hz0ma2z"></a>

* Active Directory || SimpleAD Connector upgrade
  * UserAccountControl attribute support added
  * memberOf attribute support in manage system viewer
  * ProxyAttribute attribute support added
* **Amaya**
  * Added the following templates for quick setup:
    * Atlassian
    * Zoho CRM
    * Zoho Desk
    * Zoho Books
    * Zoho Expenses
  * General Config based role data type
  * Provided support for integer values for ROLE assignment through Amaya.
* **LDAP Connector**
  * A new connector named 'SimpleLDAP' has been added for connecting to LDAP Applications.
  * The LDAP adapter has been updated with a new feature that eliminates the need to enter a username and password for each execution.
* **ScriptOn(Database) Connector**
  * Manual Link operation support added

#### **14. Configuration** <a href="#idwtgtmc8rjx" id="idwtgtmc8rjx"></a>

* **Email Configuration Update**
  * Mail Username and Password fields no longer require validation, allowing them to be empty. This is because some email servers do not require authentication.
  * Other fields, such as Mail Port, Mail Host, and Mail Sender, still require validation to ensure proper email functionality

#### **15. Insights** <a href="#ap8m25a48glf" id="ap8m25a48glf"></a>

#### **Identity Analytics** <a href="#o3c2374bkws9" id="o3c2374bkws9"></a>

* **Reports Email Scheduling**
  * Configuration support added for fetching a report of current business day.

**Advanced Analytics**

* Authentication Data model created
* Support for downloading reports in CSV or PDF.
* **Generate Report**
  * New Generate Report button when viewing reports in Insights > Reports > View icon

#### **16. Logs** <a href="#mq0owkr4vl9z" id="mq0owkr4vl9z"></a>

* **External Logs**
  * This feature provides a centralised way to capture and view logs from external applications interacting with Cymmetri via webhooks or batch tasks.
  * This enables administrators to debug external interactions directly within Cymmetri, simplifying the monitoring and troubleshooting process

#### **17. Backend Enhancements** <a href="#be4qz5fpao1b" id="be4qz5fpao1b"></a>

* #### **End-to-End Encryption** <a href="#v83z13f6xymm" id="v83z13f6xymm"></a>
  * End-to-end encryption has been added for all authservice APIs (/authsrvc/\*). This includes encryption of request and response payloads.
  * End-to-end encryption (E2EE) support added in provisionengine
* Redis Cache support provided for the My Workspace section to improve performance.
* **APIEXT:**
  * Exposed a new API for implementation team to get user details based on email, login and/or displayName

## Known Bugs

1. manager notification: receiving user name required manager name &#x20;
2. In application setting if show to user flag off then also application show in recent application &#x20;
3. Amaya || Unable to identify application properties data type where value is empty &#x20;
4. Amaya || Create user operation falls due to invalid password&#x20;
5. Reports-Records are getting displayed after 11min approximately &#x20;
6. recommendation run for tenant 2711 taken 2 days, 3 hours, 8 minutes, and 12 seconds for 345,000 users
7. During reconciliation, when the user login ID is left blank and the loginGenerator is activated, the process fails due to the empty login


# 3.1.x Consolidated

(3.1.0 - 3.1.6)

<table data-full-width="true"><thead><tr><th>VERSION</th><th>New Features</th><th>Fixes</th><th>Known Bug</th></tr></thead><tbody><tr><td>3.1.0 Beta <br>(02 May 2024)</td><td><p></p><ol><li>Add a Welcome Guide when no nodes are added</li><li>Amaya Operations cards messages updated</li><li>Tooltip DX enhancements</li><li>Add confirmation dialogue when the request method is missing</li><li>File Upload Validations based on filename length and file size: File validation applied on User Bulk Imports, Group Assignments, Application Assignments, Role Imports, and Upload metadata SSO. Branding Image upload applied image size validation and image name length validation. Validation is also applied on self-service User avatar upload and application icon upload.</li><li>Cymmetri Verify App issuer format is changed now so there wont be duplicate record creation from now onwards, earlier we did not take into account of the environment but now we are considering that as well</li></ol></td><td><p></p><ol><li>Deprovision Via scheduler when threshold value is set:- Past date user is also getting deprovisioned when rule is applied on status ﻿</li><li>Application-Role-One role mandatory, validation should be present at least one active ﻿</li><li>Node name without spaces overlap</li><li>﻿﻿Amaya- Not able to drag down node which is at the top most corner ﻿</li><li>Campaign - Campaign action reminder email time calculation wrong﻿</li><li>Campaign- Campaign is getting aborted and summary is showing blank when campaign for local group is executed. ﻿</li><li>Custom attribute - When custom attribute filter is applied in users, showing no users found ﻿ </li><li>Workflow- Preference config box is not visible while deprovisioning application ﻿</li><li>Self service app: While setting up secret question authentication in mobile app, user need to click twice on question field. ﻿</li><li>User activity Ascending Descending not working ﻿</li><li> ﻿Amaya Connector Recon- Showing duplicate role remarks, but in duplicate field showing 0 records</li><li>Identity Hub- Groups- After editing groups when on application / activity page user is redirected to users page by default</li><li> My workspace> Create new tags- showing older suggestion as soon as clicked on new tag field ﻿</li><li>AD Application - View attribute is empty</li><li>Tenant registration | Pressing tab key glitches UI </li><li>Missing error code mapping </li><li>Grade Workflow- When workflow preference config is set to visible, and workflow is applied for user creation, then popup box is showing user list but in pending showing unknown instead of user list </li><li>Amaya- When the back button is clicked, a save/discard popup box will appear. However, clicking anywhere on the page directly navigates the user away from the operation page.</li><li>Amaya - Save/Discard popup box should not be shown when user is trying to go back without saving any changes. </li><li>Mobile app- Secret question- Field is showing required even when data is present in field</li><li>Cymmetri Verify app- Password recovery should be provided for Exported TOTP user files in case user forgets the password</li><li>﻿login via Authenticator-identity provider is inactive then also user able to login. </li><li>syslog-configuration- UDP test, for invalid IP also giving success. ﻿ ﻿Unable to have TOTP account for same username on different environments .</li></ol></td><td><p></p><ol><li>Manager notification: receiving user name required manager name</li><li>Workflow initiated for form but form is getting updated without workflow approval.</li><li>In application setting if show to user flag off then also application show in recent application.</li><li>Unable to identify application properties data type where value is em</li></ol></td></tr></tbody></table>

<table data-full-width="true"><thead><tr><th>VERSION</th><th>New Features</th><th>Fixes</th><th>Known Bugs</th></tr></thead><tbody><tr><td>3.1.2 Beta <br>(26 July 2024)</td><td><p></p><ol><li>Workflow self-approval module updated to support custom attribute (type :user type and Converter Type: String ) as condition parameter.</li><li>Teams config module updated to support custom attribute (type :user type and Converter Type: String ) as condition parameter.</li><li>On behalf module updated to support custom attribute (type :user type and Converter Type: String ) as condition parameter.</li><li>Auth Rule module updated to support custom attribute (type :user type and Converter Type: String ) as condition parameter.</li><li>Quick Setup - Setup applications using pre-defined operations</li><li>Import-Export App Configuration - Transfer configurations of application smoothly between tenants, simplifying the setup for users by ensuring all configuration, including user configurations, server configurations, and policy maps, are accurately migrated.</li><li>Removal of Deprovision Rule Exclusion Applications Field: a) Manual Execute Deprovisioning b) Deprovisioning via Scheduler c) Update Threshold Delete Config d) Deprovision Rule Updation e) Backward Compatibility f) Suspend or Resume User g) Impact on UI</li><li>Access review reject process updated, on rejection workflow support added.</li><li>SAML Single Logout</li><li>New screen that will show loading on UI till tenant creation is completed once OTP is verified</li><li>Interchanged position of login id and email on add/edit user for better UX.</li><li>Add support for page number field for pagination in Amaya</li><li>360 Recon</li><li>Lotus Notes Connector</li><li>Application Policy Map (Active Directory) samAccountName is compulsary for Create only flag in User as well as Group (AD application new bundle - When SAMaccount name is set to false in Group policy map, members are not assigned in group when recon Pull is executed for both exist=Update).</li><li>Added Warning information and warning popups (Only UI changes no impact on backend functionality): a. Creation of user manually. b. Updation of user manually. c. Bulk upload csv (creation of user) d. Manager assignment e. Policy map creation and updation f. Reconciliation Pull operation g. Reconciliation push operation h. Selfservice ➝ Teams: i. Creation of user ii. Updation of user</li><li>Removal of Email validation from backend</li></ol></td><td><p></p><ol><li>User info page gets crashed while user edit fails</li><li>Import/Export of App Configuration</li><li>Amaya- Detailed description of failed/executed logs should be shown</li><li>AD application new bundle- Group link attribute in db is empty, users are not getting updated in group</li><li>AD policy map- Spaces should be trimmed automatically if included while creating a policy attribute</li><li>Tenant creation not working</li><li>New tenant Registration- Showing subscription end for tenant which is not even registered completely</li><li>Secret question configuration- Admin user should be able to delete secret question when not in use</li><li>Secret Question-When a question is already in use and user trying to delete question then it should not display successful delete message</li><li>Secret question- Displaying removal validation message when editing a question</li><li>User> Activity- Add cross (x) button to clear the selection</li><li>Onbehalf Config - If Description is kept blank , no error message is getting displayed on screen while saving.</li><li>Team Config - If Description is kept blank , no error message is getting displayed on screen while saving.</li><li>On Behalf config- When the view button is clicked, the user is still able to check or uncheck the boxes</li><li>Custom attribute- Even when a custom attribute is disabled from the configuration, it remains visible in the policy map selected dropdown menu</li><li>Users - View User- Custom attribute fields text UI is breaking</li><li>Custom Attribute- Require text change in success message to " Custom Attribute activated successfully"</li><li>Edit User - After deactivating the already assigned custom attribute, in edit user , system is showing info "xyz" attribute is inactive for active custom attribute also.</li><li>Identity Hub- When clicked on edit info from user menu action, user account edit page should get open instead of user display page</li><li>CTRL+K: When any feature/module is already opened and user press ctrl +k button from keyboard then search filter modal is getting opened at back</li><li>Delegation - Delegator and Delegatee consent should not get updated if user has already set some other consent</li><li>Users> Group- Rename the label from 'Delete' to 'Unassign'.</li><li>Audit- Logs for deprovisioned user is getting repeated.</li><li>Custom Field- Policy Map- Date is not showing in correct format</li><li>Mobile app- When clicked on user name for first time after killing app , keyboard is getting hidden</li><li>Custom Attribute-Provision- When a custom attribute with special characters is created and applied in a provision rule (for user creation), the provision rule fails to trigger after the user is created.</li><li>Global search (Ctrl+K) - even if characters are not matching still showing suggestions</li><li>User setting- Error message should be shown when any action is performed and when landing/refreshing setting page</li><li>Cymmetri Selfservice App - Need to change the message showing in popup screen while TOTP is getting authenticated.</li><li>Mozilla Browser specific- User getting stuck when password less Webauthn is On</li><li>Application - SSO - While clicking on Preview assertion , getting error "processing please wait"</li><li>Product menu getting hide on workflow page: a. Menu action- Displaying an error message when a user already has one role assigned and tries to assign a menu action.</li><li>User info page gets crashed while user edit fails</li><li>Import/Export- Showing error message when importing file into new tenant (AD specific)</li><li>Custom Attribute-Provision- When a custom attribute with special characters is created and applied in a provision rule (for user creation), the provision rule fails to trigger after the user is created.</li><li>Quick setup- Data is not getting reset after closing policy mapping popup box, but getting reset when clicked on "I ll do later button"</li><li>Add Page Number support for Amaya</li><li>Application - SSO While saving the same config in two applications, while clicking on Edit SP config , popup showing do you want to continue editing the SP configuration? but only continue button is given</li><li>Application - SSO - While saving the configuration in new application, save button loader is loading continuously</li><li>360 recon-Hide runnow button from detail view</li><li>360 recon dashboard filter-add dropdown for break type</li><li>360 recon dashboard-label change account overdue to account overdue in the target (also add some info on i icon what is this)</li><li>360 recon-Already running recon need to handle,disable play button or show message</li><li>360 dashboard-make label consistent</li><li>360 recon dashboard-action details showing blank</li><li>360 Degree recon-For execution showing error</li><li>360 Degree Recon- History some time loading some time not</li><li>Recon 360 recon- Validation message for missing data is not required as it already shows no data found on page when recon is not executed at all</li><li>360 recon dashboard-action details showing blank</li><li>360 dashboard-Search not working on break type</li><li>360dashboard-loginid filter not working</li><li>360 recon detail data showing mismatch</li><li>360 recon execute audit log not present</li><li>360 recon dashboard-on 2nd run details getting repeated</li><li>Amaya Azure- Showing route issue error message</li><li>Import Application- UI for name is not proper</li><li>Import/Export- Recon is not working for AD new application bundle</li><li>Teams config - while removing the condition in Group condition, showing error " Please try again"</li><li>On Behalf config - while removing the condition in Group condition, showing error " Please try again"</li><li>Teams Config - If condition is kept blank and save is clicked , getting error " Please try again"</li><li>On behalf config- If condition is kept blank and save is clicked , getting error " Please try again"</li><li>Import/Export Application- Convertor field types in policy map is not getting imported</li><li>Import/Export - When any application configuration is imported into a new tenant, the user should be redirected to the application provisioning page after the upload</li><li>Import application- Showing an error message when importing an Amaya-based application if the exported application was without the policy map checked</li><li>Amaya- Policy Map Password attribute datatype identified as password instead of string</li><li>Amaya- Rename all operations(Test, Search, Sync, etc....) in sentence case</li><li>Workflow- Even after updating Grade as the 2nd level approver in the workflow, the 1st level approver is still being set at level 2</li><li>Workflow- After updating the user list as the 2nd level approver in the workflow, the 1st level approver is still being set at level 2</li><li>Workflow- When the level 3 approver is updated in the workflow, a 'Workflow Not in Range' error message is displayed.</li><li>Workflow- Even after updating the reporting manager as the 2nd level approver in the workflow, the 1st level approver is still being set at level 2</li><li>Workflow- When workflow over workflow is applied 2nd level approver is not getting updated</li><li>360 recon should consider full sync</li><li>360 recon fails then that 360 recon should be abort</li><li>Amaya Felicity Role assignment- Taking time to provide error message</li><li>Deprovision- Exclusion Application- Application going in pending deletion state when that particular application is added in exclusion application while manually deleting user from Identity hub</li><li>360 Recon sync with bulk data showing heap size issue</li><li>AD new application- User list is not getting displayed showing urersrvc unknown error.</li><li>My workspace> Inbox- When workflow assignment is reassigned by admin, then previous approver should not be able to accept or reject request if page is already open in previous approver account.</li><li>Inbox - Workflow Request for setup for application - Need to enhance the details as per user interface.</li><li>Error in the server log-authsrvc ,No impact on functional flow</li><li>After the campaign workflow triggered on revoked, even though the campaign had ended and the workflow was approved, applications were still getting unassigned.</li><li>Campaign - Reviewer can approve self review request</li><li>Campaign not getting end, for tenant 2711</li><li>Workflow TAT- Workflow is getting aborted when grade is set at second level approver and set TAT time is over</li><li>Workflow TAT- Workflow is getting aborted when 2 level approver is set and set TAT time is over</li><li>Workflow TAT- Workflow is getting aborted when workflow approver is assigned to user list</li><li>Workflow TAT- Showing error when user is not present and TAT is over</li><li>Workflow TAT- Showing unauthorized error when TAT is over and operation is getting aborted</li><li>Recon pull- with both exist link, audit detail not showing</li><li>Workflow rule configuration-on edit workflow ,previously selected role getting save</li><li>AD new bundle- Managed View- View should be proper while separating multiple OU in proxy addresses</li><li>AD new bundle- Manager and account expiry is not visible in Managed view</li><li>AD new bundle- managed view- Value is not displayed in proper format in <strong>Name</strong> in managed view</li><li>AD new bundle- Managed View- Showing different Start time/created time</li><li>In User creation workflow L1 - User List approved , L2 - reporting manager , after TAT is expired , request is not getting auto reject.</li><li>Pending Workflow List - If approver is User list and Grade then it should display in Current Assign in pending list</li><li>User Workflow - If reporting manager is set as 2 level approver , reporting manager is showing as Unknown</li><li>Policy Map- When attribute is searched via search button and that attribute is deleted then other attributes are not getting loaded</li><li>Profile Picture- After clicking once on the upload button, that button should be disabled</li><li>PAM-Server access not getting terminated even after time end (Related to HA environment only)</li><li>User - Assign Application - Workflow initiated - Workflow Approvals page displays User list in Grade type</li><li>Pending Workflow -If L1 approver is User List , then while clicking on the info icon, popup not showing user list .Also it is " Grade List Details"</li><li>PAM-Server access not getting terminated even after time end (Related to HA environment only)</li><li>Workflow Rule - Workflow is initiated when group is set as approver , group is not visible on popup screen</li><li>AD new bundle>Group- When the "Sam account name" update checkbox is unchecked and user attempt to update the description, the description does not get updated in AD</li><li>deployment_analytics_1 Service CPU utilisation is 100%</li><li>Import/ Export- When file is exported from different env (Dev) and imported to QA env, then credentials are also imported along</li><li>Security Bug Fixes :- E2E request/response payload encryption for all APIs of authservice</li></ol></td><td><p></p><ol><li>manager notification : receiving user name required manager name</li><li>Unable to identify application properties data type where value is empty</li><li>Amaya || Create user operation fails due to invalid password</li><li>In forgot password/password breach condition-asking disabled MFA factor also</li><li>Amaya-Autofill policy map, When value is not present to the user at the time of application then amaya passing "$." to the target</li><li>Campaign - Reviewer can approve self review request</li><li>After the campaign workflow triggered on revoked, even though the campaign had ended and the workflow was approved, applications were still getting unassigned.</li><li>Remote Group- AD Application- When users are removed from a remote group in Cymmetri, those members should also be removed from the group in Active Directory</li><li>Amaya- Client id should be visible in encrypted form</li><li>Provision Rule - While creating and configuring the custom attribute as "New ", system is not initiating the rule.</li><li>AD new bundle- When an AD application is assigned to a remote group, the application is highlighted in the background while assigning but disappears as soon as the application popup box is closed</li><li>Reports- When report is scheduled, Scheduler history is showing content not found and execution status is getting aborted</li><li>AD Application- When Ad test provision is failed, and user trying to delete application from user account, then application should go in fail deletion state</li><li>Audit- Taking time to load audit logs</li><li>AD Application- Showing error when inserting start date in AD</li><li>In application setting if show to user flag off then also application show in recent application.</li><li>User lock- When a user account is active, and the same account is logged in through another browser and by any means account gets locked, the first session should get terminated.</li><li>Branding- When show Unlock link from branding is kept as No, and admin user account gets locked, then user is not able to unlock account from login page</li><li>Application- When user is adding /removing role then it is not getting reflected without refreshing</li><li>group push-not taking user in AD at the time of update</li><li>Passwordless- WebAuthn; Showing not allowed error</li><li>Delegation-On behalf: when login by delegate and on-behalf condition is not satisfied still showing on-behalf toggle button and getting removed when refreshed</li><li>AD Application- Group name should not accept space while creating or updating group name</li><li>Audit- Audi log should show log when user is not getting any records in Recon history but showing task executed</li></ol></td></tr></tbody></table>

<table data-full-width="true"><thead><tr><th>VERSION</th><th>New Feature</th><th>Fixes</th><th>Known Bugs</th></tr></thead><tbody><tr><td>3.1.3 Beta <br>(26 July 2024)</td><td><p></p><ol><li>User Threshold: a. A UI change has been made in the general configuration for the threshold. b. Creation of user c. Updation of user d. Deletion of user e. Staging for user threshold f. Retry staging user from staging dashboard. g. Archive for user threshold h. Notification for user threshold</li><li>User directory search API updated for quick search (keyword): a. Support dropped for: grade, userType, department, designation, custom-attributes b. Supported on: employeeId, email, mobile, firstName, lastName, middleName, displayName, login</li><li>Data logger service version info added.</li><li>Tenant registration database creation process optimisation.</li><li>Pending Workflow Inner page applied functionality to reassign user from inner page</li><li>Added QR code zoom feature on FIDO, TOTP and push Authenticator scanner.</li><li>VPT: Modify routes of api - /usersrvc/api/user/directory/list/{appId} remove user role form routes.</li><li>Custom Attribute support in following Workflow Rule Events a. User Creation b. Application Provisioning c. Application Deprovisioning d. Application Update</li><li>Added the following templates in Amaya Quick Setup: • Atlassian • Zoho CRM • Zoho Desk • Zoho Books • Zoho Expenses</li><li>Provided support for integer values for <strong>ROLE</strong> assignment through Amaya.</li><li>Tenant Registration Process Resumption: In the event that the tenant registration process is interrupted, it can be seamlessly resumed and completed using the existing account configuration. The registration process can be resumed from the following stages: a. Pending OTP Verification b. Incomplete Credential Setup</li><li>Active Directory || SimpleAD Connector upgrade: a. UserAccountControl attribute support added b. memberOf attribute support in manage system viewer c. ProxyAttribute attribute support added</li><li>External IDP SSO: a. added support to login into cymmetri as external identity provider as idp initiated sso.</li><li>SAML IDP SSO: a. added support to send idp initiated (cymmetri) sso response to cymmetri as service provider.</li><li>TOTP Config</li><li>Removal of Email validation from backend</li><li>DataLogger | Refer configuration steps here: a. data-logging framework optimisation. b. Full sync support, this step is optional step and required only if, • Tenant audit database is not present, or • Tenant audit database is corrupt so fresh setup is required.</li></ol></td><td><p></p><ol><li>Error in the server log-authsrvc ,No impact on functional flow</li><li>Team config - Create - Discard button issue - After clicking not able to add the details in condition section</li><li>Rule engine- Remove "above" word from note</li><li>login with admin-Campaign detail show role also, currently role showing only for campaign manager</li><li>Amaya API returning null if error instead of error and errorCode</li><li>Hide metabase analytics</li><li>Workflow rule configuration-on edit workflow ,previously selected role getting save</li><li>User - Assign Application - Workflow initiated - Workflow Approvals page displays User list in Grade type</li><li>Pending Workflow -If L1 approver is User List , then while clicking on the info icon, popup not showing user list .Also it is " Grade List Details"</li><li>Identity Hub- Pending initial login symbol is visible far away from user name</li><li>On behalf configuration - While disable and enabling the toggle,popup message shows "This change will take effect on user's next login" but it is getting reflecting on the fly.</li><li>On-behalf>Delegation- On behalf menu is not visible when logged in via Delegatee account</li><li>SSO- Group mapping- Save button should be enabled when mandatory fields are filled</li><li>Workflow- Even after updating the reporting manager as the 2nd level approver in the workflow, the 1st level approver is still being set at level 2</li><li>Global search (Ctrl+K) - even if characters are not matching still showing suggestions</li><li>Product menu getting hide on workflow page</li><li>LDAP connector-LDAP SSL should be save in Boolean in the DB</li><li>User setting- Error message should be shown when any action is performed and when landing/refreshing setting page</li><li>User setting- External idp rule is active-An admin user should not be able to lock a user when the external IDP rule matches the user condition</li><li>Schedule history-ad by default todays filter for from and to</li><li>Teams config- When the view button is clicked, the user is still able to check or uncheck the boxes</li><li>Menu action- Displaying an error message when a user already has one role assigned and tries to assign a menu action.</li><li>Custom Attribute-Provision- When a custom attribute with special characters is created and applied in a provision rule (for user creation), the provision rule fails to trigger after the user is created.</li><li>Lifecycle Management - All menus - Discard button is not working as expected.</li><li>Application - SSO While saving the same config in two applications, while clicking on Edit SP config , popup showing do you want to continue editing the SP configuration? but only continue button is given</li><li>Application - SSO - While saving the configuration in new application, save button loader is loading continuously</li><li>Amaya- Rename all operations(Test, Search, Sync, etc....) in sentence case</li><li>Group Policy map- For group custom attribute Cymmetri field type should be automatically selected as working in users custom field</li><li>Teams config - while removing the condition in Group condition, showing error " Please try again"</li><li>On Behalf config - while removing the condition in Group condition, showing error " Please try again"</li><li>Teams Config - If condition is kept blank and save is clicked , getting error " Please try again"</li><li>On behalf config- If condition is kept blank and save is clicked , getting error " Please try again"</li><li>Import/Export- Showing error message when importing file into new tenant (AD specific)</li><li>Import application-show error message user or groupwise</li><li>Import application- Showing an error message when importing an Amaya-based application if the exported application was without the policy map checked</li><li>Import/Export - When any application configuration is imported into a new tenant, the user should be redirected to the application provisioning page after the upload</li><li>Amaya Azure- Showing route issue error message</li><li>Import/Export Application- Convertor field types in policy map is not getting imported</li><li>Import/Export- Recon is not working for AD new application bundle</li><li>Workflow- When workflow over workflow is applied 2nd level approver is not getting updated</li><li>Workflow- Even after updating Grade as the 2nd level approver in the workflow, the 1st level approver is still being set at level 2</li><li>Workflow- After updating the user list as the 2nd level approver in the workflow, the 1st level approver is still being set at level 2</li><li>Workflow- When the level 3 approver is updated in the workflow, a 'Workflow Not in Range' error message is displayed.</li><li>Workflow TAT- Workflow is getting aborted when workflow approver is assigned to user list</li><li>Team config - Create - Discard button issue - After clicking not able to add the details in condition section</li><li>Import/Export- By default, the time in the application name should be removed when exported</li><li>Rule engine- Remove "above" word from note</li><li>login with admin-Campaign detail show role also, currently role showing only for campaign manager</li><li>Hide metabase analytics</li><li>Error in the server log-authsrvc ,No impact on functional flow</li><li>AD new application- User list is not getting displayed showing urersrvc unknown error.</li><li>Campaign not getting end, for tenant 2711</li><li>Workflow rule configuration-on edit workflow ,previously selected role getting save</li><li>AD application new bundle - When SAMaccount name is set to false in Group policy map, members are not assigned in group when recon Pull is executed for both exist=Update</li><li>My workspace> Inbox- When workflow assignment is reassigned by admin, then previous approver should not be able to accept or reject request if page is already open in previous approver account.</li><li>After the campaign workflow triggered on revoked, even though the campaign had ended and the workflow was approved, applications were still getting unassigned.</li><li>Workflow TAT- Workflow is getting aborted when grade is set at second level approver and set TAT time is over</li><li>Workflow TAT- Workflow is getting aborted when 2 level approver is set and set TAT time is over</li><li>Workflow TAT- Showing error when user is not present and TAT is over</li><li>Workflow TAT- Showing unauthorized error when TAT is over and operation is getting aborted</li><li>User - Assign Application - Workflow initiated - Workflow Approvals page displays User list in Grade type</li><li>Reports- SSO based application- Reports are blank/ not showing data when SSO based application are accessed</li><li>Pending Workflow -If L1 approver is User List , then while clicking on the info icon, popup not showing user list .Also it is " Grade List Details"</li><li>AD new bundle>Group- When the "Sam account name" update checkbox is unchecked and user attempt to update the description, the description does not get updated in AD</li><li>Import/ Export- When file is exported from different env (Dev) and imported to QA env, then credentials are also imported along</li><li>Identity Hub- Pending initial login symbol is visible far away from user name</li><li>On behalf configuration - While disable and enabling the toggle,popup message shows "This change will take effect on user's next login" but it is getting reflecting on the fly.</li><li>In User creation workflow L1 - User List approved , L2 - reporting manager , after TAT is expired , request is not getting auto reject.</li><li>On-behalf>Delegation- On behalf menu is not visible when logged in via Delegatee account</li><li>Import Manager-Manager is deleted and user trying to assign then in the import history showing success but in audit showing failed</li><li>Application delete-Campaign-Deleted application available for review</li><li>AD new bundle- User policy map- When Sam account name is mapped with any attribute and update checkbox is kept false, and user is updated, audit log is showing failed</li><li>Workflow>Inbox- Address fields name in inbox /pending workflow and identity hub users are not same</li><li>SSO- Group mapping- Save button should be enabled when mandatory fields are filled</li><li>Campaign-email report showing error</li><li>deployment_analytics_1 Service CPU utilization is 100%</li><li>Application - Form - When submitted as blank, after assigning the application page is getting blank.</li><li>Reports- Records are getting displayed after 11min approximately</li><li>Csv Import users- An error message is not shown when the user is unable to save user details if a space is included in the email</li><li>After the campaign workflow triggered on revoked, even though the campaign had ended and the workflow was approved, applications were still getting unassigned.</li><li>User Workflow - If reporting manager is set as 2 level approver , reporting manager is showing as Unknown</li><li>Workflow>Inbox- Address fields name in inbox /pending workflow and identity hub users are not same</li><li>Export- Rename Config type to Select All</li><li>MFA- When default MFA rule is inactive, user is able to delete default rule as well</li><li>Amaya connector>Policy mapping- Bottom slider should be fixed</li><li>Amaya || Validation preventing usage of long valid header</li><li>Amaya Connector- By default only green colored (confirmed policy attributes) only should be checked</li><li>Amaya Quick Setup- When an auto test run fails and operations are manually updated, clicking 'Generate Policy Mapping' should exit the page.</li><li>Application delete-Campaign-Deleted application available for review</li><li>Import Manager-Manager is deleted and user trying to assign then in the import history showing success but in audit showing failed</li><li>Import/Export- By default, the time in the application name should be removed when exported</li><li>SSO - OpenID - Configure CIDR - Add - While clicking on Add icon without entering any details , blank data is getting added.</li><li>SSO - OpenID - Configure CIDR - While clicking on delete icon ,no message is getting displayed and entry is getting removed</li><li>Workflow List - View - Showing label as "Custom Workflow "</li><li>Import/ Export- Application name while importing file should be limited to 50character</li><li>Application - SSO - SLO toggle enable/disable audit log</li><li>SOD; policies-Policy owner name is not getting updated after updating user name from Identity hub and without owner name policy is getting saved</li><li>AD new bundle- When recon is executed for both exist update but application is not linked, still user is getting updated.</li><li>Application - Form - When submitted as blank, after assigning the application page is getting blank.</li><li>Masters - Grade- While clicking on Add button it is showing edit page of existing record</li><li>Tenant registration- Showing suspicious popup box when clicked on verify your email</li><li>New tenant registration- If tenant is already on registration page then after clicking verify email from mail box should show tenant is already registered</li><li>Tenant registration- Taking time to register tenant</li><li>Email verification - Email verify link is redirecting to otp verification screen.</li><li>My Workflow> Teams- Add short menu button</li><li>Tenant creation not working</li><li>After release v 3.1.2, for old updated tenant campaign module is disabled</li><li>Portal-For module update showing error, already exist</li><li>Push and FIDO scan zoom functionality not available at the time of Device MFA</li><li>Push and FIDO scan zoom functionality not available at the time of application MFA</li><li>User setting- External idp rule is active-An admin user should not be able to reset user password when the external IDP rule matches the user condition</li></ol></td><td><p></p><ol><li>manager notification : receiving user name required manager name</li><li>In application setting if show to user flag off then also application show in recent application.</li><li>Unable to identify application properties data type where value is empty</li><li>Amaya || Create user operation fails due to invalid password</li><li>User-Email with invalid email id like NA, this user not able to use MFA with OTP</li></ol></td></tr></tbody></table>

<table data-full-width="true"><thead><tr><th>VERSION</th><th>New Feature</th><th>Fixes</th><th>Known Bugs</th></tr></thead><tbody><tr><td>3.1.4 Beta <br>(13 August 2024)</td><td><p></p><ol><li>UI/UX || Warning added || Application Config Import Modal || Auto 'Create Only' for User Principal policy mappings</li><li>A new feature has been developed for the "Recommendation Engine", enabling seamless integration and management of application and role recommendations. The recommendation engine supports the generation of personalised application and role suggestions for each user. The system supports the automatic synchronisation of data from various sources, ensuring that recommendations are always based on the user behaviour. All recommendation engine configurations, data synchronisation are stored and can be easily retrieved and updated as needed.</li><li>UI/UX || Amaya || Add support for JSON body validation through validate button</li><li>Audit log comparison for oldObject and newObject when they are in detailed format</li><li>UI/UX Inconsistent buttons placement in some module fixed to a default below position</li><li>UI/UX Onboarding walkthrough of New users</li><li>ICICI: a. The inbox title in the workflow setup event has been updated to display the workflow name. b. Workflow (Pending workflow list) requester and requestedFor column added for display</li><li>Identity Analytics (Reporting Engine)</li><li>End to End Request/Response Payload Encryption for all authservice's API. (/authsrvc/*)</li><li>User Threshold (Phase 2): i. Update Email Title and Template ii. Create a new 'Move to Archive' button to manually archive a user. iii. Make the notifications field mandatory in the User Threshold Configuration. iv. Added the Org Admin as the default notifier in the user threshold configuration.(Not supported for old tenant). v. Update UI Error Message Format vi. The User Threshold staging mode name has been changed. vii. Failure to Move Staging User to Archive Manually and Audit Log Display for fail. viii. The changes made to the staging dashboard view. Include a comparison between the previous and updated versions of the UI. ix. Show the display name in the Threshold Delete operation on the Staging Dashboard. x. Notification Field in User Threshold Config for delete users.</li></ol></td><td><p></p><ol><li>Amaya- When server connector timeout is changed and test configuration is clicked, it is showing "connector not found in cloud" error in Audit log</li><li>Import User - If loginid already exist , then remark shows "Usrsrvc.existing Login" . Change this text to "Existing Login Id"</li><li>Import/Export- Showing host server details when file is imported for script connector</li><li>My Access - Tags - Roles is not getting displayed in Application</li><li>Application - Clicking on the role tile ,SSO is happening and also while clicking on close icon, SSO is happening</li><li>Applications- When any attribute is updated (made empty in the target application) and recon for both exist operation is executed, the corresponding attribute in Cymmetri should also be cleared</li><li>Reports- SSO based application- Reports are blank/ not showing data when SSO based application are accessed (To correct the data need to perform data-logger sync for respective tenant. Refer configuration steps here)</li><li>Deprovision- User is getting deprovisioned even after user status is changed to Active from Inactive</li><li>User threshold mail notification- Title changes required</li><li>Audit log-Recon - When recon is executed with status as Inactive, audit log is showing "Recon initiated successfully" but not any log for execution failed/aborted</li><li>Audit Filter- Add cross button in Target Type and Action field.</li><li>Threshold Config- Validation message for all three operations should be similar</li><li>Threshold Create/Update- Spelling for exceeded is not correct</li><li>Notification Template - Toggle and status should display in status column as per other modules.</li><li>Create User- While creating user on newly created tenant, assign group page showing text "No group assigned , assign group"</li><li>User setting- External idp rule is active-An admin user should not be able to reset user password when the external IDP rule matches the user condition</li><li>Create user - While creating user on newly created tenant, assign application page showing text "No data found, add application"</li><li>Audit Filter- Add cross button in Target Type and Action field.</li><li>Portal-For module update showing error, already exist</li><li>My Access - Tags - Roles is not getting displayed in Application</li><li>Threshold Config- Validation message for all three operations should be similar</li><li>Threshold Create/Update- Spelling for exceeded is not correct</li><li>Notification Template - Toggle and status should display in status column as per other modules.</li><li>Create User- While creating user on newly created tenant, assign group page showing text "No group assigned , assign group"</li><li>Create user - While creating user on newly created tenant, assign application page showing text "No data found, add application"</li><li>Group Unassignment: The message appearing on group unassignment is incorrect</li><li>Push and FIDO scan zoom functionality not available at the time of Device MFA</li><li>Push and FIDO scan zoom functionality not available at the time of application MFA</li><li>Campaign Reassign -inactive users are also listed for reassignment on click</li><li>Login page- AD auth- Provide proper UI message when AD adapter details are incorrect</li><li>Amaya- When server connector timeout is changed and test configuration is clicked, it is showing "connector not found in cloud" error in Audit log</li><li>Import User - If loginid already exist , then remark shows "Usrsrvc.existing Login" . Change this text to "Existing Login Id"</li><li>User threshold- Pending Staging- When changing page select all box should be unchecked.</li><li>Threshold Pending staging- Whenever the page changes or the number of records per page is modified, the selection should be reset</li><li>Import/Export- Showing host server details when file is imported for script connector</li><li>Threshold pending staging- When the retry button is clicked multiple times, the validation message does not appear after the third click on UI</li><li>Application assignment- Change user search suggestion watermark</li><li>Onboarding registration- When resolution is at 80%, PAM report admin option is not visible in dropdown</li><li>Reports- SSO based application- Reports are blank/ not showing data when SSO based application are accessed</li><li>After release v 3.1.2, for old updated tenant campaign module is disabled</li><li>Onboarding registration- When an application is selected and then reverted to the previous page, selecting the application again causes the application count to double</li><li>External JIT- JIT configuration should be disabled until new external idp configuration details are filled</li><li>External IDP- JIT- API is showing "undefined" error on clicking JIT button and on enabling JIT configuration</li><li>External IDP- JIT- Reverse the title, it is confusing for user</li><li>MFA - Secret Question - Question selection is getting non-selectable after entering incorrect answers and then retrying for correct answer</li><li>My workspace>Inbox- Count is not showing when records are in claim</li><li>Reports( Employee's with upcoming contract end date) - By default date filter should be applied of 30 days</li><li>Provision Rule - Cursor of the condition is getting overlapped with footer of the page.</li><li>Onboarding - Login credentials timeout error</li><li>My Access - Superset Application logo and label should be changed</li><li>Applications- When any attribute is updated (made empty in the target application) and recon for both exist operation is executed, the corresponding attribute in Cymmetri should also be cleared</li><li>Deprovision- User is getting deprovisioned even after user status is changed to Active from Inactive</li><li>Audit log-Recon - When recon is executed with status as Inactive, audit log is showing "Recon initiated successfully" but not any log for execution failed/aborted</li><li>User threshold mail notification- Title changes required</li><li>Application- Managed view- When manager is removed from Cymmetri, user is still getting displayed in managed view</li><li>Create Threshold Config> Csv import- Showing empty records in pending staging list when threshold limit is exceed and user are imported via csv file</li><li>Reports- SSO based application- Reports are blank/ not showing data when SSO based application are accessed</li><li>My workspace>Inbox- Count is not showing when records are in claim</li><li>login with admin-Campaign detail show role also, currently role showing only for campaign manager</li><li>Cymmetri Selfservice App - Once we click on the web link from scanner , it should show confirmation popup on screen (Suggestion)</li><li>Selfservice Mobile App - When app is in Quit state and open the app via scanner(camera), it is not redirecting to login page of the website</li><li>Push Authenticator - Need to change the error message</li><li>User creation- While creating new users then going to next level that is on groups page and then on application page ,then user should be redirected back to the group's page when back button is clicked instead of existing user creation page</li><li>Showing error when saving workflow with name( User creation, Application provisioning, Application deprovisioning)</li><li>deployment_analytics_1 Service CPU utilisation is 100%</li><li>Campaign-email report showing error</li><li>Some time tenant registration not working,showing WriteConflict error in the service</li><li>Application provisioning and deprovisioning workflow initiated request is not getting displayed in activity logs.</li><li>Workflow Rules - Application Deprovisioning event - If condition is set as RegEx for custom attribute is not working</li><li>User update-Showing audit failed-Write conflict</li><li>Report - Updated record should display on top.</li><li>Auth rule showing unknown error</li><li>Workflow List - View any workflow detail - While clicking on info icon it is showing Grade List Detail</li><li>AD-Recon-If Policy attribute marked inactive then also it is getting pull from AD</li><li>Login via Application admin- When click on application showing processing please wait error message</li><li>Applications- Application are not getting assigned to user and also audit log is not visible for the same</li><li>PAM write admin not able to assign users, user list not populating</li></ol></td><td><p></p><ol><li>manager notification : receiving user name required manager name</li><li>In application setting if show to user flag off then also application show in recent application.</li><li>Unable to identify application properties data type where value is empty</li><li>Amaya || Create user operation fails due to invalid password</li><li>Reports- Records are getting displayed after 11min approximately</li></ol></td></tr></tbody></table>

<table data-full-width="true"><thead><tr><th>VERSION</th><th>New Feature</th><th>Fixes</th><th>Known Bugs</th></tr></thead><tbody><tr><td>3.1.5 Beta<br> (6 August 2024)</td><td><p></p><ol><li>UI/UX - Workflow Inbox User detail will now have applications detail as well assigned to the user</li><li>UI/UX - Workflow Inbox will have start date and end date filter</li><li>User delete workflow support a. Workflow configuration support b. Rule configuration support</li><li>CISO Dashboard - REVERTED</li><li>Amaya || General Config based role data type</li></ol></td><td><p></p><ol><li>PAM write admin not able to assign users, user list not populating</li><li>Policy map- Empty value are getting saved in policy mapping</li><li>Workflow Rule update - View - Created by and updated by fields are empty</li><li>Superset - OpenId issue - While doing sso for superset application, it should is getting redirect superset url with error "The request to sign in was denied"</li><li>Threshold configuration- Replace could be to can be</li><li>Policy Map- When searching in the search box by any attribute, the search should get reset after changing tabs</li><li>Onboarding - Login credentials timeout error</li><li>Application- When searching user in application, user can be searched by first name, last name, login id but not by First name+lastname</li><li>PAM write admin not able to assign users, user list not populating</li><li>TOTP-Lookahead window change , on click save button show warning message,</li><li>User delete Workflow - Pending Workflow - Application details tab is not present</li></ol></td><td><p></p><ol><li>manager notification : receiving user name required manager name</li><li>In application setting if show to user flag off then also application show in recent application.</li><li>Unable to identify application properties data type where value is empty</li><li>Amaya || Create user operation fails due to invalid password</li><li>Reports- Records are getting displayed after 11min approximately</li><li>Deprovision Rule executed via Scheduler - Workflow is not getting initiated for the set of users on the basis of status/end date</li><li>Workflow List - Getting error " Contact system administrator" on technova tenant</li></ol></td></tr></tbody></table>

<table data-full-width="true"><thead><tr><th>Version</th><th>New Features</th><th>Fixes</th><th>Known Bugs</th></tr></thead><tbody><tr><td>3.1.6 (10 September 2024)</td><td><ol><li>Form Logic - The FormLogic functionality, enables you to store custom data using flexible, administrator-defined forms. It empowers you to create forms tailored to your specific data collection requirements, providing a versatile solution for various data management needs.  360 Degree Reconciliation - Compare tab added to the current feature, where user can compare with the source application and target application and further generate reports and download csv.</li><li>SkipPasswordExpiry - We are enhancing our Password Policy by introducing a new field</li><li>SkipPasswordExpiry, within the PasswordChangeRule. This enhancement allows users to opt out of the password expiry process entirely. When the SkipPasswordExpiry field is enabled, users will not receive warnings or notifications about password expiry, nor will they be prompted to change their password due to its expiration.</li><li>Connector: SimpleLDAP application. </li><li>ICICI Client - Role Based form delivery in IGA.</li><li>SDK based integration to send mobile push notifications to mitigate legacy API issues: a. Fido Based Notifications b. Normal Push Based Notifications The LDAP adapter has been updated with a new feature that eliminates the need to enter a username and password for each execution.</li></ol></td><td><p></p><ol><li>Form logic-Configured Forms -On click setting icon screen getting flicker</li><li>Selfservice Submit form-Update error message and backend error code if pre and post hook script h</li><li>Form logic-on form submit close form</li><li>Form logic-Selfservice-My Form Submissions pagination, page getting blank</li><li>Archived Forms detail-Revision data showing wrong, showing non existing list</li><li>Form logic-After changing form schema, form detail showing blank</li><li>Form logic-User submissions-Provide search by taskeid, username, loginid</li><li>Form logic-on all screen search only working for the exact case, expected should be work for matchin</li><li>Form logic-Form table-sorting not working</li><li>Form logic-Pre and post hook should be non mandatory</li><li>Form map with rule-if form map more than defined limit then error message showing only one time</li><li>Staging users details - Version history log user details not loading</li><li>Form logic-Configured form and archive form detail, back button behaviour is not as expected, need</li><li>Form logic-Form Access Rules-Link form, save button should be disabled till form selection</li><li>form logic- if request is timeout or fail then feature showing disabled</li><li>Form logic-User submissions-Provide date filter</li><li>Workflow || Additional Form Info || Readonly text-based form submissions</li><li>Timebased Application: Timebased application assignment message spelling incorrect</li><li>Deprovision- When applications are assigned via group and deprovision is executed all the application</li><li>Teams - Suspended Users - List View - Edit - It is redirecting to Users but showing a blank screen</li><li>Application Search: When clicking on "View More Applications" and searching for an application, the</li><li>Pending Staging- When no records are present on the page, the "Select All" button should be disabled</li><li>User Onboarding - Dropdowns are not loading when creating a user after adding an Admin during t</li><li>Global search - Pending action is not coming in global search</li></ol></td><td><p></p><ol><li>manager notification : receiving user name required manager name</li><li>In application setting if show to user flag off then also application show in recent application.</li><li>Unable to identify application properties data type where value is empty</li><li>Amaya || Create user operation fails due to invalid password</li><li>Reports- Records are getting displayed after 11min approximately</li><li>Deprovision Rule executed via Scheduler - Workflow is not getting initiated for the set of users on th</li><li>Workflow List - Getting error " Contact system administrator" on technova tenant</li><li>FormLogic || Step 2 of form || Form config JSON should be mandatory</li></ol></td></tr></tbody></table>


# 4.0

**Version: cloud\_4.0 product release**

**Date:** 10 October 2025

## Frontend Framework Upgrade

Upgraded Node.js version to v20.16.0 for frontend build generation.

## Spring Boot Upgrade

Migrated the backend framework to Spring Boot v3.4.4 and upgraded multiple dependent libraries.

## Amaya Enhancements

### Multi-role Support

Supports multiple role assignments if the application supports it.

### New Node Types & Capabilities

* Conditional Node: Expression builder support using forwarded data variables.
* Transformational Node: Modify or add new attributes (primarily used in sync operations).
* API Node:
  * Create/Update/Delete/Role Assign/Unassign operations.
  * Resolved a bug which previously required calling an additional API to get UID.
* Iterator Node: Transform and update object lists for synchronization.
* Subflow: Sub-process specifically applicable within an Iterator context.
* Run Flow: Allows debugging with mock data to validate flow logic.
* Run Request: Preview flow execution with input variables, bypassing actual provisioning.

### Quick Setup Templates Updated

New templates added in AMAYA for:

* Zoho Expenses
* Zoho Books
* Zoho CRM
* Zoho Desk

## SSO Policy

* 12-hour frequency added for MFA enforcement on applications.

## Separation of SSO and PAM

Based on a configuration property, SSO and PAM can now be enabled/disabled independently for flexible access control.

## SOD

* Enhanced UI with conflict details on Teams & Inbox pages.
* Bug fix for handling multiple conflicting rules under the same SoD policy.

### External SoD Violation Handling (Preventive)

Preventive approach for checking the potential violation of the user to stop violations from occurring.

## Reconciliation

### Reconciliation History UI

Users can now view reconciliation summaries directly from the table view.

### Reconciliation Improvements

* Skip updates if the application is not assigned.
* Skip user update if already linked; remarks added to history.
* For both-exist update case: if application is not assigned then user update will not happen; remark “Application not present so skipping” added and marked as error.
* For both-exist link case: validation added — if the application is already assigned, the user will be skipped and a remark added in the reconciliation history.
* Multipod reconciliation support added.
* Assign a deleted or inactive user as a manager to users (updation provided to allow creation and updation of users with inactive RM).

### Role Reconciliation Enhancements

This release extends reconciliation capabilities to include both users and their associated roles.

* Role Synchronization: Along with users, one or more roles (if present) can now be synced into Cymmetri. Supported sources include REST API applications, database applications, and Amaya.
* Role Reconciliation Dashboard: A new dashboard provides visibility into roles, with options to keep or remove stale roles (roles not present in the source but existing in Cymmetri).

## Suspend to Archive Enhancements

* Final delete provisioning call triggered by default unless explicitly disabled.
* Property-based toggle: cymmetri.suspend.to.archive.provision.triggered = false disables it.

## Suspend During Deletion Logging

Application and status logs are now captured under USER\_CHANGE\_STATUS for traceability.

## Bulk User Actions

Bulk actions introduced via the dashboard:

* Lock/Unlock User
* Activate/Deactivate User
* Delete User
* Assign Local Group
* Bulk Action Summary Dashboard
* Assign Delete Manager to user

## Post-Commit Hook for Application Update

New hook: Application Post Update After Commit — provides enhanced support for executing actions after an application update is finally committed in Cymmetri.

## Redis Stream Support

Support for JMS with Redis Streams is provided now.

## Workflows

* Enhanced logic for unique Task ID generation.
* Task ID format can now be configured (length, characters).
* New notification templates added for application assign / un-assign / update, post-workflow emails:
  * Target User Notification (the user for whom application event is triggered)
  * Requester Notification (the user who initiated application event for the target user)
* Inbox - Bulk Action: Approvers can perform bulk actions on multiple access requests directly from their inbox (select several requests and approve or reject in one operation).
* Pending Workflows – Unclaimed Workflows:
  * On the Pending Workflows page, workflows not yet claimed will display "UNCLAIMED" in the Current Assign column.
  * A note will be shown: “Pending claim with group, grade, userlist, or no approver found. See details for actual assignment.”

## Annotations

Annotations enable dynamic approver configuration in access reviews and workflows. They can be assigned as reviewers or approvers for both Application and Group Reviews. Supported combinations include:

* User only
* User + Application
* User + Application + Role
* User + Group

Approvers can be individual users or groups.

## Group Review

Introduced the Group Review capability in access reviews. Admins can now initiate reviews based on:

* All Groups
* Specific multiple Groups
* Specific multiple Applications

## Exclusion Access Types in Campaigns

Support for Exclusion Access Types has been introduced in Application Access Review Campaigns, allowing more granular control over which accesses are excluded from reviews. The following types are now supported:

* On Create by Provision Rule
* On Update by Provision Rule
* Exception Applications
* Global Applications
* On Demand Applications

## Data Pipeline

The Data Pipeline enables merging and processing of data from multiple sources for views, such as:

* MongoDB to ClickHouse
* ClickHouse to ClickHouse

The processed data is stored in ClickHouse, and can be leveraged in hooks, APIs, and for reporting.

## Policy Simulator

Cymmetri's Policy Simulator enables rule-based enforcement of access and compliance policies by evaluating "Should" and "Should NOT" scenarios. It identifies access gaps or violations (e.g., missing MFA or conflicting roles) and allows launching targeted review campaigns based on these insights.

## CAPTCHA Support

Cymmetri now supports CAPTCHA validation using hCaptcha and Traditional CAPTCHA, enhancing protection against automated and bot-based attacks.

## Ticker

The Ticker feature allows administrators to broadcast time-bound text-based updates, announcements, or alerts directly within Cymmetri. Messages can be broadcasted to specific users before and after login based on rules.

## Self Registration

Cymmetri now supports configurable Self Registration, allowing users to securely register themselves based on defined parameters and policies.

### Sub User Creation

Admins can configure registration fields and hook code for creating and updating sub users (Team Members).

### Activation Link

New self-registered users can set their login passwords using the Activation link support.

### Reset Password Link

Admins or Managers can send a reset password link to registered users so they can set their login passwords.

## Role Management

Cymmetri’s Role Management enhancements improve handling of roles at an individual level, including:

* Role-wise Status Management (e.g., Success, Fail) for better visibility and traceability of role lifecycle events.
* Single Role Retry Mechanism.
* Time-based Role Management with Status Tracking.
* Old vs. New Role List Management.

{% stepper %}
{% step %}

### Role Management: Overview

As per the new implementation in scripts, the following role variables are available for role assignment/unassignment cases.
{% endstep %}

{% step %}

### \<ROLE\_ASSIGN> Case

* **ROLE**: Backward compatibility with all roles list; contains a list of successfully assigned roles and new roles that are to be assigned.
* **ALREADYASSIGN**: Set of all the roles that are assigned to the user.
* **NEWROLE**: Single role (new role which is being assigned).
  {% endstep %}

{% step %}

### \<ROLE\_UNASSIGN> Case

* **ROLE**: Single role (role which is being unassigned).
  {% endstep %}
  {% endstepper %}

## 360 Generate Comparison Report

The 360 Degree Reconciliation feature allows pulling user and role information from target applications connected to Cymmetri, enabling comparison of users and their entitlements across applications, the source of truth, and the Cymmetri identity store. Use cases include:

* Identities present in Source application but not in Identity Store.
* Identities present in Source but not in Target application.
* Similar reports for entitlements across applications.

## Team Configuration Changes

* Admin can provide configuration, registration fields, password reset activation link, and hook code for creating and updating sub users (Team Members).
* Admin can configure the Manager Application setting in the Assign Application setting to restrict the Manager to assign and the user to request only applications that are assigned to the manager.

## Banner

The Banner feature allows administrators to broadcast time-bound image-based updates, announcements, or alerts directly within Cymmetri. Banners can display scrolling images or carousels and can link to an external page via a valid URL. They can be broadcasted to specific users before and after login based on rules.

## Advanced Analytics (Cube.js) – Custom Reports & Dashboards

Enhancements provide more control and flexibility over Cymmetri data:

* Custom Reports (Dashlets): End users can create reports with various dimensions and measures.
* Export & Share: Download reports as CSV/PDF or send via email.
* Custom Dashboards: Combine multiple reports into personalized dashboards for a complete view of KPIs and metrics.

<details>

<summary>Note</summary>

* For SAML related services - the Spring upgradation has not been performed for this release.

</details>


# Starting your Cymmetri Trial

1. Start by clicking on the link [register.cymmetri.io](https://register.cymmetri.io/) to start the registration of your tenant on the Cymmetri Cloud 2.0, and enter your personal details with your work email. Click on Next. &#x20;

<figure><img src="/files/jinUvQucTXUtmW6LyfhQ" alt=""><figcaption></figcaption></figure>

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003393280/original/TCG5t3nwg3bL8ZgBgrs3MpwgNrZVw3_rHg.png?1649310456" alt=""><figcaption></figcaption></figure>

2. Enter your country and phone number (mandatory to receive OTP), and enter a domain name for your tenant. In case the domain available message is not shown, choose a different domain name. Click on the **Start Trial** button.&#x20;

<figure><img src="/files/wKJHFirdAN3T3tGHg0Bl" alt=""><figcaption></figcaption></figure>

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003393282/original/lJ_srOx34VH2bEyFuXhQMhtEtT8cYGalNg.png?1649310457" alt=""><figcaption></figcaption></figure>

3. You will receive an OTP on your mobile number from the previous step. Enter the OTP here and wait for a few seconds for your tenant to be created.&#x20;

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003393281/original/bHgH6kmwNeMeJB1XVNxAJjSHQao9CwbTRw.png?1649310457" alt=""><figcaption></figcaption></figure>

4. You will be redirected to your domain to create the first *Organization Admin* user. Ensure that your password matches the password policy.

<figure><img src="/files/xa5N2kRzOS8wAReHwthT" alt=""><figcaption></figcaption></figure>

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003393285/original/Vj02z2bb6OuHdZ4qSNojAtJUV-Ec98BNow.png?1649310457" alt=""><figcaption></figcaption></figure>

5. You will receive a message showing that your tenant has been created.

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003393283/original/k4EL-KvYz5WtNQWZOL6AM_bjyo5piTn7pA.png?1649310457" alt=""><figcaption></figcaption></figure>

6. Click on the **Login** button to proceed with the onboarding process&#x20;

<figure><img src="/files/sF1mVPtzTtwFTjcgXNGf" alt=""><figcaption></figcaption></figure>

6. Enter your username and press Next

<figure><img src="/files/HKmqRKyAktoXMatAGfi1" alt=""><figcaption></figcaption></figure>

7. Enter your password and proceed with the setup of your tenant by clicking on the Login button.

<figure><img src="/files/gNrFBuHnIK91jdspe4cS" alt=""><figcaption></figcaption></figure>

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003393287/original/HFTJE_C7rbDmzHvg8BXBzSM7BhQLeH0l7g.png?1649310457" alt=""><figcaption></figcaption></figure>

8. Choose applications from the application catalogue, and click on the application icon for all the applications you wish to add. Then click on the Next button.&#x20;

<figure><img src="/files/CNBr0u9RUrwze6eVqZC8" alt=""><figcaption></figcaption></figure>

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003393290/original/oGoJOpg6qL_uqiUSGd8RniU_C19CXfmo4w.png?1649310458" alt=""><figcaption></figcaption></figure>

9. Enter details to create a second administrator account. Click on the Send Invite button to create an administrator. Click on the Next button to proceed. &#x20;

<figure><img src="/files/RdNqiUqHnT87kFFMea2E" alt=""><figcaption></figcaption></figure>

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003393286/original/XM5i6voWyzhDMMaKfNNfw6QhCJ1b6UIFqA.png?1649310458" alt=""><figcaption></figcaption></figure>

10. (Optional) Add users if you wish to. Then click on Finish. &#x20;

<figure><img src="/files/yWFS5Rfd7fWv41YZ2ECO" alt=""><figcaption></figcaption></figure>

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003393289/original/1i2HpU3yAeTOhyg_u0Px7gpZUc39J7ENhg.png?1649310458" alt=""><figcaption></figcaption></figure>

11. You will be redirected to the Dashboard to proceed with the system.&#x20;

<figure><img src="/files/TSKM56THYiqbQ1pB7o93" alt=""><figcaption></figcaption></figure>

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003393288/original/b6nAcDeUFiw_EoJjRfx2O-F19m0X3YCRVw.png?1649310458" alt=""><figcaption></figcaption></figure>

&#x20;Next Steps:

1. [Learn how new users can access your tenant. ](/my-workspace/getting-started/first-time-user-registration)
2. [Manage your users and groups. ](/identity-hub/managing-users-and-groups)
3. [Manage your applications. ](/lifecycle-management/application-management/getting-started/introduction-to-application-management)
4. [Check out your workspace. ](/my-workspace/how-to-use-the-my-workspace/dashboard)
5. [Add your own branding. ](/getting-started/personalization/tenant-branding)


# Admin Dashboard

The Cymmetri dashboard acts as a central command center for identity management, providing a visual summary of key metrics and quick access to administrative functions. Upon logging in, administrators see a comprehensive overview of user activity, system health, and important shortcuts.

### Dashboard Overview

The main dashboard section provides critical insights into daily user activity and authentication health:

* **Users Activity**: The total count of successful user logins on the current day.
* **Accounts Locked**: The number of user accounts that have been locked on the current day, often due to failed login attempts.
* **Users Onboarded**: A count of all new users who have been provisioned in the system on the current day.
* **Password Reset**: The total number of password reset activities that have occurred on the current day.
* **Authentication Stats**: A breakdown of successful and failed login attempts over a specified period, helping to monitor security events.
* **App Identity**: Displays the status of application reconciliation, specifically related to user identities.
* **Shortcut to Configure Recently Added Application**: A direct link to configure newly onboarded applications by defining roles, provisioning, reconciliation, and Single Sign-On (SSO) settings.

<figure><img src="/files/LKlE4Qgxm6pgE9OEt9pP" alt=""><figcaption></figcaption></figure>

### System Key Performance Indicators (KPIs)

The dashboard also displays high-level system KPIs, providing a snapshot of the identity environment's scale and configuration.

* **Application**: The total number of applications integrated into Cymmetri.
* **Active Users**: The total number of users with active accounts in the system.
* **Total Users**: The overall count of all users who have been onboarded into Cymmetri.
* **Roles**: The total number of application-specific roles that have been created.
* **Workflows**: The total number of approval workflows configured in the system.
* **Password Policy**: The total number of distinct password policies created for user authentication.
* **Rules**: The total number of business rules created for provisioning, Multi-Factor Authentication (MFA), and approval workflows.
* **Users Unlogged**: The number of users who have been provisioned but have never logged in to Cymmetri.

<figure><img src="/files/3TxGtY6DSbOJLXdbiZnc" alt=""><figcaption></figcaption></figure>

### Dashboard Shortcuts

Located on the right side of the dashboard, the Shortcuts section offers quick access to common administrative tasks, streamlining routine operations.

#### **User Management Shortcuts**

* **Add User**: Directs you to the user creation page to add new users to the system.

<figure><img src="/files/J8a9yeSeEGw6nIZWsNPV" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/DKyMuZip5GWL6UcRuCWF" alt=""><figcaption></figcaption></figure>

* **Activate User**: Displays a list of inactive users, allowing you to quickly reactivate an account.

<figure><img src="/files/sDpoeXQzz2eIY3l5Y3pG" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/QImfdStQd4wvZieG1fwS" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/0JhEKjE15PFslzOUeTgh" alt=""><figcaption></figcaption></figure>

* **Deactivate User:** Displays a list of active users, allowing you to deactivate an account and revoke access.<br>

  <figure><img src="/files/bTySrIjvpS8W9yF5DqLF" alt=""><figcaption></figcaption></figure>

  <figure><img src="/files/4bJGarUtHdMdqCWd6QZy" alt=""><figcaption></figcaption></figure>
* **Reset Password**: Navigates to the password reset function for a selected user.

<figure><img src="/files/TNUBYZ9yrDSReEIio0TZ" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/O1QoSKuzNYtptb875AGW" alt=""><figcaption></figcaption></figure>

* **Unlock User**: Provides a direct way to unlock a user account that has been locked due to failed login attempts or other restrictions.

<figure><img src="/files/h07rRdkRX7MAIvSq1zTZ" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/XsxUVsRFF7eCookpRrUN" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/oCqWtJYBe4ZDv7wAMgqZ" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/mKaFk3kGpGJNu2vORkmn" alt=""><figcaption></figcaption></figure>

#### **Application Management Shortcuts**

* **Add Application**: A direct link to the application integration wizard.

<figure><img src="/files/WV0dgWKPtJu38rmxfGxa" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/pFJbLnZlrlIOxirvxQgC" alt=""><figcaption></figcaption></figure>

* **Assign Application**: Simplifies the process of assigning an existing application to an individual user or a group.

<figure><img src="/files/h8msQxYp9mrjJgT1w9Y0" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/YV6z3ycg3vmtwwzyyWgb" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/cgZ4g0VXerdshy5xp09B" alt=""><figcaption></figcaption></figure>


# Accessing Cymmetri

To access Cymmetri, users must use a web browser, such as <mark style="color:blue;">Google Chrome</mark> or <mark style="color:blue;">Safari</mark>, and enter the appropriate address in the address bar as shown below:

<mark style="color:blue;">URL</mark>: https\://\<companyname>.cymmetri.io/login

<mark style="color:blue;">Example</mark>: <https://helpdocs.cymmetri.io/login><br>

<figure><img src="/files/tMtDjSWqiacLUtNXofm1" alt=""><figcaption></figcaption></figure>

Once the address is entered, it opens a page as shown below, where the users may enter their username and password to access Cymmetri.

<figure><img src="/files/190vqNssIiDfApsd84Gc" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/hPkYjBKLLmewNR5Z3bs1" alt=""><figcaption></figcaption></figure>

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003188615/original/rwhScbcMWiqEhpoKFfcbK4BtLjurEyCtZg.png?1648985335" alt=""><figcaption></figcaption></figure>


# Supported Web Browsers

Cymmetri supports the following web browsers:

<table data-full-width="false"><thead><tr><th width="127">OS</th><th width="121" align="center">Chrome</th><th width="121" align="center">Firefox</th><th width="106" align="center">IE</th><th width="154" align="center">Edge</th><th align="center">Safari</th></tr></thead><tbody><tr><td>Android </td><td align="center"><img src="/files/fQNjLhmy5YC1zTss5iXg" alt="" data-size="line"></td><td align="center"><img src="/files/PxGRsTkjycHxybiFOnHT" alt="" data-size="line"></td><td align="center"><strong>NA</strong></td><td align="center"><img src="/files/0OoheFaX1fngeh40oiwV" alt="" data-size="line"></td><td align="center"><img src="/files/xa7JHHhXZttOy8i3vDv8" alt="" data-size="line"></td></tr><tr><td>iOS </td><td align="center"><img src="/files/SLvsGgZoyJfxdq3sPcTT" alt="" data-size="line"> </td><td align="center"><img src="/files/Z0w4gcOGPiVBPJGgTfKD" alt="" data-size="line"></td><td align="center"><strong>NA</strong></td><td align="center"><img src="/files/RLe4pXE6rrJDEd0dgeqZ" alt="" data-size="line"></td><td align="center"><img src="/files/TnZBmlMsS5VxBPBHEN7I" alt="" data-size="line"></td></tr><tr><td>Mac OS </td><td align="center"><img src="/files/7mevPxYy1ljbm7dDakQj" alt="" data-size="line"></td><td align="center"><img src="/files/OF572AOrrxNNZZz8Ucts" alt="" data-size="line"></td><td align="center"><strong>NA</strong></td><td align="center"><img src="/files/URhNwI7WzbJ6f9crbpCR" alt="" data-size="line"></td><td align="center"><img src="/files/c6om629wQYzSDhLGtNbb" alt="" data-size="line"></td></tr><tr><td>Windows </td><td align="center"><img src="/files/BETZO8kwmRwkdekK8BKu" alt="" data-size="line"></td><td align="center"><img src="/files/AKDg2PTJjyXMJbzvaY1R" alt="" data-size="line"></td><td align="center"><img src="/files/Bfe5z1OAJyuUgLKLasRe" alt="" data-size="line"> </td><td align="center"><img src="/files/Mzu0QwBV0rOATDRpYplG" alt="" data-size="line"></td><td align="center"><img src="/files/suWndGA4K3tgHSuXJA4D" alt="" data-size="line"></td></tr></tbody></table>

Version of specific browsers supported by Cymmetri are:

### DESKTOP:

<table><thead><tr><th width="73">Browser</th><th width="73">Version</th></tr></thead><tbody><tr><td>Chrome</td><td>66</td></tr><tr><td>Edge</td><td>16</td></tr><tr><td>Firefox</td><td>57</td></tr><tr><td>Opera</td><td>57</td></tr><tr><td>Safari</td><td>53</td></tr></tbody></table>

### MOBILE:

<table><thead><tr><th width="126">Browser</th><th width="115">Version</th></tr></thead><tbody><tr><td>Chrome Android</td><td>12.1</td></tr><tr><td>Firefox Android</td><td>66</td></tr><tr><td>Opera Android</td><td>57</td></tr><tr><td>Safari iOS</td><td>47</td></tr><tr><td>Samsung Browser</td><td>12.2</td></tr></tbody></table>


# Cymmetri Error Codes

A comprehensive list of all known Cymmetri error codes and their summary understanding:

<table data-full-width="true"><thead><tr><th width="405">ERROR CODE</th><th width="393">ERROR TEXT</th></tr></thead><tbody><tr><td>CONNECTION_ERROR</td><td>Unable to connect. Please check your connection and try again.</td></tr><tr><td>USRSRVC.LAST_DATE_REACHED</td><td>The application's request end date is greater than the user's end date.</td></tr><tr><td>USRSRVC.MISSING_DATES</td><td>Incorrect dates Please ensure the selected date range is proper.</td></tr><tr><td>USRSRVC.EXPIRED_TIME_BOUND</td><td>Access request duration has ended</td></tr><tr><td>REGSRVC.UNKNOWN</td><td>Error. Please try again later or contact Cymmetri Administrator.</td></tr><tr><td>REGSRVC.USER_NOT_FOUND</td><td> User not found.</td></tr><tr><td>REGSRVC.INVALID_TOKEN</td><td> Token expired. Try again.</td></tr><tr><td>REGSRVC.OTP_EXPIRED</td><td> OTP expired. Please resend and try again.</td></tr><tr><td>REGSRVC.OTP_LIMIT_EXCEED</td><td> Otp limit exceeded.</td></tr><tr><td>REGSRVC.INVALID_OTP</td><td> OTP does not match. Please check &#x26; try again</td></tr><tr><td>REGSRVC.INVALID_ARGUMENTS</td><td> Error. Please correct input and try again.</td></tr><tr><td>REGSRVC.INVALID_DOMAIN</td><td> Invalid Domain. Please try again.</td></tr><tr><td>REGSRVC.INVALID_CREDENTIALS</td><td> Invalid Credentials. Please try again.</td></tr><tr><td>REGSRVC.TERMS_AND_CONDITIONS_NOT_FOUND</td><td> Invalid Terms &#x26; Conditions. Please try again.</td></tr><tr><td>REGSRVC.INVALID_ACCOUNT_VERIFICATION_TOKEN</td><td> Invalid request. Contact Cymmetri administrator.</td></tr><tr><td>REGSRVC.DATA_IS_NOT_VALID</td><td> Invalid data. Please try again.</td></tr><tr><td>REGSRVC.PASSWORD_NOT_VALID</td><td> Invalid password. Please try again</td></tr><tr><td>REGSRVC.EMAIL_EXISTS</td><td> Duplicate Email Address. Please try again.</td></tr><tr><td>REGSRVC.DOMAIN_EXISTS</td><td> Duplicate Domain.</td></tr><tr><td>REGSRVC.DB_CONFIG_EXISTS</td><td> Database already exists. Contact Cymmetri administrator.</td></tr><tr><td>REGSRVC.USER_ALREADY_ACTIVE</td><td> User status is active. Contact Cymmetri administrator.</td></tr><tr><td>USRSRVC.MANAGER_NOT_FOUND</td><td> No Manager Found</td></tr><tr><td>USRSRVC.UNSUPPORTED_FILE_TYPE</td><td> Unsupported File Type</td></tr><tr><td>USRSRVC.UNKNOWN</td><td> Error. Please try again later or contact Cymmetri Administrator.</td></tr><tr><td>USRSRVC.INVALID_ARGUMENTS</td><td> Error. Please correct input and try again.</td></tr><tr><td>USRSRVC.NONUNIQUE_GROUPNAME</td><td> Group name already exists. Please try again.</td></tr><tr><td>USRSRVC.GROUPTYPE_NOT_FOUND</td><td> Group type not found. Contact Cymmetri administrator.</td></tr><tr><td>USRSRVC.OU_NOT_FOUND</td><td> Organization Unit not found. Please try again.</td></tr><tr><td>USRSRVC.PARENTGROUP_NOT_FOUND</td><td> Parent Group not found. Please try again.</td></tr><tr><td>USRSRVC.GROUP_NOT_FOUND</td><td> Group not found. Please try again.</td></tr><tr><td>USRSRVC.USER_NOT_FOUND</td><td> User not found. Please try again.</td></tr><tr><td>USRSRVC.CYCLIC_UPDATE</td><td> Operation not allowed for current input.</td></tr><tr><td>USRSRVC.INHERITED_GROUP</td><td> Operation not allowed for current input.</td></tr><tr><td>USRSRVC.USERTYPE_NOT_FOUND</td><td> User type not found. Please try again.</td></tr><tr><td>USRSRVC.EXISTING_MOBILE</td><td> User mobile number in use. Please try again.</td></tr><tr><td>USRSRVC.EXISTING_EMAIL</td><td> User email address in use. Please try again.</td></tr><tr><td>USRSRVC.DEPARTMENT_NOT_FOUND</td><td> Department not found. Please try again.</td></tr><tr><td>USRSRVC.DESIGNATION_NOT_FOUND</td><td> Designation not found. Please try again.</td></tr><tr><td>USRSRVC.COUNTRY_NOT_FOUND</td><td> Country not found. Please try again.</td></tr><tr><td>USRSRVC.EXISTING_LOGIN</td><td> User Login ID in use. Please try again.</td></tr><tr><td>USRSRVC.APPLICATION_NOT_FOUND</td><td> Application not found. Please try again.</td></tr><tr><td>USRSRVC.APPLICATION_ROLE_NOT_FOUND</td><td> Application role not found. Please try again.</td></tr><tr><td>PROVSRVC.CYMMETRI_LOGIN_FIELD_NOT_CONFIGURED</td><td> Please configure Cymmetri Login field for Policy Mapping.</td></tr><tr><td>PROVSRVC.APPLICATION_TEST_FAILED</td><td> Provision Configuration failed.</td></tr><tr><td>USRSRVC.USER_NOT_PROVISIONED</td><td> User not provisioned. Please try again.</td></tr><tr><td>USRSRVC.CHILD_GROUP_FOUND</td><td> Cannot Delete as Child group found.</td></tr><tr><td>USRSRVC.GROUP_HAS_ASSIGNED_APPS</td><td> Group has assigned applications. Remove and try again.</td></tr><tr><td>USRSRVC.USER_ASSIGNED_GROUP</td><td> Cannot delete as User assigned to group.</td></tr><tr><td>USRSRVC.USER_MUST_PRESENT_IN_TARGET</td><td> User must present in target system before assign it to group.</td></tr><tr><td>USRSRVC.INACTIVE_USER</td><td> Inactive User cannot perform this action.</td></tr><tr><td>USRSRVC.INVALID_MANAGER</td><td> Invalid manager.</td></tr><tr><td>USRSRVC.MIN_ORG_ADMIN_RULE_VIOLATION</td><td> Admin role cannot be removed for this user.</td></tr><tr><td>USRSRVC.USER_ROLE_MAPPING_EXISTS</td><td> Role Already Exists.</td></tr><tr><td>USRSRVC.APPLICATION_ROLE_ALREADY_ASSIGNED</td><td> Application role is already assigned.</td></tr><tr><td>USRSRVC.APPLICATION_ALREADY_ASSIGNED</td><td> Application is already assigned.</td></tr><tr><td>USRSRVC.USER_ROLE_MAPPING_NOT_EXISTS</td><td> User role mapping does not exists.</td></tr><tr><td>USRSRVC.CANNOT_REMOVE_PROVISIONED_APPLICATION</td><td> Cannot remove already provisioned application.</td></tr><tr><td>USRSRVC.EMPTY_FILE</td><td> Empty file uploaded.</td></tr><tr><td>USRSRVC.SELF_STATUS_CHANGE_NOT_ALLOWED</td><td> This user cannot be deleted.</td></tr><tr><td>USRSRVC.MANAGER_ASSIGNMENT_REJECTED</td><td> Error. The manager assignment is invalid.</td></tr><tr><td>USRSRVC.INVALID_ENDDATE</td><td> The end date should be greater than start date.</td></tr><tr><td>USRSRVC.SELF_ROLE_CHANGE_NOT_ALLOWED</td><td> Self role change is not allowed.</td></tr><tr><td>USRSRVC.CUSTOM_ATTRIBUTE_MASTER_EXIST</td><td> Custom attribute already exist.</td></tr><tr><td>USRSRVC.CUSTOM_ATTRIBUTE_MASTER_NOT_FOUND</td><td> Custom attribute not found.</td></tr><tr><td>USRSRVC.DUPLICATE_NAME</td><td> Duplicate name record already exist.</td></tr><tr><td>USRSRVC.DUPLICATE_LABEL</td><td> Duplicate label record already exist.</td></tr><tr><td>USRSRVC.ATTRIBUTE_RIGHTS_NOT_FOUND</td><td> Attribute rights not found.</td></tr><tr><td>USRSRVC.REMOTE_GROUP_APPLICATION_NOT_FOUND</td><td> Application must present before assign user to remote group.</td></tr><tr><td>USRSRVC.REMOTE_GROUP_NAME_NOT_MODIFIED_EXCEPTION</td><td> Remote group name not able to update</td></tr><tr><td>USRSRVC.EMPTY_LOGIN</td><td> Something went wrong Please contact the administrator.</td></tr><tr><td>USRSRVC.TOO_LARGE_FILE</td><td> File size should not be more than {size}</td></tr><tr><td>USRSRVC.FORM_DEACTIVATED_EXCEPTION</td><td> Form is inactive</td></tr><tr><td>USRSRVC.ACTION_NOT_SUPPORTED</td><td> This action is not supported</td></tr><tr><td>AUTHSRVC.ACCESS_DENIED</td><td> Invalid Credentials.</td></tr><tr><td>AUTHSRVC.TENANT_EXPIRED</td><td> Free trial expired. Please contact Cymmetri administrator.</td></tr><tr><td>AUTHSRVC.UNKNOWN</td><td> Please contact system administrator.</td></tr><tr><td>AUTHSRVC.INVALID_TOKEN</td><td> Token is invalid.</td></tr><tr><td>AUTHSRVC.USER_NOT_FOUND</td><td> User not found.</td></tr><tr><td>AUTHSRVC.CANT_SET_FALSE_DEFAULT_PASSWORD_POLICY</td><td> Default password policy cannot be false.</td></tr><tr><td>AUTHSRVC.CONNECTION_FAILED</td><td> Connection failed.</td></tr><tr><td>AUTHSRVC.CANT_DELETE_DEFAULT_PASSWORD_POLICY</td><td> Cannot delete default password policy.</td></tr><tr><td>AUTHSRVC.INVALID_ARGUMENTS</td><td> Invalid argument.</td></tr><tr><td>AUTHSRVC.INVALID_AUTH_POLICY_CONFIG</td><td> Invalid auth policy config.</td></tr><tr><td>AUTHSRVC.ACCESS_DENIED_TOKEN</td><td> Session expired. Please login again</td></tr><tr><td>AUTHSRVC.ADAPTIVE_BLOCK_ACTION</td><td> Action blocked. Please contact administrator.</td></tr><tr><td>SESSION_EXPIRED</td><td> Session expired. Please refresh and try again</td></tr><tr><td>AUTHSRVC.NON_REMOVABLE_REFERENCED_ENTITY</td><td> Cannot modify IDP configuration till active under Authentication Policy.</td></tr><tr><td>AUTHSRVC.PASSWORD_POLICY_NAME_ALRAEDY_EXISTS</td><td> Password policy name already exists.</td></tr><tr><td>AUTHSRVC.PASSWORD_POLICY_CONDITION_ALRAEDY_EXISTS</td><td> Policy Conditions already exists.</td></tr><tr><td>AUTHSRVC.DEFAULT_POLICY_UPDATE_NOT_ALLOWED</td><td> Default password policy update not allowed.</td></tr><tr><td>AUTHSRVC.PASSWORD_COMPOSITION_RULE_VIOLATION</td><td> Password provided does not match the required guidelines.</td></tr><tr><td>AUTHSRVC.MOBILE_NOT_FOUND</td><td> Mobile number is not registered please contact Cymmetri Administrator.</td></tr><tr><td>AUTHSRVC.ALREADY_EXISTS</td><td> Name already exist. Please enter unique name.</td></tr><tr><td>AUTHSRVC.LDAP_ACCESS_DENIED</td><td> Access denied.</td></tr><tr><td>AUTHSRVC.CLIENT_EXISTS</td><td> API Client with same name already configured.</td></tr><tr><td>AUTHSRVC.USER_NOT_ACTIVE</td><td> Delegated user not active</td></tr><tr><td>AUTHSRVC.INVALID_AUTH_CONFIG</td><td> Invalid auth config</td></tr><tr><td>AUTHSRVC.PASSWORD_POLICY_NAME_ALREADY_EXISTS</td><td> Password policy name already exists.</td></tr><tr><td>AUTHSRVC.TRUST_DEVICE_MAX_DEVICE_EXCEPTION</td><td> Exceeded device trust max limit</td></tr><tr><td>AUTHSRVC.TRUST_DEVICE_EXPIRY_EXCEPTION</td><td> Exceeded expiration time for trust devices</td></tr><tr><td>AUTHSRVC.MULTIPLE_TRUST_DEVICE_CONFIG</td><td> Multiple trust device configuration found</td></tr><tr><td>AUTHSRVC.INVALID_GLOBAL_SESSION_CONFIGURATION</td><td> Invalid global auth configuration</td></tr><tr><td>AUTHSRVC.MULTI_SESSION_ACCESS_DENIED</td><td> Session(s) already in progress. Logout from all sessions to continue.</td></tr><tr><td>MFASRVC.UNKNOWN</td><td> Error. Please try again.</td></tr><tr><td>MFASRVC.USER_NOT_FOUND</td><td> User not found. Please try again.</td></tr><tr><td>MFASRVC.ALREADY_SENT_SMS_OTP</td><td> SMS OTP already sent.</td></tr><tr><td>MFASRVC.INVALID_SMS_OTP</td><td> Invalid SMS OTP provided.</td></tr><tr><td>MFASRVC.RESEND_COUNT_EXCEED</td><td> Allowed resend attempt exceed please try after some time</td></tr><tr><td>MFASRVC.PUSH_NOTIFICATION_FAILED</td><td> Failed to send the push notification. Please try again later or contact Cymmetri Administrator. </td></tr><tr><td>MFASRVC.MFA_CONFIG_NOT_FOUND</td><td> Multi Factor Authentication configuration not found.</td></tr><tr><td>MFASRVC.INVALID_ARGUMENTS</td><td> Error. Invalid request.</td></tr><tr><td>MFASRVC.QUESTION_NOT_FOUND</td><td> Question not found.</td></tr><tr><td>MFASRVC.DUPLICATE_QUESTION</td><td> Question field is duplicate. Please try again.</td></tr><tr><td>MFASRVC.INCORRECT_ANSWER</td><td> Answer field is incorrect. Please try again.</td></tr><tr><td>MFASRVC.INVALID_USERID</td><td> Invalid User. Please try again.</td></tr><tr><td>MFASRVC.INVALID_QUESTIONID</td><td> Question is invalid. Please try again.</td></tr><tr><td>MFASRVC.USER_NOT_REGISTERED</td><td> User is not registered for TOTP/Push Authentication</td></tr><tr><td>MFASRVC.EMPTY_QUESTION</td><td> Question field is empty. Please try again.</td></tr><tr><td>MFASRVC.FAILED_MINIMUM_CORRECT_ANSWER</td><td> Please provide correct answer for each question.</td></tr><tr><td>MFASRVC.INVALID_TOTP</td><td> Invalid Time based OTP provided.</td></tr><tr><td>MFASRVC.INVALID_ANSWER</td><td> Answer field is invalid. Please try again.</td></tr><tr><td>MFASRVC.QUESTION_NOT_REGISTERED</td><td> Question is not registered.</td></tr><tr><td>MFASRVC.NON_REMOVABLE_QUESTION</td><td> Question in use and cannot be removed.</td></tr><tr><td>MFASRVC.USER_RESPONSE_PENDING</td><td> User response is pending.</td></tr><tr><td>MFASRVC.USER_DENIED_ACCESS</td><td> User denied access.</td></tr><tr><td>MFASRVC.NOT_ABLE_TO_MODIFY</td><td> Not able to modify. Please try again</td></tr><tr><td>MFASRVC.INVALID_ANSWER_LENGTH</td><td> Invalid answer length</td></tr><tr><td>MFASRVC.DISPOSABLE_EMAIL</td><td> </td></tr><tr><td>MFASRVC.FIREHOL_IP_REPUTATION</td><td> Ip reputation sync failed</td></tr><tr><td>MFASRVC.SYNC_PROCESS_RUNNING</td><td> Sync is in progress. Please wait</td></tr><tr><td>MFASRVC.IMPOSSIBLE_TRAVEL_NOT_FOUND</td><td> Config not found</td></tr><tr><td>MFASRVC.DEVICE_TRUST_NOT_FOUND</td><td> Config not found</td></tr><tr><td>MFASRVC.BLACKLISTED_LOCATION_NOT_FOUND</td><td> Config not found</td></tr><tr><td>MFASRVC.LOCATION_EMPTY</td><td> </td></tr><tr><td>MFASRVC.BLACKLISTED_IP_NOT_FOUND</td><td> Blacklisted IP not found</td></tr><tr><td>MFASRVC.IP_ADDRESS_EMPTY</td><td> </td></tr><tr><td>MFASRVC.MFA_NOT_FOUND</td><td> MFA not found</td></tr><tr><td>MFASRVC.INVALID_CONFIG</td><td> Invalid configuration</td></tr><tr><td>MFASRVC.SERVICE_NOT_SUPPORTED</td><td> </td></tr><tr><td>MFASRVC.PLUGIN_REGISTRY_NOT_REGISTERED</td><td> </td></tr><tr><td>MFASRVC.BLACKLISTED_IPADDRESS_CONFIG_NOT_FOUND</td><td> Config not found</td></tr><tr><td>MFASRVC.BLACKLISTED_LOCATION_CONFIG_NOT_FOUND</td><td> Config not found</td></tr><tr><td>MFASRVC.IMPOSSIBLE_TRAVEL_CONFIG_NOT_FOUND</td><td> Config not found</td></tr><tr><td>MFASRVC.BREACHED_PASSWORD_CONFIG_NOT_FOUND</td><td> Config not found</td></tr><tr><td>MFASRVC.COUNTRY_CODE_MISMATCH_CONFIG_NOT_FOUND</td><td> Config not found</td></tr><tr><td>MFASRVC.SHORT_LIVED_DOMAIN_CONFIG_NOT_FOUND</td><td> Config not found</td></tr><tr><td>MFASRVC.USER_BEHAVIOUR_CONFIG_NOT_FOUND</td><td> Config not found</td></tr><tr><td>MFASRVC.MULTIPLE_DEVICE_TRUST_FOUND</td><td> Multiple config found</td></tr><tr><td>MFASRVC.COMMON_CREDENTIAL_DOWNLOAD_FAILED</td><td> </td></tr><tr><td>WKFLSRVC.UNKNOWN</td><td> Please contact system Administrator</td></tr><tr><td>WKFLSRVC.WORKFLOW_NOT_FOUND</td><td> No workflow available</td></tr><tr><td>WKFLSRVC.INVALID_ARGUMENTS</td><td> Please check input and try again.</td></tr><tr><td>WKFLSRVC.INVALID_LEVEL</td><td> Workflow Config issue</td></tr><tr><td>WKFLSRVC.EXCEEDED_REPORTING_MANAGER</td><td> Can not more than reporting manager</td></tr><tr><td>WKFLSRVC.WORKFLOW_SETUP_NOT_FOUND</td><td> No workflow config available</td></tr><tr><td>WKFLSRVC.REQUESTOR_NOT_FOUND</td><td> Requestor not found in the system.</td></tr><tr><td>WKFLSRVC.WORKFLOW_IN_PROGESS</td><td> Request is pending for approval.</td></tr><tr><td>WKFLSRVC.REPORTING_MANAGER_NOT_FOUND</td><td> Please assign approver's manager to complete workflow.</td></tr><tr><td>WKFLSRVC.LEVEL_NOT_IN_RANGE</td><td> Workflow level is not in range.</td></tr><tr><td>WKFLSRVC.WORKFLOW_SETUP_ALREADY_EXISTS</td><td> Workflow setup already exists.</td></tr><tr><td>WKFLSRVC.COMMON_REQ_ASSG_ID</td><td> Self-approval is not allowed Please contact the administrator for the reassignment.</td></tr><tr><td>WKFLSRVC.SAME_REQUESTOR_ASSIGNEE</td><td> Workflow cannot be assigned to same user.</td></tr><tr><td>WKFLSRVC.WORKFLOW_ALREADY_EXISTS</td><td> Workflow with same name already exists.</td></tr><tr><td>WKFLSRVC.DAYS_THRESHOLD_EXCEED_EXCEPTION</td><td> Max allowed TAT is {maxAllowedDays} days</td></tr><tr><td>WKFLSRVC.DELEGATE_COMMON_REQ_ASSG_ID</td><td> Approver and assignee can't be same.</td></tr><tr><td>WKFLSRVC.APPLICATION_DECOMMISSIONED</td><td> This application is decommissioned so the request can not be approved/rejected please refresh the page.</td></tr><tr><td>SSOCONFIGSRVC.UNKNOWN</td><td> Error. Please try again.</td></tr><tr><td>SSOCONFIGSRVC.SSO_CONFIG_NOT_FOUND</td><td> SSO config not found.</td></tr><tr><td>SSOCONFIGSRVC.SAML_CONFIG_NOT_FOUND</td><td> Saml config not found.</td></tr><tr><td>SSOCONFIGSRVC.OPENID_CLIENT_NOT_FOUND</td><td> OpenID config not found.</td></tr><tr><td>SSOCONFIGSRVC.DUPLICATE_OPENID_CLIENT_ID</td><td> Duplicate OpenID Client ID.</td></tr><tr><td>SSOCONFIGSRVC.API_CONFIG_NOT_FOUND</td><td> API config not found.</td></tr><tr><td>SSOCONFIGSRVC.INVALID_ARGUMENTS</td><td> Invalid Arguments.</td></tr><tr><td>SSOCONFIGSRVC.INVALID_CIDR</td><td> Not all CIDR are valid</td></tr><tr><td>SSOCONFIGSRVC.UNSUPPORTED_FILE_TYPE</td><td> Unsupported File Type</td></tr><tr><td>SSOCONFIGSRVC.ERROR_GENERATING_KEYS</td><td> Failed to generate keys.</td></tr><tr><td>SSOCONFIGSRVC.CERTIFICATE_PARSING_ERROR</td><td> Failed to read certificate. Please try again.</td></tr><tr><td>SSOCONFIGSRVC.ERROR_DEACTIVATING_KEYS</td><td> Failed to deactivate key. Please try again.</td></tr><tr><td>SSOCONFIGSRVC.KEY_GENERATION_FAILED</td><td> Failed to generate keys.</td></tr><tr><td>SSOCONFIGSRVC.METADATA_GENERATION_FAILED</td><td> Could not generate Metadata.</td></tr><tr><td>SSOCONFIGSRVC.ALRAEDY_EXISTS</td><td> Configuration for same Entity ID already exists.</td></tr><tr><td>SSOCONFIGSRVC.KEYS_CANNOT_BE_DISABLED</td><td> Key is being used in IDP or SP</td></tr><tr><td>SSOCONFIGSRVC.KEY_DOES_NOT_EXISTS</td><td> No related key found</td></tr><tr><td>SSOCONFIGSRVC.IDENTITY_PROVIDER_IS_DISABLED</td><td> Identity Provider is disabled</td></tr><tr><td>SSOCONFIGSRVC.DUPLICATE_POLICY_MAPPING</td><td> Policy mapping already exists</td></tr><tr><td>SSOCONFIGSRVC.USER_DOES_NOT_HAVE_ACCESS</td><td> User does not have access</td></tr><tr><td>SSOCONFIGSRVC.KEYS_IS_DISABLED</td><td> Keys Disabled</td></tr><tr><td>SSOCONFIGSRVC.IDENTITY_PROVIDER_DOES_NOT_EXISTS</td><td> Identity Provider does not exist</td></tr><tr><td>SSOCONFIGSRVC.IDENTITY_PROVIDER_KEY_IS_DISABLED</td><td> Identity Provider key disabled</td></tr><tr><td>SSOCONFIGSRVC.SERVICE_PROVIDER_IS_DISABLED</td><td> Service Provider disabled</td></tr><tr><td>SSOCONFIGSRVC.IDENTITY_PROVIDER_ALREADY_ENABLED</td><td> Identity Provider already enabled</td></tr><tr><td>SSOCONFIGSRVC.IDENTITY_PROVIDER_CANNOT_BE_DISABLED</td><td> Identity Provider can not be disabled</td></tr><tr><td>SSOCONFIGSRVC.KEYS_ALREADY_EXISTS</td><td> Keys already exists</td></tr><tr><td>SSOCONFIGSRVC.KEY_MINIMUM_EXPIRATION</td><td> Key Minimum expiration</td></tr><tr><td>SSOCONFIGSRVC.SERVICE_PROVIDER_ENABLED</td><td> Service provider enabled</td></tr><tr><td>SSOCONFIGSRVC.SERVICE_PROVIDER_DISABLED</td><td> Service provider disabled</td></tr><tr><td>SSOCONFIGSRVC.KEY_IS_BEING_USED</td><td> Key already used</td></tr><tr><td>SSOCONFIGSRVC.SERVICE_PROVIDER_CANNOT_BE_UPDATED</td><td> Service provider can not be updated</td></tr><tr><td>SSOCONFIGSRVC.SERVICE_PROVIDER_IS_BEING_USED</td><td> Service provider is being used</td></tr><tr><td>SSOCONFIGSRVC.INVALID_SAML_CONFIG</td><td> invalid saml configuration</td></tr><tr><td>SSOCONFIGSRVC.NOT_FOUND</td><td> SSO cofiguration not found</td></tr><tr><td>SSOCONFIGSRVC.CONNECTION_FAILED</td><td> SSO configuration connection failed</td></tr><tr><td>SSOCONFIGSRVC.FORBIDDEN</td><td> SSO configuration forbidden</td></tr><tr><td>SSOCONFIGSRVC.UNAUTHORIZED</td><td> SSO configuration unauthorized</td></tr><tr><td>SSOCONFIGSRVC.CERTIFICATE_EXPIRED</td><td> SSO configuration certificate is expired</td></tr><tr><td>SSOCONFIGSRVC.SAML_APP_CONFIG_NOT_FOUND</td><td> SSO configuration saml application configuration not found</td></tr><tr><td>SSOCONFIGSRVC.SAML_ATTR_CONFIG_NOT_FOUND</td><td> SSO configuration saml attribute configuration not found</td></tr><tr><td>SSOCONFIGSRVC.OPENID_SCOPE_NOT_FOUND</td><td> SSO configuration openid scope not found</td></tr><tr><td>SSOCONFIGSRVC.OPENID_CLAIM_NOT_FOUND</td><td> SSO configuration openid claim not found</td></tr><tr><td>SSOCONFIGSRVC.APPLICATION_NOT_FOUND</td><td> SSO configuration application not found</td></tr><tr><td>SSOCONFIGSRVC.DUPLICATE_POLICYATTRIBUTE</td><td> SSO configuration policy attribute is duplicate</td></tr><tr><td>SSOCONFIGSRVC.INVALID_POLICYATTRIBUTE_ID</td><td> SSO configuration policy attribute is invalid</td></tr><tr><td>SSOCONFIGSRVC.INAVLID_POLICYATTRIBUTE_APPLICATION</td><td> SSO configuration policy attribute application is invalid</td></tr><tr><td>SSOCONFIGSRVC.MANDATORY_ENTRY</td><td> SSO configuration policy field is mandatory</td></tr><tr><td>SSOCONFIGSRVC.INVALID_POLICY_MAP</td><td> SSO configuration policy map is invalid</td></tr><tr><td>SSOCONFIGSRVC.NO_MAPPING_FOUND</td><td> SSO configuration mapping is not found</td></tr><tr><td>SSOCONFIGSRVC.IDENTITY_PROVIDER_DOES_EXISTS</td><td> SSO configuration identity provider does not exist</td></tr><tr><td>SSOCONFIGSRVC.MULTIPLE_IDENTITY_PROVIDER_EXISTS</td><td> SSO configuration multiple identity provider exists</td></tr><tr><td>SSOCONFIGSRVC.SERVICE_PROVIDER_EXISTS</td><td> SSO configuration service provider already exists</td></tr><tr><td>SSOCONFIGSRVC.SERVICE_PROVIDER_DOES_NOT_EXISTS</td><td> Service provider does not exist</td></tr><tr><td>SSOCONFIGSRVC.DOMAIN_EXISTS</td><td> Domain doesn't exists</td></tr><tr><td>SAMLSRVC.KEY_DOES_NOT_EXISTS</td><td> Key doesn't exists</td></tr><tr><td>SAMLSRVC.INVALID_COOKIE</td><td> Invalid session. Re-login and try again</td></tr><tr><td>SAMLSRVC.IDENTITY_PROVIDER_IS_DISABLED</td><td> Identity Provider is disabled</td></tr><tr><td>SAMLSRVC.EXPIRED_TOKEN</td><td> Session Expired. Please re-login and try again</td></tr><tr><td>SAMLSRVC.KEYS_IS_DISABLED</td><td> Key is disabled</td></tr><tr><td>SAMLSRVC.KEYS_IS_EXPIRED</td><td> Key is expired</td></tr><tr><td>SAMLSRVC.KEYS_NOT_GENERATED</td><td> Public and private key is not generated</td></tr><tr><td>SAMLSRVC.SAML_TYPE_NOT_APPLICABLE</td><td> SAML type configured and SAML type received mismatched</td></tr><tr><td>SAMLSRVC.NAMEID_MISMATCH</td><td> SAML nameId configured and nameId received mismatched</td></tr><tr><td>SAMLSRVC.INVALID_SAML2_AUTHN_REQUEST_SIGNATURE</td><td> SAML authentication request signature is invalid</td></tr><tr><td>SAMLSRVC.ISSUE_INSTANT_MISMATCH</td><td> SAML authentication response is invalid with issue instant</td></tr><tr><td>SAMLSRVC.MESSAGE_REPLAY</td><td> SAML message is being sent again</td></tr><tr><td>SAMLSRVC.DESITNATION_MISMATCH</td><td> SAML destination configured and received mismatched</td></tr><tr><td>SAMLSRVC.VERSION_MISMATCH</td><td> SAML version does not match</td></tr><tr><td>SAMLSRVC.PROTOCOL_BINDING_MISMATCH</td><td> SAML protocol binding does not match</td></tr><tr><td>SAMLSRVC.REQUEST_ISSUER_URI_MISMATCH</td><td> SAML request issuer uri does not match</td></tr><tr><td>SAMLSRVC.ASSERTION_CONSUMER_SERVICE_URI_MISMATCH</td><td> SAML request assertion consumer service uri does not match</td></tr><tr><td>SAMLSRVC.INVALID_USER_SESSION</td><td> SAML user session is invalid</td></tr><tr><td>SAMLSRVC.USER_DOES_NOT_HAVE_ACCESS</td><td> User does not have access</td></tr><tr><td>SAMLSRVC.IDENTITY_PROVIDER_DOES_NOT_EXISTS</td><td> Identity Provider does not exist</td></tr><tr><td>SAMLSRVC.IDENTITY_PROVIDER_KEY_IS_DISABLED</td><td> Identity Provider key is disabled</td></tr><tr><td>SAMLSRVC.SERVICE_PROVIDER_IS_DISABLED</td><td> Service Provider is disabled</td></tr><tr><td>UTILSRVC.UNKNOWN</td><td> Error. Please try again.</td></tr><tr><td>UTILSRVC.INVALID_ARGUMENTS</td><td> Error. Please correct input and try again.</td></tr><tr><td>UTILSRVC.CONFIGURATION_EXIST</td><td> Hook already present.</td></tr><tr><td>UTILSRVC.ALREADY_EXISTS</td><td> Hook already present.</td></tr><tr><td>UTILSRVC.META_ATTRIBUTE_EXISTS</td><td> Name/Key or Value already exist.</td></tr><tr><td>UTILSRVC.MODULES_ENQUIRY_EXIST</td><td> Sales team is working on your request. We will get back to you soon.</td></tr><tr><td>UTILSRVC.LABEL_ALREADY_EXIST</td><td> Label Already Exists</td></tr><tr><td>UTILSRVC.EVENT_ALREADY_EXIST</td><td> Event Already Exists</td></tr><tr><td>UTILSRVC.BEHALF_CONFIG_NOT_FOUND</td><td> On Behalf configuration is not found.</td></tr><tr><td>UTILSRVC.MULTIPLE_BEHALF_CONFIG_FOUND</td><td> Multiple Behalf configurations found.</td></tr><tr><td>UTILSRVC.LENGTH_EXCEED_EXCEPTION</td><td> Length exceeded</td></tr><tr><td>UTILSRVC.SCRIPT_CUSTOM_ERROR-MOBILEALREADYEXIST</td><td> Mobile number already in use Try again with another number.</td></tr><tr><td>UTILSRVC.SCRIPT_CUSTOM_ERROR-EMAILALREADYEXIST</td><td> Email already in use Try again with another email.</td></tr><tr><td>USRSRVC.FORM_NOT_FOUND</td><td> Form not found</td></tr><tr><td>UTILSRVC.WEBHOOK_CALL_FAILED</td><td> Webhook test failed.</td></tr><tr><td>UTILSRVC.BATCH_TASK_EXECUTION_FAILED</td><td> Batch process execution failed.</td></tr><tr><td>UTILSRVC.BATCH_TASK_ALREADY_EXIST</td><td> Batch task already exists.</td></tr><tr><td>PROVSRVC.UNKNOWN</td><td> Error. Please try again later or contact Cymmetri Administrator.</td></tr><tr><td>PROVSRVC.USER_NOT_FOUND</td><td> User not found.</td></tr><tr><td>PROVSRVC.INVALID_ARGUMENTS</td><td> Error. Please correct input and try again.</td></tr><tr><td>PROVSRVC.APPLICATION_NOT_FOUND</td><td> Application not found. Please try again.</td></tr><tr><td>PROVSRVC.INVALID_USER_ACTION</td><td> User action not allowed. Please check configuration.</td></tr><tr><td>PROVSRVC.INVALID_GROUP_ACTION</td><td> Group action not allowed. Please check configuration.</td></tr><tr><td>PROVSRVC.INVALID_ROLE_ACTION</td><td> Role action not allowed. Please check configuration.</td></tr><tr><td>PROVSRVC.INAVLID_ACTION</td><td> Error. Please try again.</td></tr><tr><td>PROVSRVC.UID_NOT_FOUND</td><td> Record not found. Please try again.</td></tr><tr><td>PROVSRVC.Empty_Role_Id</td><td> Role not provided. Please try again.</td></tr><tr><td>PROVSRVC.Duplicate_GroupID</td><td> Duplicate Group association.</td></tr><tr><td>PROVSRVC.Invalid_GroupId</td><td> Invalid Group association.</td></tr><tr><td>PROVSRVC.CONNECTOR_NOT_FOUND</td><td> Connector not available. Please contact Cymmetri administrator.</td></tr><tr><td>PROVSRVC.UNSUPPORTED_OPERATION</td><td> Operation not supported.</td></tr><tr><td>PROVSRVC.APPLICATION_ALREADY_EXISTS</td><td> Application already exists.</td></tr><tr><td>PROVSRVC.INVALID_POLICYATTRIBUTE_ID</td><td> Invalid Policy configuration. Please try again.</td></tr><tr><td>PROVSRVC.DUPLICATE_POLICYATTRIBUTE</td><td> Duplicate Policy attribute selected.</td></tr><tr><td>PROVSRVC.INVALID_POLICY_MAP</td><td> Invalid Policy map.</td></tr><tr><td>PROVSRVC.INVALID_MASTER_AAPPLICATION_Id</td><td> Invalid master application reference.</td></tr><tr><td>PROVSRVC.NO_MAPPING_FOUND</td><td> Policy map not found.</td></tr><tr><td>PROVSRVC.DUPLICATE_POLICY_MAPPING</td><td> Duplicate Policy mapping.</td></tr><tr><td>PROVSRVC.INAVLID_POLICYATTRIBUTE_APPLICATION</td><td> Invalid Policy association. Please try again.</td></tr><tr><td>PROVSRVC.PROVISIONING_NOT_ENABLE</td><td> Provisioning not enable</td></tr><tr><td>PROVSRVC.DUPLICATE_ROLE</td><td> Role ID in use. Please try again.</td></tr><tr><td>PROVSRVC.DUPPLICATE_NAME</td><td> Name already in use.</td></tr><tr><td>PROVSRVC.IDENTITY_ALREADY_EXISTS_EXCEPTION</td><td> User principle is already checked Please reset and try again.</td></tr><tr><td>PROVSRVC.IDENTITY_NOT_CHECKED_EXCEPTION</td><td> At least one user principle should be checked.</td></tr><tr><td>RULESRVC.UNKNOWN</td><td> Error. Please try again.</td></tr><tr><td>RULESRVC.RULE_NOT_FOUND</td><td> Rule not found.</td></tr><tr><td>RULESRVC.RULE_CONDITION_NOT_FOUND</td><td> Rule condition not found.</td></tr><tr><td>RULESRVC.RULE_ACTION_GROUP_NOT_FOUND</td><td> No group associated with rule. Please try again.</td></tr><tr><td>RULESRVC.NON_REMOVABLE_REFERENCED_ENTITY</td><td> Cannot be modified as entity in use.</td></tr><tr><td>RULESRVC.ALRAEDY_EXISTS</td><td> Rule with same name already exists.</td></tr><tr><td>RULESRVC.RULE_CONFIGURE_ALREADY_EXIST</td><td> Rule with same condition configuration already exists.</td></tr><tr><td>RULESRVC.MULTIPLE_ZONES_FOUND</td><td> Multiple zones found.</td></tr><tr><td>RULESRVC.ZONE_NOT_FOUND</td><td> Zone not found.</td></tr><tr><td>RULESRVC.INVALID_ARGUMENTS</td><td> Please correct the input and try again.</td></tr><tr><td>RULESRVC.DEFAULT_RULE_NOT_FOUND</td><td> Default rule not found.</td></tr><tr><td>IGSRVC.UNKNOWN</td><td> Error. Please try again.</td></tr><tr><td>IGSRVC.INVALID_JWT</td><td> Error. Invalid JWT token.</td></tr><tr><td>IGSRVC.CAMPAIGN_COMPLETION_PERIOD_EXCEED</td><td> Error. Campaign Completion Period Exceeded.</td></tr><tr><td>IGSRVC.CAMPAIGN_STAGE_NOT_FOUND</td><td> Error. Campaign Stage Not Found.</td></tr><tr><td>IGSRVC.CAMPAIGN_SCOPE_NOT_FOUND</td><td> Error. Campaign Scope Not Found.</td></tr><tr><td>IGSRVC.CAMPAIGN_ALREADY_IN_DRAFT_STATE</td><td> Error. Campaign Already In Draft State.</td></tr><tr><td>IGSRVC.CAMPAIGN_ALREADY_IN_PUBLISHED_STATE</td><td> Error. Campaign Already In Published State.</td></tr><tr><td>IGSRVC.CAMPAIGN_EXECUTION_IN_PROGRESS</td><td> Error. Campaign Execution in Progress.</td></tr><tr><td>IGSRVC.CAMPAIGN_ASSIGNMENT_NOT_FOUND</td><td> Error. Campaign Assignment Not Found.</td></tr><tr><td>IGSRVC.CAMPAIGN_HISTORY_NOT_FOUND</td><td> Error. Campaign History Not Found.</td></tr><tr><td>IGSRVC.UNABLE_TO_PROCESS_RESPONSE</td><td> Error. Unable To Process Response.</td></tr><tr><td>IGSRVC.CAMPAIGN_ASSIGNMENT_APPLICATION_NOT_FOUND</td><td> Error. Campaign Assignment Application Not Found.</td></tr><tr><td>IGSRVC.CAMPAIGN_ASSIGNMENT_APPLICATION_ROLE_NOT_FOUND</td><td> Error. Campaign Assignment Application Role Not Found.</td></tr><tr><td>IGSRVC.APP_ROLE_ALREADY_PROCEED</td><td> Error. App Role Already Proceeded.</td></tr><tr><td>IGSRVC.INACTIVE_USER_FOUND</td><td> Error. Inactive User Found.</td></tr><tr><td>IGSRVC.NO_ACTIVE_EXECUTION_FOUND</td><td> Error. No Active Execution Found.</td></tr><tr><td>IGSRVC.INVALID_CRON_EXPRESSION</td><td> Error. Invalid Cron Expression.</td></tr><tr><td>IGSRVC.DUPLICATE_CAMPAIGNNAME</td><td> Error. Duplicate Campaign Name.</td></tr><tr><td>IGSRVC.CAMPAIGN_NOT_FOUND</td><td> Campaign not found.</td></tr><tr><td>IGSRVC.INVALID_ARGUMENTS</td><td> Error. Please correct input and try again.</td></tr><tr><td>IGSRVC.CAMPAIGN_STATE_STARTED</td><td> Error. Campaign State Already Started.</td></tr><tr><td>IGSRVC.STAGE_LIMIT_EXCEED</td><td> Error. Stage Limit Exceeded.</td></tr><tr><td>IGSRVC.DUPLICATE_STAGE</td><td> Error. Duplicate Stage.</td></tr><tr><td>IGSRVC.ASSIGNMENT_ALREADY_PROCEED</td><td> Error. Assignment Already Proceeded.</td></tr><tr><td>IGSRVC.INVALID_CAMPAIGN_ITERATION</td><td> Invalid Campaign Iteration.</td></tr><tr><td>IGSRVC.INVALID_CAMPAIGN_MANAGER_ASSIGNEE</td><td> Campaign manager or assignee configured in stages are not valid.</td></tr><tr><td>IGSRVC.INVALID_CAMPAIGN_STATUS</td><td> Campaign execution in progress operation not allowed.</td></tr><tr><td>IGSRVC.USER_WITH_NO_VALID_APPLICATION</td><td> No valid assignments found aborted execution.</td></tr><tr><td>IGSRVC.CONNECTION_FAILED</td><td> Please check your internet connection.</td></tr><tr><td>IGSRVC.ALRAEDY_EXISTS</td><td> Record already exists.</td></tr><tr><td>IGSRVC.FORBIDDEN</td><td> Please contact system administrator.</td></tr><tr><td>IGSRVC.UNAUTHORIZED</td><td> Please contact system administrator.</td></tr><tr><td>IGPROCESS.UNKNOWN</td><td> Error. Please try again.</td></tr><tr><td>IGPROCESS.INVALID_ARGUMENTS</td><td> Error. Please correct input and try again.</td></tr><tr><td>IGPROCESS.CAMPAIGN_NOT_FOUND</td><td> Error. Campaign Not Found.</td></tr><tr><td>IGPROCESS.NO_ACTIVE_EXECUTION_FOUND</td><td> Error. No Active Execution Found.</td></tr><tr><td>IGPROCESS.CAMPAIGN_HISTORY_NOT_FOUND</td><td> Error. Campaign History Not Found.</td></tr><tr><td>IGPROCESS.INVALID_CAMPAIGN_ITERATION</td><td> Error. Invalid Campaign Iteration.</td></tr><tr><td>IGPROCESS.CAMPAIGN_EXECUTION_IN_PROGRESS</td><td> Error. Campaign Execution In Progress.</td></tr><tr><td>IGPROCESS.MATCHING_ASSIGNMENTS_NOT_FOUND</td><td> Error. Matching Assignments Not Found.</td></tr><tr><td>SCHEDULER.UNKNOWN</td><td> Error. Please try again.</td></tr><tr><td>SCHEDULER.TASK_NOT_FOUND</td><td> Error. Task Not Found.</td></tr><tr><td>SCHEDULER.TASK_NOT_ACTIVE</td><td> Error. Task Not Active.</td></tr><tr><td>SCHEDULER.INVALID_ARGUMENTS</td><td> Error. Please correct input and try again.</td></tr><tr><td>SCHEDULER.INVALID_START_DATE</td><td> Error. Invalid Start Date.</td></tr><tr><td>SCHEDULER.TENANT_NOT_FOUND</td><td> Error. Tenant Not Found.</td></tr><tr><td>SCHEDULER.UPDATE_NOT_SUPPORTED</td><td> Error. Update Is Not Supported.</td></tr><tr><td>SCHEDULER.CRON_REPETITION_BELOW_ALLOWED_LIMIT</td><td> Error. Cron Repetition Is Below Allowed Limit.</td></tr><tr><td>SCHEDULER.INVALID_CRON_EXPRESSION</td><td> Invalid Cron Expression.</td></tr><tr><td>SODSRVC.ALREADY_EXISTS</td><td> Error. Value Already Exists.</td></tr><tr><td>SODSRVC.INVALID_ARGUMENTS</td><td> Error. Please correct the input and try again.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.UNKNOWN</td><td> Error. Please try again.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.IDENTITY_PROVIDER_WITH_NAME_EXISTS</td><td> Idenity Provider with same name already exist. Please enter unique name.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.SERVICE_PROVIDER_WITH_NAME_EXISTS</td><td> Service Provider with same name already exists.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.NON_REMOVABLE_REFERENCED_ENTITY</td><td> Cannot modify or remove service provider till active under external identity policy or rule.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.INVALID_ARGUMENTS</td><td> Please correct the input and try again.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.CERTIFICATE_PARSING_ERROR</td><td> Error occurred while parsing certificate.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.AUTH_TYPE_CANNOT_BE_UPDATED</td><td> Identity provider type cannot be updated.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.CONNECTION_FAILED</td><td> Please check your internet connection.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.IDP_CONFIGURATION_NOT_FOUND</td><td> Identity provider configuration not found.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.MULTIPLE_IDP_CONFIGURATION_FOUND</td><td> Multiple identity provider configuration found.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.NAME_ID_POLICY_NAME_ID_VALUE_MISMATCH</td><td> NameIdPolicy and NameIdValue does not match.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.SP_CONFIGURATION_NOT_FOUND</td><td> Service provider configuration not found.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.UNAUTHORIZED</td><td> Please contact system administrator.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.SERVICE_PROVIDER_NOT_FOUND</td><td> Service provider not found.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.CERTIFICATE_NOT_FOUND</td><td> Certificate not found.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.EAMIL_EXISTS</td><td> Email already exists.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.CUSTOM_IDENTITY_TYPE_MUST_HAVE_ID</td><td> Custom identity type must have ID.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.INACTIVE_CONFIGURATION_FOUND</td><td> Inactive configuration found.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.INVALID_IDP_CONFIGURED</td><td> Invalid IDP configured.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.NO_MAPPING_FOUND</td><td> No mapping found.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.INVALID_POLICY_MAPPING</td><td> Invalid policy mapping.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.POLICY_MAP_REQUIRED_FIELD_NOT_FOUND</td><td> Policy map required field not found.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.MANDATORY_FIELD_EXCEPTION</td><td> Mandatory field exception.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.MAPPING_ALREADY_EXISTS</td><td> Mapping already exists.</td></tr><tr><td>SAMLEXTIDPCONFIGSRVC.JIT_CONFIGURATION_NOT_FOUND</td><td> JIT configuration not found.</td></tr><tr><td>USRSRVC.INVALID_EXTENSION_ENDDATE</td><td> Extended end date should be less than current access end date.</td></tr><tr><td>MFASRVC.SMS_OTP_EXPIRED</td><td> SMS OTP expired.</td></tr><tr><td>MFASRVC.SHORT_ANSWER_LENGTH</td><td> Answer length is short.</td></tr><tr><td>MFASRVC.DEVICE_INFO_NOT_FOUND</td><td> Please scan the QR code.</td></tr><tr><td>AUTHSRVC.USER_LOCKED</td><td> User locked. Please Unlock your Account.</td></tr><tr><td>AUTHSRVC.EMAIL_NOT_FOUND</td><td> Email not found.</td></tr><tr><td>AUTHSRVC.INVALID_USER_ACCOUNT_STATE</td><td> Your account is expired/inactive. Please contact Cymmetri Administrator</td></tr><tr><td>AUTHSRVC.INVALID_DATE</td><td> Start/End date should be greater than current date and time.</td></tr><tr><td>AUTHSRVC.DELEGATE_CONSENT_NOT_FOUND</td><td> Error. Delegate consent not found.</td></tr><tr><td>AUTHSRVC.DELEGATE_USER_NOT_FOUND</td><td> Error. User doesn't have delegation access.</td></tr><tr><td>AUTHSRVC.NO_OPTION_AVAILABLE</td><td> Please contact Cymmetri Administrator for Password Reset.</td></tr><tr><td>AUTHSRVC.DELEGATION_DEACTIVATE</td><td> Error. Delegation is inactive.</td></tr><tr><td>AUTHSRVC.PASSWORD_EXPIRED</td><td> Your password has expired Please reset your password.</td></tr><tr><td>PROVSRVC.UNSUPPORTED_DELEGETE_MFA_SETUP</td><td> Delegatee can't setup MFA for application having additional authentication</td></tr><tr><td>PAMSRVC.UNSUPPORTED_DELEGETE_MFA_SETUP</td><td> Delegatee can't setup MFA for application having additional authentication</td></tr><tr><td>SLFSRVC.EXISITNG_APP_IN_TAG_FOUND</td><td> Application already available in tag.</td></tr><tr><td>AD-ADAPTER.FAILED_TO_PWD_CHANGE</td><td> Password change failed.</td></tr><tr><td>AUTHSRVC.INVALID_CONFIG</td><td> Invalid config for authentication policy or rule</td></tr><tr><td>PROVSRVC.UNAUTHORIZED</td><td> Unauthorized access.</td></tr><tr><td>REGSRVC.UNAUTHORIZED</td><td> Unauthorized access.</td></tr><tr><td>MFASRVC.INVALID_MFA_OTP_CONFIG</td><td> Invalid Otp config please contact admin</td></tr><tr><td>MFASRVC.EMAIL_NOT_FOUND</td><td> Email not registered please contact admin</td></tr><tr><td>MFASRVC.MOBILE_NOT_FOUND</td><td> Mobile not registered please contact admin</td></tr><tr><td>MFASRVC.EMAIL_MOBILE_NOT_FOUND</td><td> Mobile or email not registered please contact admin</td></tr><tr><td>MFASRVC.LARGE_ANSWER_LENGTH</td><td> Maximum answer lenght exceeded try with shorter length answer</td></tr><tr><td>SLFSRVC.EXISITNG_USER_TAG_FOUND</td><td> Tag with same name already exists</td></tr><tr><td>SLFSRVC.IMAGE_MAXSIZE_EXCEEDED</td><td> Maximum limit for file size exceeded.</td></tr><tr><td>SLFSRVC.IMAGE_TYPE_NOTALLOWED</td><td> Image Type not allowed</td></tr><tr><td>SLFSRVC.INVALID_ARGUMENTS</td><td> Invalid Arguments</td></tr><tr><td>REPORT.EMAIL_NOT_EXISTS_EXCEPTION</td><td> User Email Not Found. Please contact cymmetri administrator.</td></tr><tr><td>REPORT.CONNECTION_FAILED</td><td> Failed to send report.</td></tr><tr><td>SOME_ERROR_OCCURRED_WORKING_ON_IT</td><td> Please contact cymmetri administrator.</td></tr><tr><td>INVALID_IDENTITY_PROVIDER_STATUS</td><td> Invalid Identity Provider Status. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_ARGUMENTS</td><td> Please correct Input and try again. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SERVICE_PROVIDER_STATUS</td><td> Invalid Service Provider Status. Please contact cymmetri administrator.</td></tr><tr><td>MANDATORY_FIELD_EXCEPTION</td><td> Mandatory Field is Missing. Please contact cymmetri administrator.</td></tr><tr><td>TENANT_OR_HOST_NOT_RECEIVED_FROM_NGINX</td><td> Please contact cymmetri administrator.</td></tr><tr><td>TENANT_OR_HOST_PROTO_NOT_RECEIVED_FROM_NGINX</td><td> Please contact cymmetri administrator.</td></tr><tr><td>SOME_IMPERSONATE_ACCESS</td><td> Unauthorized Access. Please contact cymmetri administrator.</td></tr><tr><td>SERVICE_PROVIDER_INBOUND_MESSAGE_ERROR</td><td> Invalid SAML Message Received. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE_ASSERTION_VERSION</td><td> Invalid SAML Response Assertion version. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE_ISSUE_INSTANT</td><td> Invalid SAML Response Issue. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE_STATUS</td><td> Invalid SAML Response Status. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE_STATUS_REQUESTER_URI</td><td> Invalid SAML Response Status Requester URI. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE_STATUS_RESPONDER_URI</td><td> Invalid SAML Response Status Response URI. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE_STATUS_VERSION_MISMATCH_URL</td><td> Invalid SAML Response Status Version Mismatch URI. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE</td><td> Invalid SAML Response. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE_DESTINATION</td><td> Invalid SAML Response Destination. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE_VERSION_OR_ASSERTION_VERSION</td><td> Invalid SAML Response Version or Assertion Version. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE_ASSERTION_SUBJECT</td><td> Invalid SAML Response Assertion Subject. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE_ASSERTION_SUBJECT_NAMEID</td><td> Invalid SAML Response Assertion Subject NameId. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE_ASSERTION_ISSUER</td><td> Invalid SAML Response Assertion Issuer. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE_ASSERTION_CONDITION_AUDIENCE</td><td> Invalid SAML Response Assertion Condition Audience. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE_ASSERTION_AUTHNSTATEMENT</td><td> Invalid SAML Response Assertion AuthNStatement. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE_ASSERTION_ATTRIBUTE</td><td> Invalid SAML Response Assertion Attribute. Please contact cymmetri administrator.</td></tr><tr><td>MULTIPLE_ASSERTIONS_IN_RESPONSE_NOT_SUPPORTED</td><td> Multiple Assertion in Response Not Supported. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE_ASSERTION_SIGNATURE</td><td> Invalid SAML Response Assertion Signature. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE_SIGNATURE</td><td> Invalid SAML Response Signature. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE_ASSERTION_CONDITION</td><td> Invalid SAML Response Assertion Condition. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE_ASSERTION</td><td> Invalid SAML Response Assertion. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_RESPONSE_ISSUER</td><td> Invalid SAML Response Issuer. Please contact cymmetri administrator.</td></tr><tr><td>IDP_CONFIGURATION_NOT_FOUND</td><td> Idp Configuration Not Found. Please contact cymmetri administrator.</td></tr><tr><td>SP_ID_IDP_ID_LOGIN_EMPTY</td><td> Service provider or identity provider login not provided. Please contact cymmetri administrator.</td></tr><tr><td>SERVICE_PROVIDER_CONFIGURATION_NOT_FOUND</td><td> Service Provider Configuration Not Found. Please contact cymmetri administrator.</td></tr><tr><td>ERROR_BUILDING_SAML_AUTHN_REQUEST</td><td> Failed To Build SAML Authentication Request. Please contact cymmetri administrator.</td></tr><tr><td>ERROR_PERSISTING_SAML_AUTHN_REQUEST</td><td> Failed To Persist SAML Authentication Request. Please contact cymmetri administrator.</td></tr><tr><td>ERROR_SENDING_SAML_AUTHN_REQUEST</td><td> Failed to Send SAML Authentication Request. Please contact cymmetri administrator.</td></tr><tr><td>USER_EMAIL_ADDRESS_NOT_PRESENT</td><td> User Email Not Found. Please contact cymmetri administrator.</td></tr><tr><td>USER_LOGIN_NOT_PRESENT</td><td> User Login Not Found. Please contact cymmetri administrator.</td></tr><tr><td>EMAIL_ADDRESS_DOES_NOT_MATCH</td><td> Email Address does not matching. Please contact cymmetri administrator.</td></tr><tr><td>LOGIN_DOES_NOT_MATCH</td><td> Login does not match. Please contact cymmetri administrator.</td></tr><tr><td>USER_NOT_AVAILABLE</td><td> User is not present. Please contact cymmetri administrator.</td></tr><tr><td>SERVICE_PROVIDER_NOT_FOUND</td><td> Service provider is not found. Please contact cymmetri administrator.</td></tr><tr><td>UNAUTHORIZED_ACCESS</td><td> Unauthorized Access. Please contact cymmetri administrator.</td></tr><tr><td>UNAUTHORIZED</td><td> Unauthorized Access. Please contact cymmetri administrator.</td></tr><tr><td>USER_NOT_FOUND</td><td> User Not found. Please contact cymmetri administrator.</td></tr><tr><td>DATA_NOT_PRESENT</td><td> Application configuration does not exist. Please contact cymmetri administrator.</td></tr><tr><td>ARGUMENT_IS_REQUIRED</td><td> Please correct Input and try again. Please contact cymmetri administrator.</td></tr><tr><td>APPLICATION_CONFIG_EXISTS</td><td> Application Configuration already exists. Please contact cymmetri administrator.</td></tr><tr><td>APPLICATION_CONFIG_NOT_PRESENT</td><td> Application configuration does not exists. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_TOKEN</td><td> Invalid token Please contact cymmetri administrator.</td></tr><tr><td>TENANT_NOT_FOUND</td><td> Tenant detail not availaible. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_APPLICATION_ID</td><td> Invalid application id. Please contact cymmetri administrator.</td></tr><tr><td>APPLICATION_WITH_ISSUER_NOT_FOUND</td><td> Application configuration with issuer not found. Please contact cymmetri administrator.</td></tr><tr><td>EXCEPTION_OCCURED_WITH_TENANT_JKS</td><td> Please contact cymmetri administrator.</td></tr><tr><td>EXCEPTION_OCCURED_WITH_TENANT_JKS_KEY_GENERATE</td><td> Please contact cymmetri administrator.</td></tr><tr><td>APPLICATION_NOT_ASSIGNED_TO_USER</td><td> Application is not assigned to the user. Please contact cymmetri administrator.</td></tr><tr><td>USER_NOT_ASSIGNED_SERVICE_PROVIDER_ERROR</td><td> User is not assigned to the service provider. Please contact cymmetri administrator.</td></tr><tr><td>SOMETHING_WENT_WRONG</td><td> Please contact cymmetri administrator.</td></tr><tr><td>SERVICE_PROVIDER_NAMEIDVALUE_MISMATCH_ERROR</td><td> Service provider nameId value does not match with configured application. Please contact cymmetri administrator.</td></tr><tr><td>SERVICE_PROVIDER_NAMEID_MISMATCH_ERROR</td><td> Service provider nameId value does not match with configured application. Please contact cymmetri administrator.</td></tr><tr><td>TENANT_HOST_NOT_FOUND</td><td> Please contact cymmetri administrator.</td></tr><tr><td>APPLICATION_CONFIG_NOT_FOUND</td><td> Application Configuration not found. Please contact cymmetri administrator.</td></tr><tr><td>SAMLREQUEST_NOT_PRESENT_IN_REQUEST</td><td> SAML Request is not present in Request. Please contact cymmetri administrator.</td></tr><tr><td>CONFIGURED_REQUEST_ISSUER_AND_SAML_REQUEST_NOT_ISSUER_NOT_MATCH</td><td> Application issuer Configuration does not match. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_REQUEST_ISSUER</td><td> Invalid Request Issuer. Please contact cymmetri administrator.</td></tr><tr><td>IDENTITY_TOKEN_SAML_REQUEST_NOT_FOUND</td><td> Invalid Identity SAML Request Token. Please contact cymmetri administrator.</td></tr><tr><td>IDENTITY_REFRESH_SAML_REQUEST_NOT_FOUND</td><td> Invalid Refresh SAML Request Token. Please contact cymmetri administrator.</td></tr><tr><td>USER_NOT_ASSIGNED_TO_APPLICATION</td><td> User is not associated with the application. Please contact cymmetri administrator.</td></tr><tr><td>SSO_ERROR_SENDING_SAML_RESPONSE</td><td> Error Sending SAML Response. Please contact cymmetri administrator.</td></tr><tr><td>SSO_CONFIG_NOT_FOUND_APPLICATION_ID</td><td> SSO configuration not found for application. Please contact cymmetri administrator.</td></tr><tr><td>SSO_USER_NOT_FOUND</td><td> SSO user found for application. Please contact cymmetri administrator.</td></tr><tr><td>INTERNAL_SERVER_ERROR</td><td> Please contact cymmetri administrator.</td></tr><tr><td>IDP_SSO_JKS_MANAGER_FAILED</td><td> Please contact cymmetri administrator.</td></tr><tr><td>IDP_SSO_CUSTOM_JKS_FAILED</td><td> Please contact cymmetri administrator.</td></tr><tr><td>IDP_SSO_FAILED</td><td> SSO failed for identity provider. Please contact cymmetri administrator.</td></tr><tr><td>SERVICE_PROVIDER_SESSION_NOT_FOUND</td><td> Service provider session not availaible. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SP_INITIATED_REQUEST</td><td> Invalid service provider request. Please contact cymmetri administrator.</td></tr><tr><td>ERROR_PARSING_SAML_SLO</td><td> Error validating saml slo request. Please contact cymmetri administrator.</td></tr><tr><td>SERVICE_PROVIDER_ERROR</td><td> Failed with service provider. Please contact cymmetri administrator.</td></tr><tr><td>EXPIRED_REFRESH_TOKEN</td><td> Refresh token is expired. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_REFRESH_TOKEN</td><td> Invalid refresh token. Please contact cymmetri administrator.</td></tr><tr><td>EMPTY_REFRESH_TOKEN</td><td> Empty refresh token. Please contact cymmetri administrator.</td></tr><tr><td>REFRESH_TOKEN_COOKIE_NOT_PRESENT</td><td> Refresh token cookie not present. Please contact cymmetri administrator.</td></tr><tr><td>APPLICATION_ID_NOT_PRESENT_IN_CONFIG</td><td> Application id not present. Please contact cymmetri administrator.</td></tr><tr><td>APPLICATION_ID_NOT_PRESENT_IN_REQUEST</td><td> Application id is not present in request Please contact cymmetri administrator.</td></tr><tr><td>EXPIRED_SSO_IDENTITY_TOKEN</td><td> SSO identity token is expired. Please contact cymmetri administrator.</td></tr><tr><td>EMPTY_SSO_IDENTITY_TOKEN</td><td> SSO identity token is invalid. Please contact cymmetri administrator.</td></tr><tr><td>REQUEST_ISSUER_FROM_SAML_REQUEST_NOT_PRESNETTITY_TOKEN</td><td> Request issuer is not present in saml request. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SSO_IDENTITY_TOKEN</td><td> Invalid SSO identity token. Please contact cymmetri administrator.</td></tr><tr><td>IDP_SLO_FAILED</td><td> Identity provider single logout failed. Please contact cymmetri administrator.</td></tr><tr><td>BUILD_SLO_REQUEST_FAILED</td><td> Build to failed single logout request. Please contact cymmetri administrator.</td></tr><tr><td>SLO_REQUEST_SEND_FAILED</td><td> Failed to send single logout request. Please contact cymmetri administrator.</td></tr><tr><td>SLO_RESPONSE_SEND_FAILED</td><td> Failed to send single logout response. Please contact cymmetri administrator.</td></tr><tr><td>ERROR_PERSISTING_SLO_REQUEST</td><td> Failed to persist single logout request. Please contact cymmetri administrator.</td></tr><tr><td>SLO_RESPONSE_SAML_ATTRIBUTE_VALIDATION_FAILED</td><td> Failed to validate single logout response attribute. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_SLO_RESPONSE</td><td> Invalid saml single logout response. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_SAML_SLO_MESSAGE</td><td> Invalid saml single logout message. Please contact cymmetri administrator.</td></tr><tr><td>SLO_REQUEST_VALIDATION_FAILED</td><td> Failed to validate single logout request. Please contact cymmetri administrator.</td></tr><tr><td>SLO_RESPONSE_VALIDATION_FAILED</td><td> Failed to validate single logout response. Please contact cymmetri administrator.</td></tr><tr><td>REMOVE_USER_BEFORE_APPLICATION</td><td> Users should get removed before removing the application.</td></tr><tr><td>PROVSRVC.REMOVE_USER_BEFORE_APPLICATION</td><td> Users should get removed before removing the application.</td></tr><tr><td>PAMSRVC.INVALID_ARGUMENTS</td><td> AD Parameter not found</td></tr><tr><td>PAMSRVC.IMPORT_DATA_TO_CSV_FILE_FAILED</td><td> CSV file not generated</td></tr><tr><td>PAMSRVC.UPDATE_AD_USER_PASSWORD_FAILED</td><td> Password update fail</td></tr><tr><td>PAMSRVC.VAULT_USER_ALREADY_AVAILABLE</td><td> Vault user already exist</td></tr><tr><td>PAMSRVC.BREAK_GLASS_NOT_FOUND</td><td> Break Glass Configuration Not Found</td></tr><tr><td>PAMSRVC.SERVER_ALREADY_EXISTS</td><td> Device Already Exists</td></tr><tr><td>DORMANCY_DISABLE_DAYS_EXCEEDED</td><td> Config days exceeded</td></tr><tr><td>PAMSRVC.DORMANCY_DISABLE_DAYS_EXCEEDED</td><td> Config days exceeded</td></tr><tr><td>SAMLSPSRVC.SOME_ERROR_OCCURRED_WORKING_ON_IT</td><td> Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_IDENTITY_PROVIDER_STATUS</td><td> Invalid Identity Provider Status. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_ARGUMENTS</td><td> Please correct Input and try again. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SERVICE_PROVIDER_STATUS</td><td> Invalid Service Provider Status. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.MANDATORY_FIELD_EXCEPTION</td><td> Mandatory Field is Missing. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.TENANT_OR_HOST_NOT_RECEIVED_FROM_NGINX</td><td> Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.TENANT_OR_HOST_PROTO_NOT_RECEIVED_FROM_NGINX</td><td> Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.SOME_IMPERSONATE_ACCESS</td><td> Unauthorized Access. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.SERVICE_PROVIDER_INBOUND_MESSAGE_ERROR</td><td> Invalid SAML Message Received. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE_ASSERTION_VERSION</td><td> Invalid SAML Response Assertion version. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE_ISSUE_INSTANT</td><td> Invalid SAML Response Issue. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE_STATUS</td><td> Invalid SAML Response Status. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE_STATUS_REQUESTER_URI</td><td> Invalid SAML Response Status Requester URI. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE_STATUS_RESPONDER_URI</td><td> Invalid SAML Response Status Response URI. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE_STATUS_VERSION_MISMATCH_URL</td><td> Invalid SAML Response Status Version Mismatch URI. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE</td><td> Invalid SAML Response. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE_DESTINATION</td><td> Invalid SAML Response Destination. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE_VERSION_OR_ASSERTION_VERSION</td><td> Invalid SAML Response Version or Assertion Version. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE_ASSERTION_SUBJECT</td><td> Invalid SAML Response Assertion Subject. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE_ASSERTION_SUBJECT_NAMEID</td><td> Invalid SAML Response Assertion Subject NameId. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE_ASSERTION_ISSUER</td><td> Invalid SAML Response Assertion Issuer. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE_ASSERTION_CONDITION_AUDIENCE</td><td> Invalid SAML Response Assertion Condition Audience. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE_ASSERTION_AUTHNSTATEMENT</td><td> Invalid SAML Response Assertion AuthNStatement. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE_ASSERTION_ATTRIBUTE</td><td> Invalid SAML Response Assertion Attribute. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.MULTIPLE_ASSERTIONS_IN_RESPONSE_NOT_SUPPORTED</td><td> Multiple Assertion in Response Not Supported. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE_ASSERTION_SIGNATURE</td><td> Invalid SAML Response Assertion Signature. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE_SIGNATURE</td><td> Invalid SAML Response Signature. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE_ASSERTION_CONDITION</td><td> Invalid SAML Response Assertion Condition. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE_ASSERTION</td><td> Invalid SAML Response Assertion. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.INVALID_SAML_RESPONSE_ISSUER</td><td> Invalid SAML Response Issuer. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.IDP_CONFIGURATION_NOT_FOUND</td><td> Idp Configuration Not Found. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.SP_ID_IDP_ID_LOGIN_EMPTY</td><td> Service provider or identity provider login not provided. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.SERVICE_PROVIDER_CONFIGURATION_NOT_FOUND</td><td> Service Provider Configuration Not Found. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.ERROR_BUILDING_SAML_AUTHN_REQUEST</td><td> Failed To Build SAML Authentication Request. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.ERROR_PERSISTING_SAML_AUTHN_REQUEST</td><td> Failed To Persist SAML Authentication Request. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.ERROR_SENDING_SAML_AUTHN_REQUEST</td><td> Failed to Send SAML Authentication Request. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.USER_EMAIL_ADDRESS_NOT_PRESENT</td><td> User Email Not Found. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.USER_LOGIN_NOT_PRESENT</td><td> User Login Not Found. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.EMAIL_ADDRESS_DOES_NOT_MATCH</td><td> Email Address does not matching. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.LOGIN_DOES_NOT_MATCH</td><td> Login does not match. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.USER_NOT_AVAILABLE</td><td> User is not present. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.SERVICE_PROVIDER_NOT_FOUND</td><td> Service provider is not found. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.UNAUTHORIZED_ACCESS</td><td> Unauthorized Access. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.UNAUTHORIZED</td><td> Unauthorized Access. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSPSRVC.USER_NOT_FOUND</td><td> User Not found. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.SOME_ERROR_OCCURRED_WORKING_ON_IT</td><td> Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.DATA_NOT_PRESENT</td><td> Application configuration does not exist. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.ARGUMENT_IS_REQUIRED</td><td> Please correct Input and try again. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.APPLICATION_CONFIG_EXISTS</td><td> Application Configuration already exists. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.APPLICATION_CONFIG_NOT_PRESENT</td><td> Application configuration does not exists. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.INVALID_TOKEN</td><td> Invalid token Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.TENANT_NOT_FOUND</td><td> Tenant detail not availaible. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.INVALID_APPLICATION_ID</td><td> Invalid application id. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.APPLICATION_WITH_ISSUER_NOT_FOUND</td><td> Application configuration with issuer not found. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.EXCEPTION_OCCURED_WITH_TENANT_JKS</td><td> Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.EXCEPTION_OCCURED_WITH_TENANT_JKS_KEY_GENERATE</td><td> Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.APPLICATION_NOT_ASSIGNED_TO_USER</td><td> Application is not assigned to the user. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.TENANT_OR_HOST_PROTO_NOT_RECEIVED_FROM_NGINX</td><td> Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.USER_NOT_ASSIGNED_SERVICE_PROVIDER_ERROR</td><td> User is not assigned to the service provider. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.SOMETHING_WENT_WRONG</td><td> Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.SERVICE_PROVIDER_NAMEIDVALUE_MISMATCH_ERROR</td><td> Service provider nameId value does not match with configured application. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.SERVICE_PROVIDER_NAMEID_MISMATCH_ERROR</td><td> Service provider nameId value does not match with configured application. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.TENANT_HOST_NOT_FOUND</td><td> Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.TENANT_OR_HOST_NOT_RECEIVED_FROM_NGINX</td><td> Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.APPLICATION_CONFIG_NOT_FOUND</td><td> Application Configuration not found. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.SAMLREQUEST_NOT_PRESENT_IN_REQUEST</td><td> SAML Request is not present in Request. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.CONFIGURED_REQUEST_ISSUER_AND_SAML_REQUEST_NOT_ISSUER_NOT_MATCH</td><td> Application issuer Configuration does not match. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.INVALID_REQUEST_ISSUER</td><td> Invalid Request Issuer. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.IDENTITY_TOKEN_SAML_REQUEST_NOT_FOUND</td><td> Invalid Identity SAML Request Token. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.IDENTITY_REFRESH_SAML_REQUEST_NOT_FOUND</td><td> Invalid Refresh SAML Request Token. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.USER_NOT_ASSIGNED_TO_APPLICATION</td><td> User is not associated with the application. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.SSO_ERROR_SENDING_SAML_RESPONSE</td><td> Error Sending SAML Response. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.SSO_CONFIG_NOT_FOUND_APPLICATION_ID</td><td> SSO configuration not found for application. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.SSO_USER_NOT_FOUND</td><td> SSO user found for application. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.INTERNAL_SERVER_ERROR</td><td> Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.IDP_SSO_JKS_MANAGER_FAILED</td><td> Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.IDP_SSO_CUSTOM_JKS_FAILED</td><td> Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.IDP_SSO_FAILED</td><td> SSO failed for identity provider. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.SERVICE_PROVIDER_SESSION_NOT_FOUND</td><td> Service provider session not availaible. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.INVALID_ARGUMENTS</td><td> Please correct input and try again. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.INVALID_SP_INITIATED_REQUEST</td><td> Invalid service provider request. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.ERROR_PARSING_SAML_SLO</td><td> Error validating saml slo request. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.SERVICE_PROVIDER_ERROR</td><td> Failed with service provider. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.EXPIRED_REFRESH_TOKEN</td><td> Refresh token is expired. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.INVALID_REFRESH_TOKEN</td><td> Invalid refresh token. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.EMPTY_REFRESH_TOKEN</td><td> Empty refresh token. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.REFRESH_TOKEN_COOKIE_NOT_PRESENT</td><td> Refresh token cookie not present. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.APPLICATION_ID_NOT_PRESENT_IN_CONFIG</td><td> Application id not present. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.APPLICATION_ID_NOT_PRESENT_IN_REQUEST</td><td> Application id is not present in request Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.EXPIRED_SSO_IDENTITY_TOKEN</td><td> SSO identity token is expired. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.EMPTY_SSO_IDENTITY_TOKEN</td><td> SSO identity token is invalid. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.REQUEST_ISSUER_FROM_SAML_REQUEST_NOT_PRESNETTITY_TOKEN</td><td> Request issuer is not present in saml request. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.INVALID_SSO_IDENTITY_TOKEN</td><td> Invalid SSO identity token. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.IDP_SLO_FAILED</td><td> Identity provider single logout failed. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.BUILD_SLO_REQUEST_FAILED</td><td> Build to failed single logout request. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.SLO_REQUEST_SEND_FAILED</td><td> Failed to send single logout request. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.SLO_RESPONSE_SEND_FAILED</td><td> Failed to send single logout response. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.ERROR_PERSISTING_SLO_REQUEST</td><td> Failed to persist single logout request. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.SLO_RESPONSE_SAML_ATTRIBUTE_VALIDATION_FAILED</td><td> Failed to validate single logout response attribute. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.INVALID_SAML_SLO_RESPONSE</td><td> Invalid saml single logout response. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.INVALID_SAML_SLO_MESSAGE</td><td> Invalid saml single logout message. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.SLO_REQUEST_VALIDATION_FAILED</td><td> Failed to validate single logout request. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.SLO_RESPONSE_VALIDATION_FAILED</td><td> Failed to validate single logout response. Please contact cymmetri administrator.</td></tr><tr><td>SAMLSRVC.UNAUTHORIZED</td><td> Unauthorized. Please contact cymmetri administrator.</td></tr><tr><td>INVALID_USER_SESSION</td><td> User login session is invalid</td></tr><tr><td>USER_NOT_CONFIGURED_FOR_EXTERNAL_LOGOUT</td><td> User is not configured for external identity provider logout</td></tr><tr><td>USER_DOES_NOT_HAVE_ANY_ACTIVE_SSO_SESSION</td><td> User does not have any active sso login session</td></tr><tr><td>ISSUE_INSTANT_EXCEPTION</td><td> Invalid user issue instant exception</td></tr><tr><td>NOT_ON_OR_AFTER_EXCEPTION</td><td> Saml attribute is not valid before and after timestamp</td></tr><tr><td>NAME_ID_FORMAT_EXCEPTION</td><td> Invalid user name id is not valid</td></tr><tr><td>SESSION_INDEX_EXCEPTION</td><td> User login session index is invalid</td></tr><tr><td>DESTINATION_EXCEPTION</td><td> Saml attribute destination is invalid</td></tr><tr><td>IDENTITY_PROVIDER_EXCEPTION</td><td> External identity provider is invalid</td></tr><tr><td>IN_RESPONSE_TO</td><td> Saml attribute in response attribute is invalid</td></tr><tr><td>ISSUER_EXCEPTION</td><td> Saml attribute issuer is invalid</td></tr><tr><td>DATALOGGER.ALREADY_ACTIVATED</td><td> Already activated</td></tr><tr><td>DATALOGGER.ALREADY_DEACTIVATED</td><td> Already deactivated</td></tr><tr><td>DATALOGGER.SYSLOG_CONFIG_TEST_FAILED</td><td> Syslog configuration test failed</td></tr><tr><td>DATALOGGER.SYSLOG_CONFIG_NOT_FOUND</td><td> Syslog configuration not found</td></tr><tr><td>PAM_CONFIG_DATA_NOT_FOUND</td><td> Pam Configuration data not found</td></tr><tr><td>PAM_INVALID_CONFIG</td><td> Invalid Pam Configuration found</td></tr><tr><td>PAMSRVC.INTERNAL_ERROR</td><td> Invalid password. Please try again</td></tr><tr><td>PAMSRVC.PAM_CONNECTION_FAIL</td><td> Connection Fail</td></tr><tr><td>PAMSRVC.CONNECTION_FAILED</td><td> Connection Fail</td></tr><tr><td>REPORT.INVALID_ARGUMENTS</td><td> Please correct the input and try again</td></tr><tr><td>PROVSRVC.PASSWORDFILTER_AND_APPLICATION_DOES_NOT_SAME</td><td> Filtered application and included/excluded cannot be the same</td></tr><tr><td>PROVSRVC.PASSWORDFILTER_ALREADY_CONFIGURED</td><td> Application is already configured for password filter</td></tr><tr><td>dagsrvc.INVALID_ARGUMENTS</td><td> Invalid argument.</td></tr><tr><td>dagsrvc.INVALID_ARGUMENTS</td><td> Invalid argument.</td></tr><tr><td>dagsrvc.SERVER_NAME_ALREADY_EXIST_EXCEPTION</td><td> Server name already exit.</td></tr><tr><td>dagsrvc.ROOT_LOCATION_NOT_FOUND</td><td> Server details not found.</td></tr><tr><td>DAGSRVC.DAG_SHARED_SERVER_ALREADY_EXISTS</td><td> Server Configuration already exist</td></tr><tr><td>DAGSRVC.DAG_SHARED_SERVER_NOT_FOUND</td><td> One or more shared servers not found</td></tr><tr><td>PROVSRVC.APPLICATION_ROLE_NOT_FOUND</td><td> Application Role not found</td></tr><tr><td>PORTAL.EXPIRY_DATA_NOT_FOUND</td><td> Expiry data not found</td></tr><tr><td>PORTAL.EXPIRED_LINK</td><td> Link has been expired</td></tr><tr><td>REGSRVC.ACCOUNT_NOT_ACTIVE</td><td> Tenant account inactive. Please contact support</td></tr><tr><td>USRSRVC.IMPORT_SCHEMA_NOT_FOUND</td><td> Import  template  not found</td></tr><tr><td>SLFSRVC.OPERATION_NOT_ACTIVE</td><td> Operation not configured</td></tr><tr><td>WKFLSRVC.WORKFLOW_PREFERENCE_CONFIG_NOT_FOUND</td><td> Workflow Preference Config not found</td></tr><tr><td>USRSRVC.GROUP_ALREADY_ASSIGN_TO_USER</td><td> Group Already Assigned to User.</td></tr><tr><td>USRSRVC.USER_INACTIVE_CONFIG_NOT_FOUND</td><td> Inactive User Config not found</td></tr><tr><td>UTILSRVC.TEAMS_CONFIG_ALREADY_EXIST</td><td> Teams Config already exist</td></tr><tr><td>UTILSRVC.TEAMS_CONFIG_NOT_FOUND</td><td> Teams Config Not Found</td></tr><tr><td>PAMSRVC.RULE_CONFIGURE_ALREADY_EXIST</td><td> Configuration already exists</td></tr><tr><td>PAMSRVC.EMPTY_CONDITION_EXCEPTION</td><td> Empty Condition exception</td></tr><tr><td>SLFSRVC.INVALID_MANAGER_EXCEPTION</td><td> Invalid Manager</td></tr><tr><td>SLFSRVC.INVALID_MANAGER</td><td> Invalid Manager</td></tr><tr><td>SLFSRVC.USER_NOT_FOUND</td><td> User not found. Please try again.</td></tr><tr><td>WKFLSRVC.SELF_APPROVAL_CONFIG_EXIST</td><td> Self Approval config already exists</td></tr><tr><td>WKFLSRVC.SELF_APPROVAL_CONFIG_NOT_FOUND</td><td> Self Approval config not found</td></tr><tr><td>MFASRVC.RESEND_PERIOD_NOT_ALLOWED</td><td> Please wait we are enabling resend operation</td></tr><tr><td>MFASRVC.RESEND_TIME_EXCEED</td><td> Allowed resend attempt exceed please try after some time</td></tr><tr><td>ANALYTICS.INVALID_LOG_ARGUMENTS</td><td> Invalid arguments</td></tr><tr><td>ANALYTICS.UNAUTHORIZED</td><td> Unauthorized. Please contact cymmetri administrator.</td></tr><tr><td>ANALYTICS.ALREADY_ACTIVATED</td><td> Already activated</td></tr><tr><td>ANALYTICS.ALREADY_DEACTIVATED</td><td> Already deactivated</td></tr><tr><td>DATALOGGER.ALREADY_EXISTS</td><td> Already exists</td></tr><tr><td>DATALOGGER.CONNECTION_FAILED</td><td> Connection Fail</td></tr><tr><td>DATALOGGER.FORBIDDEN</td><td> Please contact system administrator.</td></tr><tr><td>DATALOGGER.INVALID_ARGUMENTS</td><td> Invalid arguments</td></tr><tr><td>DATALOGGER.SYNC_NOT_SUPPORTED</td><td> Sync not supported</td></tr><tr><td>ANALYTICS.SYSLOG_CONFIG_NOT_FOUND</td><td> Syslog configuration not found</td></tr><tr><td>ANALYTICS.SYSLOG_CONFIG_TEST_FAILED</td><td> Syslog configuration test failed</td></tr><tr><td>DATALOGGER.UNAUTHORIZED</td><td> Unauthorized. Please contact cymmetri administrator.</td></tr><tr><td>REPORT.ALREADY_ACTIVATED</td><td> Already activated</td></tr><tr><td>REPORT.ALREADY_DEACTIVATED</td><td> Already deactivated</td></tr><tr><td>REPORT.ALREADY_EXISTS</td><td> Already exists</td></tr><tr><td>ANALYTICS.CONNECTION_FAILED</td><td> Failed to send report.</td></tr><tr><td>REPORT.CONTENT_NOT_FOUND</td><td> Content not found</td></tr><tr><td>REPORT.EMAIL_EXISTS</td><td> Email already exists</td></tr><tr><td>ANALYTICS.EMAIL_NOT_EXISTS_EXCEPTION</td><td> User Email Not Found. Please contact cymmetri administrator.</td></tr><tr><td>REPORT.FORBIDDEN</td><td> Please contact system administrator.</td></tr><tr><td>ANALYTICS.INVALID_ARGUMENTS</td><td> Please correct the input and try again</td></tr><tr><td>REPORT.INVALID_CRON_EXPRESSION</td><td> Invalid cron expression</td></tr><tr><td>REPORT.INVALID_FREQUENCY_CONFIG</td><td> Invalid frequency config</td></tr><tr><td>REPORT.INVALID_REPORT_CONFIG</td><td> Invalid report config</td></tr><tr><td>REPORT.INVALID_SCHEDULER_TASK_EXECUTION_ID</td><td> Invalid schedular task execution ID</td></tr><tr><td>REPORT.REPORT_BATCH_TASK_NOT_FOUND</td><td> Batch task not found</td></tr><tr><td>REPORT.REPORT_EXISTS_EXCEPTION</td><td> Report already exists</td></tr><tr><td>REPORT.REPORT_NOT_FOUND</td><td> Report not found</td></tr><tr><td>REPORT.SEND_EMAIL_FAILED_EXCEPTION</td><td> Email Sending failed</td></tr><tr><td>REPORT.UNAUTHORIZED</td><td> Please contact cymmetri administrator.</td></tr><tr><td>RISKENGINE.ALREADY_ACTIVATED</td><td> Already activated</td></tr><tr><td>RISKENGINE.ALREADY_DEACTIVATED</td><td> Already deactivated</td></tr><tr><td>RISKENGINE.ALREADY_EXISTS</td><td> Already exists</td></tr><tr><td>RISKENGINE.CONNECTION_FAILED</td><td> Connection Fail</td></tr><tr><td>RISKENGINE.CONNECTOR_NOT_AVAILABLE</td><td> Connector not available</td></tr><tr><td>RISKENGINE.FORBIDDEN</td><td> Please contact cymmetri administrator.</td></tr><tr><td>RISKENGINE.INVALID_ARGUMENTS</td><td> Invalid arguments</td></tr><tr><td>RISKENGINE.INVALID_RISK_SYNC_TASK_STATUS</td><td> Invalid risk sync task status</td></tr><tr><td>RISKENGINE.NO_MAPPING_FOUND</td><td> No mapping found</td></tr><tr><td>RISKENGINE.RISK_CONFIG_NOT_FOUND</td><td> Risk config not found</td></tr><tr><td>RISKENGINE.RISK_NOT_FOUND</td><td> Risk not found</td></tr><tr><td>RISKENGINE.RISK_SYNC_TASK_IN_PROGRESS</td><td> Risk sync task in progress</td></tr><tr><td>RISKENGINE.RISK_SYNC_TASK_NOT_IN_PROGRESS</td><td> Risk sync task not in progress</td></tr><tr><td>RISKENGINE.UNAUTHORIZED</td><td> Please contact cymmetri administrator.</td></tr><tr><td>RISKENGINE.UNSUPPORTED_FIELD</td><td> Field not supported</td></tr><tr><td>RISKENGINE.UNKNOWN</td><td> Please contact cymmetri administrator.</td></tr></tbody></table>


# Help

The Cymmetri Help Page serves as a vital resource, offering users a comprehensive documentation hub that breaks down all the features and provides step-by-step configurations for various functionalities.

To access this valuable documentation, you can visit [https://help.cymmetri.io ](https://help.cymmetri.io)directly. Alternatively, you can simply click on the help icon located at the bottom left of your Cymmetri tenant screens.

#### Key Features of the Help Page:

1. **Comprehensive Feature Explanation:** The Cymmetri Help Page covers all the features of the platform straightforwardly. Whether you are a beginner or an experienced user, you can find detailed explanations of each feature, ensuring you have a clear understanding of its purpose and functionality.
2. **Step-by-Step Configurations:** One of the highlights of the Help Page is its provision of step-by-step configurations for various features. This means you can follow a simple, structured guide to set up and customize different aspects of Cymmetri according to your specific needs.
3. **User-Friendly Language:** The documentation is crafted in a manner that balances technical precision with user-friendly language. You won't find unnecessary jargon, making it accessible for users with varying levels of technical expertise.

   <figure><img src="/files/e4Z1aNMe4Is1N0RvnciS" alt=""><figcaption></figcaption></figure>


# Personalization


# General Config

In this section within Cymmetri, a range of general or broad configuration settings and options are managed. These settings encompass various foundational configurations that affect the overall behavior of Cymmetri.

<figure><img src="/files/GlieUrpIgYwZjuhvQQfY" alt=""><figcaption></figcaption></figure>

There are different system configurations in Cymmetri mentioned below:

#### Time Based&#x20;

In the Time-Based configuration, system administrators can determine whether the system will send repeated notifications to users based on the number of days remaining, as specified in the 'Send Notifications before' field. This occurs when an application is assigned to the user as a time-based application and is about to expire.

<figure><img src="/files/dKI6QwICRRP7RJAs3tqt" alt=""><figcaption><p>Time Based Config </p></figcaption></figure>

#### Email Config

These settings and configurations within Cymmetri are specifically related to the management and customization of email-related functionalities. This configuration area allows administrators to set up, manage, and customize the email communications as per the organization's needs.

<figure><img src="/files/Li9BZRidv3vAdKg7r1cW" alt=""><figcaption><p>Email Config </p></figcaption></figure>

#### **Archive Config**

Within the Archive Config section, administrators have the ability to determine the duration a user remains suspended before transitioning to the archived users' section. This can be specified using the "Archive After" setting.

<figure><img src="/files/HzfR7GTZF4EVsqRz59wE" alt=""><figcaption></figcaption></figure>

#### **Scheduler Integration**

The system incorporates a scheduler feature, enabling administrators to automate the transition of users from the suspended state to the archived state. The scheduler runs within defined time frames, streamlining the management of user statuses.

As an example, if the "User Archive After" configuration is set to 0 days, a user will promptly move to the archived users section upon suspension, and if it is set to a higher number it will wait for the configured number of days before moving the user to archive. This allows for flexibility in tailoring user management to specific organizational needs.

<figure><img src="/files/ULy7wDhVbBX2lFOxt9wD" alt=""><figcaption></figcaption></figure>

#### Workflow Preference Config&#x20;

Within the Workflow Preference Config, administrators have the ability to specify the visibility and editability of workflows associated with user access requests for a particular application. This setting allows for tailored control over how approvers interact with the configured workflow.

#### **Visible to the User:**

When this option is selected, approvers for the requested application are visible to the user initiating the access request. Transparency is maintained throughout the workflow process.&#x20;

#### **Hidden from the User:**

Opting for this configuration ensures that approvers for the requested application remain hidden from the user. The workflow operates discreetly in the background without user visibility.&#x20;

#### **Editable by the User:**

If this preference is chosen, users initiating access requests have the ability to select approvers based on their availability, providing a more dynamic and user-centric workflow experience.&#x20;

This functionality applies if a workflow has been configured for the specified application, offering flexibility in managing user access requests in alignment with organizational requirements.

<figure><img src="/files/u7ryDp4Tp8kB63oP88sL" alt=""><figcaption></figcaption></figure>

The approvers mapped in the workflow can only be edited only if they are part of the "user list"  in workflow configurations.&#x20;

<figure><img src="/files/LqFDJMZgQUtAFt6o2Nic" alt=""><figcaption></figcaption></figure>

In conclusion, if the workflow preference config is set to Editable, the requester will only be able to select the approver from the workflow if the approvers are part of a user list.

#### Reset Password Config

The administrators have a centralized control panel to define how a user's manager can perform password resets. This feature streamlines the process while ensuring security and flexibility.

<figure><img src="/files/SO1lLqvXCZFmH1WsJX78" alt=""><figcaption></figcaption></figure>

The administrator has three distinct options for configuring the password reset process, allowing them to choose a method that best fits the organization's security policies and workflow.

<figure><img src="/files/YryCIjDiDds3tC13Iv4E" alt=""><figcaption></figcaption></figure>

* **Generate Password**: This option allows the user's manager to generate a random, one-time password. The manager must then securely communicate this password to the end-user, who is required to use it for their next login and change it to a new, permanent password immediately. This method ensures that the manager does not have access to the user's long-term password.
* **Generate Password and Send to User's Email**: With this option, the manager triggers the password reset, and the system automatically generates a new password and sends it directly to the user's registered email address. This eliminates the need for the manager to manually transmit the password, reducing the risk of human error and improving efficiency.
* **Send Reset Password Link to User's Email**: This is the most secure option. The manager initiates the process, but instead of a password, the system sends a secure, time-sensitive "Reset Password" link to the user's email. The user must click the link to create a new password, ensuring that only they have access to their account and that the process is compliant with modern security best practices.

To add a layer of security and prevent unauthorized password resets, administrators can enable the "OTP required" setting. When this is activated, a one-time password (OTP) is sent to the user's registered mobile number before the password reset can be finalized. This ensures that the user is the legitimate owner of the account before any password changes are applied, guaranteeing that only the right person's password is being reset.

For understanding how the admin resets the password, refer to [User Details](/identity-hub/managing-users-and-groups/user-detail#reset-password).

#### **User Decommission Config**&#x20;

<figure><img src="/files/nHjOsKFD8tw18gZu3n4C" alt=""><figcaption><p>User Decommission Config </p></figcaption></figure>

The User Decommission Config is a vital feature in Cymmetri, allowing administrators to automate user decommissioning based on login activity.&#x20;

In this configuration, actions are triggered  if the user hasn't logged in to Cymmetri in N number of days

**Config Days**: Set the threshold for user inactivity in terms of days. Users who have not logged in for the specified duration will be subject to the defined actions.

**Actions**: Choose from three distinct actions to be taken when the specified inactivity threshold is reached:&#x20;

* None: No action will be taken based on user inactivity.
* Inactive: Users exceeding the configured inactivity period will be marked as inactive.&#x20;
* Delete: Users who have not logged in for the specified duration will be suspended from the system.

#### **Syslog Configuration**

<figure><img src="/files/plEoonUWSyi7T2p575Ol" alt=""><figcaption><p>Syslog Configuration</p></figcaption></figure>

Syslog configuration in Cymmetri allows for the seamless integration of logging and event information with external Syslog servers. By defining specific parameters, administrators can ensure that critical system events, user access information, and other relevant data are transmitted in real-time to a Syslog server.

**Syslog Config fields:**

1. Syslog Name - Assign a unique name to this Syslog configuration
2. App Name - Specify the application name associated with this Syslog configuration.
3. Server Host Name - Enter the hostname or IP address of the Syslog server that will receive log messages
4. Server port - Define the port number on the Syslog server where log messages will be sent.
5. Protocol - Choose the preferred protocol for Syslog communication - TCP or UDP.

In configuring these parameters, administrators tailor Cymmetri's interaction with external Syslog servers, optimizing the logging process to meet organizational needs.

#### **Webhooks Configuration**

Webhooks in Cymmetri's admin module provide a powerful mechanism for real-time communication and integration with external applications or services. Administrators can configure various webhook settings to enhance the system's functionality and streamline interactions with external components.

<figure><img src="/files/jogRN3jmHt0UoosRDjxP" alt=""><figcaption><p>Webhooks Configuration</p></figcaption></figure>

#### **Webhook Configs:**

1. Protocol - Communication protocol - (Static field)
2. Method - HTTP method for webhook requests - (Static Set to post)
3. Server - Enter the server or endpoint URL where the webhook payloads will be delivered.
4. Server Context path - provide the context path for the specific service within the server.
5. Secret - This secret key, known to both Cymmetri and the external service, helps authenticate the webhook requests.
6. Token Expiry Minutes - Define the duration (in minutes) for which authentication tokens associated with webhook requests are valid.

#### **Application Request Config**

This setting determines if a user can initiate requests for new applications through the Cymmetri self-service page.&#x20;

When the status is active, the user will see the "Add New" button on the "My Access" page within the "My Workspace" section. By clicking this button, the user can submit an access request for additional applications.

<figure><img src="/files/Jl5xuaqX0eFHN9RhsTM3" alt=""><figcaption><p>Application Request Config </p></figcaption></figure>

#### User Threshold Config:

The User Threshold Config in Cymmetri primarily includes three key functions — Create Count, Update Count, Delete Count, and Send threshold notifications to. These define the maximum number of user creation, modification, and deletion operations permitted within the system in a single day, ensuring controlled provisioning and preventing unintended bulk changes.

<figure><img src="/files/BFweW7DWE30YX1oE5fcI" alt=""><figcaption></figcaption></figure>

**Create Count**: Sets the maximum number of new user accounts that can be generated.

<figure><img src="/files/lszyKEILUKtS4twSq5Ih" alt=""><figcaption></figcaption></figure>

**Update Count**: Defines the upper limit for modifications or changes to existing user profiles.

<figure><img src="/files/Hxm8DYg54JVXX9ZVqWEN" alt=""><figcaption></figcaption></figure>

**Delete Count**:  Establishes the cap on how many user accounts can be removed.

<figure><img src="/files/0Fq2TuTqrs3ZqYejluUN" alt=""><figcaption></figcaption></figure>

**Threshold Notifications**: You can configure who should be notified when the threshold is exceeded. Notification will be sent via email.

<figure><img src="/files/rUhTqsUiiBvnnCf6WCIm" alt=""><figcaption></figcaption></figure>

#### Recommendation Config:

The recommendation configuration defines how the engine generates, manages, and displays application or role suggestions for users during campaigns and workflows. It ensures recommendations are personalized using user attributes, access history, and peer behavior, while maintaining compliance through segregation of duties checks. The configuration also allows dynamic recalculation of scores when user data changes, provides flexibility to enable or disable recommendations with corresponding updates in the UI and history, supports multiple tenants, and retains recommendation history for reporting even if recommendations are later disabled.\
\
1\. **Recommendation Engine in Campaign:**

<figure><img src="/files/lQwLbNEaOwk7k8Co8uAG" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/6wLOxsN4wenJyG9ll6kH" alt=""><figcaption></figcaption></figure>

2. **Recommendation Engine in Approver Inbox:**

<figure><img src="/files/jJyG8CWEXwOiLcUqqFtj" alt=""><figcaption></figcaption></figure>

#### External SOD Checks Config:

The External SoD Checks Config enables configuration of segregation-of-duties checks, webhook connections, and workflows to detect, notify, and manage access violations during application assignments. The Webhooks Config in Cymmetri’s External SoD Service is used to establish connections with external systems or services. It allows the platform to send real-time event notifications (such as SoD violations or workflow triggers) to defined webhook endpoints. When All Applications is selected, External SoD checks will run for every application, except those explicitly listed in the Excluded section, which will be ignored during violation detection.

<figure><img src="/files/QzD8THp3P5qWkIvZAxk6" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/MVCV2GC5u9fa1il2L9wv" alt=""><figcaption></figcaption></figure>

**Application Assignment with role during External SOD Checks**: When a user is assigned an application along with a specific role, the system evaluates the assignment against configured External SoD rules.

<figure><img src="/files/dPbwVASytZgeh4U507tf" alt=""><figcaption></figcaption></figure>

**Multiple SOD Violations Detected**: It indicates that a user’s application or role assignment has triggered more than one segregation-of-duties conflict, all of which are captured and sent for review through the workflow process.

<figure><img src="/files/r9mXvO2dL8PcpzPXw29T" alt=""><figcaption></figcaption></figure>

**Inbox Violations**: Segregation-of-duties conflicts detected during application or role assignments, which are delivered to the user’s or approver’s inbox for review and necessary action.

<figure><img src="/files/qulh6qvDF7Diw6njIo6f" alt=""><figcaption></figcaption></figure>

**Workflow Approver View**: It is the interface where approvers can review, approve, or reject access requests that have triggered segregation-of-duties violations, ensuring proper compliance before access is granted.

<figure><img src="/files/BLRDw2YztUvQdvkzTF19" alt=""><figcaption></figcaption></figure>

#### Captcha Configuration

This integrated advanced CAPTCHA validation capabilities bolsters the security against automated threats and bot-based attacks. The platform now supports two distinct methods, providing administrators with a flexible approach to securing user interactions.

#### Supported CAPTCHA Methods

* **hCaptcha**: This method is a privacy-focused and widely adopted alternative to traditional CAPTCHA. It requires users to perform a simple task (e.g., identifying objects in an image) to prove they are human, effectively blocking bots while maintaining user privacy.
* **Traditional CAPTCHA**: This classic method uses distorted text or numbers that users must correctly enter. While this method is effective, it can sometimes be more challenging for users to solve.

These integrations enable Cymmetri to enhance its security posture by providing a robust defense layer, ensuring that user registration and login processes are protected from malicious automated activity.

<figure><img src="/files/5lhXZcus65uGthKM0VAO" alt=""><figcaption></figcaption></figure>

From this menu, the administrator has two options:

1. **hCaptcha Type**: Selecting this option enables hCaptcha validation, which utilizes simple, interactive tasks for user verification.
2. **Traditional CAPTCHA**: Choosing this option will implement the classic method of using distorted text.

<figure><img src="/files/Jp8NQ9pCYq0H3ljchZEx" alt=""><figcaption></figcaption></figure>

The administrator can then save the configuration. Below is an example of what the traditional CAPTCHA looks like to an end-user.

<figure><img src="/files/FCMZlseJuImnQPyv7b0w" alt=""><figcaption></figcaption></figure>


# Admins

Cymmetri platform has six different admin roles with various levels of access to the various menus and resources on the administration portal of Cymmetri.

In addition to these six admin roles, Cymmetri also supports three different privileged user roles that grant varying levels of access (read, write, report) to privileged users within Cymmetri.

<figure><img src="/files/npdYYq63WA8g4U1u3AQ7" alt=""><figcaption></figcaption></figure>

### Administrators

The various admin roles on the Cymmetri Identity Platform may be described as follows:

#### Organization Administrator&#x20;

This is the so-called 'super admin' administrator role in the Cymmetri platform. Administrators with this role have the authorization to modify any settings or make changes to the tenant.

#### Domain Administrator&#x20;

This is a slightly less privileged administrator. Most tenant-wide system settings, such as the configuration of SMS and email providers (when configured by the tenant), are restricted for domain administrators. All other configurations can be viewed and edited by administrators with the Domain Administrator role.

#### Application Administrator&#x20;

An administrator with the role of Application Administrator has access to Identity Hub configurations, including Application, User, and Group configurations. The Application Administrator can map users and groups to applications and can edit all configurations related to Application Management.

#### Report Administrator&#x20;

An administrator with the role of Report Administrator has access to the Reports menu, which includes the ability to view, modify, and add new reports.

#### Help Desk Administrator&#x20;

The Helpdesk administrator has access to a very limited set of administrative functionalities, such as resetting the password of the end-user, removing configured Multifactor authentication options, and other such common use cases.

#### Read Only Administrator&#x20;

All administrative users have editing access to the various administrative sections of the Cymmetri platform. However, administrators with the "Read Only Administrator" role do not have editing access to any of the settings or configurations; they only have "Read Only" access to the administrative section.

#### PAM Write Access

PAM Write Access in Cymmetri grants users the privilege to connect to servers via RDP or SSH and perform write or modification actions on those servers. Users with PAM Write Access have the ability to make changes, update configurations, and perform tasks that involve altering data or settings on the connected servers. This access level is typically assigned to administrators and IT personnel responsible for making configuration changes or updates on various servers within the Cymmetri environment.

#### PAM Read Access

PAM Read Access provides users with the ability to connect to servers using RDP or SSH and view the content and configurations on those servers. However, users with PAM Read Access do not have the authority to make modifications or changes to the server settings or data. This level of access is suitable for individuals who need to monitor server activities, check logs, or retrieve information from servers without the need to alter any server configurations.

#### PAM Report Access

PAM Report Access is designed for users who require access to PAM-related reports without the need to connect to servers via RDP or SSH directly. Users with PAM Report Access can generate and access reports that provide insights into server activities, access logs, or other relevant data within Cymmetri. Such users can also configure schedulers to send timely reports to various other users. This level of access is beneficial for auditors, compliance teams, or individuals focused on analyzing server-related information for reporting and auditing purposes.

### Adding a New Admin

Follow the steps mentioned below to promote a user as an admin in the Cymmetri platform.

Click on the Configuration menu on the right-hand side&#x20;

<figure><img src="/files/JAq20lPdc2khlZaX2VOS" alt="" width="184"><figcaption></figcaption></figure>

Now, click on the Admins sub-menu within the Configuration menu

<figure><img src="/files/yNMw0Lv65FABXwHcgrPN" alt=""><figcaption></figcaption></figure>

Click on the "**+Add New**" button to add a new administrator<br>

<figure><img src="/files/Yu5gPHhDpyHeCZeiT1nO" alt=""><figcaption></figcaption></figure>

To assign an administrator role to a user, search for the user and then click the 'Assign' button.

<figure><img src="/files/dcwUKE7IRvNPfycDHOpQ" alt=""><figcaption></figcaption></figure>

Select the chosen administration role and click on Save

<figure><img src="/files/EFsuzbiSDjF6pSAwzKx0" alt=""><figcaption></figcaption></figure>

The administrator has been assigned the role of “Report Administrator”.

#### All Admins&#x20;

All admins is a section where various Cymmetri admins are displayed to the admin user&#x20;

<figure><img src="/files/95Gvy4Hw5dkEBSjoYC6W" alt=""><figcaption></figcaption></figure>


# Banners

The Banner Management feature allows you to display customizable messages or images to users. These banners can be configured to appear either on the login page (before a user authenticates) or within the user portal (after a user logs in). You can define a name, a start and end date, visibility options, and an active status toggle for each banner. This is useful for sharing announcements, reminders, or policy updates with specific audiences.

**Prerequisites**:

To configure a banner, ensure you have the following:

* **Image Files**: You can upload up to five images. They must be in JPEG, PNG, or JPG format and have a maximum file size of 500 KB each.
* **Filenames**: Each image filename can be up to 30 characters long.
* **Targeting Conditions**: For banners shown After Login, you can set conditions using user attributes such as User Type (e.g., "Employee") or Department (e.g., "HR"). You can use AND/OR logic to create complex rules.

<figure><img src="/files/RloNIE6BfSO0uiRh9KxD" alt=""><figcaption></figcaption></figure>

#### Configuration Steps for Banner:

**Step 1: Create a New Banner**

1. Navigate to the Configurations section.
2. Click on Add Banner.

<figure><img src="/files/9DwqJEIDzRe8p3damtiW" alt=""><figcaption></figcaption></figure>

**Step 2: Define Banner Details**

1. Enter a descriptive Name for the banner.
2. Set the Start Date and End Date to control when the banner is active.

<figure><img src="/files/7VYIIry9iWSWONlTWwXG" alt=""><figcaption></figcaption></figure>

**Step 3: Select Banner Visibility**

Choose whether the banner should appear Before Login or After Login.

<figure><img src="/files/OI2VJx69VyqMhjWSti5K" alt=""><figcaption></figcaption></figure>

**After Login Banner:**

* **Upload**: Click to upload an image file. You can use drag-and-drop or a manual upload.

<figure><img src="/files/lH41vyLfSsaPe22kfdEf" alt=""><figcaption></figcaption></figure>

* **URL**: Enter a URL to redirect users to a specific page when they click the banner.

<figure><img src="/files/c53tHhcxLazl65IViuDk" alt=""><figcaption></figcaption></figure>

* **Conditions**: Apply a set of conditions based on user attributes to ensure the banner is only displayed to a targeted group of users. Once configured, the banner will appear as a pop-up after a user logs in. Clicking the banner will redirect them to the specified URL. Users can close the banner by clicking the cross mark and confirming.

<figure><img src="/files/FpKDvFUnl5mjnIfOMw0u" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/QDuWLW0odhZibtp4rwPD" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/Tqen8527E85xgAhv5KAj" alt=""><figcaption></figcaption></figure>

**Before Login Banner:**

* Select the Before Login option and save the changes.

<figure><img src="/files/kebA5HWoLpsnTK69CRij" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/1PNWbzhr0o4BZtz9GQwx" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/GcJaeBJUGzuYfeCd8tu3" alt=""><figcaption></figcaption></figure>

* The banner will be displayed on the login page before any authentication occurs.

  <figure><img src="/files/SnOes8QzCh3L1PNsuhrg" alt=""><figcaption></figcaption></figure>
* Clicking the banner will redirect to the specified URL. Users can dismiss the banner by clicking the cross mark.

<figure><img src="/files/Itysecn9hj872aLXu5a8" alt=""><figcaption></figcaption></figure>


# Masters in Cymmetri

Masters are key-value pairs that can be defined for the entire tenant. The key(name) in this context refers to the label to be shown on the Cymmetri User Interface, and the value is the backend identifier used to reference this field in various processes, rules, and policies defined in the Cymmetri platform.

<figure><img src="/files/RAH5llDxAP1qNLlKRc3v" alt=""><figcaption></figcaption></figure>

Cymmetri platform allows for configuring several masters in the system, the major classification among which are Global masters (which allow for creating master key-value pairs that may be used for various situations, such as creating a new department, designation, and other custom attributes for users in the system) and Zone masters (which are network configurations that may be used to whitelist or blacklist user access onto the platform as well as act as a source for adaptive Multi-factor authentication).

### Global Masters

These are system-wide key-value pairs primarily used to setup key-value pairs referring to various masters as given below:

#### Types of Global Masters:

<table data-full-width="true"><thead><tr><th width="146">Type</th><th>Description</th></tr></thead><tbody><tr><td><strong>Country</strong></td><td>Country key-value pairs are stored in the system, and are available as drop-downs wherever needed in the system - User attributes, Policies and other mappings.</td></tr><tr><td><strong>UserType</strong></td><td>UserType is used as one of the conditions while defining authentication policies and as an input in the rule engine.</td></tr><tr><td><strong>Department</strong></td><td>Department is used as one of the conditions while defining authentication policies and as an input in the rule engine, and also as a user attribute.</td></tr><tr><td><strong>Designation</strong></td><td>Designation is used as one of the conditions while defining authentication policies and as an input in the rule engine, and also as a user attribute.</td></tr><tr><td><strong>RBAC</strong></td><td>RBAC (System Roles) is used as one of the conditions while defining authentication policies and as an input in the rule engine, and also as a user attribute.</td></tr></tbody></table>

### Adding a new Master

Follow the steps below to Add a New Master:

Click on the "**+Add New**" button to add a new master of any category mentioned above.

<figure><img src="/files/0MFIzfV4pfoNhVpgSFnx" alt=""><figcaption></figcaption></figure>

Enter the Name and Value for the new Master, then select the type of master you wish to create and enable the active toggle button to make the master active. Once all values are entered, click on the **Save** button

<figure><img src="/files/zGEQvQMLIkPZQR5RVoxy" alt=""><figcaption></figcaption></figure>

A new Global Master is successfully created in the selected category

<figure><img src="/files/45GCJfYwHrTlbuR1cj6e" alt=""><figcaption></figcaption></figure>

### RBAC Master

The RBAC Master allows the maintenance of role entitlements for the organization.

<figure><img src="/files/XPRH3bQUVpIvPfzD9dbL" alt=""><figcaption></figcaption></figure>

### Zone Masters

Zone masters indicate the network zones that may be used for blacklisting or whitelisting access to the Cymmetri Identity platform deployment. It may also be used for detecting users from certain zones and assigning relevant multi-factor authentication policies.

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003445189/original/mgekYllA80lOO9TAamYZDUuvgGIXO-glEQ.png?1649351539" alt=""><figcaption></figcaption></figure>

**Zone Name:** Used to refer to a zone in other configurations on the Cymmetri platform.

**Inactive/Active:** Toggle button to check whether the zone is active (configurable as a condition for other rules on the Cymmetri platform).

**Gateway IP:** Refers to the Gateway IP address for the network zone.

**Proxy IPs:** Proxy Server IP addresses that may be used to direct to this network or the IP addresses outside of the zone that would indicate a connection from this zone.

**CIDR:** Refers to the CIDR notation of the subnet of the network that this zone refers to. [CIDR Notation](https://en.wikipedia.org/wiki/Classless_Inter-Domain_Routing).

For adding a new Zone Master or for editing an existing one, fill in all the mandatory details on the screen as shown above, click on the enable toggle button, and finally click the “Save” button.

A sample is shown below :

<div align="left"><figure><img src="/files/pFQA3gIpV6Kl4F0na0rJ" alt="" width="389"><figcaption></figcaption></figure> <figure><img src="/files/tfQfknYTUnLCiLbPv2XH" alt="" width="392"><figcaption></figcaption></figure></div>

*Note: This screenshot shows sample/test data only and must not be used in production*

### Grade Master

The **Grade Master**  is a **Global Master** used to define numeric grades that categorize employees and establish hierarchical precedence. Grades are critical for building approval matrices in workflow rules that depend on organizational levels. Here we define **Grade Values** (numbers) and associated **Labels** (descriptions).

### Why numeric grades?

* Numeric grades allow clear **precedence ordering**.
* Lower numbers usually represent higher precedence (e.g., Grade 1 = Director).
* Easy comparison (e.g., Grade 2 > Grade 3) makes it suitable for workflows.
* Avoids ambiguity that text-only labels would create.

### Attributes

| Field           | Description                                                                        | Required |
| --------------- | ---------------------------------------------------------------------------------- | -------- |
| **Grade Value** | Numeric value representing the grade. Determines precedence logic. Must be unique. | Yes      |
| **Label**       | A descriptive label for the grade (e.g., “Manager”, “Executive”).                  | Yes      |
| **Status**      | Active / Inactive toggle. Only active grades can be used in workflows.             | Yes      |

### Configuration

#### Access

Go to **Admin → Configurations → Masters → Grade**.

#### View Grades

The Grade Master page displays a list of existing grades with:

* **Precedence** (from Grade Value)
* **Grade Value**
* **Label**
* **Status**
* **Actions** (Edit option)

<figure><img src="/files/UaP8OV1pyoV5P2BAzRH9" alt=""><figcaption></figcaption></figure>

#### Add a Grade

1. Click **+ Add New**.
2. Enter **Grade Value** (numeric).
3. Enter **Label**.
4. Set **Status** (Active/Inactive).
5. Click **Save**.<br>

   <figure><img src="/files/X2Sw9tP5xEXnRay0RJsH" alt=""><figcaption></figcaption></figure>

#### Edit a Grade

1. Click the **Edit** icon.
2. Update **Grade Label**, or **Status**.
3. Save changes.

<figure><img src="/files/RzZP9HzB0qx6t4azGslk" alt=""><figcaption></figcaption></figure>

### Best Practices

* Keep Grade Values **numeric and unique**.
* Align numbers with your organizational hierarchy (e.g., 1 = most senior).
* Use meaningful **labels** for clarity.
* Set obsolete grades to **Inactive** rather than deleting them.


# Personalize Notification Templates

Notifications are triggered from the Cymmetri platform for various actions occurring on the platform either through direct action by the end-user or by the virtue of some backend action (such as running of a scheduler for a campaign). Cymmetri platform ships with default notification templates listed below-

1. **Mandatory Notifications**

<figure><img src="/files/T9ZF44focqKpY3SGuWLh" alt=""><figcaption></figcaption></figure>

| Template                             | Trigger                                                                           | Usage                                                                                                | Recipient(s)                                                             |
| ------------------------------------ | --------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------ |
| **Access Code Manager Notification** | Triggers when forgot password option used and user does not have email configured | It contains the MFA OTP for the user to enter and reset the forgotten password                       | User's Manager                                                           |
| **Organization Sign-Up**             | Tenant registration                                                               | Sent when a new tenant (organization) is created in the system.                                      | The user performing the registration (initial Organization Admin).       |
| **OTP Notification**                 | OTP-based MFA verification                                                        | Sends a One-Time Password (OTP) along with its expiry details to verify Multi-Factor Authentication. | The user attempting to log in using MFA.                                 |
| **Password**                         | Admin/Manager password generation                                                 | Sends the system-generated password via email for user login.                                        | The user whose password has been generated or reset by an Admin/Manager. |
| **Reset Password**                   | Admin/Manager initiated password reset                                            | Provides a secure reset password link allowing the user to set a new password.                       | The user whose password reset has been initiated.                        |
| **Self Registration**                | User self-registration                                                            | Sends account details along with an activation link/button to activate the newly created account.    | The self-registered user.                                                |

2. **Optional Notifications**

<figure><img src="/files/86MvFpDtxUTGpdbtEGd4" alt=""><figcaption></figcaption></figure>

| Notification Template                                      | Trigger                                                                                                                                        | Usage                                                                                                                                                                                                                                                                                                   | Recipient(s)                                                                                           |
| ---------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------ |
| **Application access approval request**                    | When application provisioing is triggered to a user.                                                                                           | The user (typically a manager or administrator) is being notified that a new access or extension request has been submitted and requires their attention. This message identifies who made the request, which application it’s for, and the specific timeframe they are asking for.                     | Workflow Approver                                                                                      |
| **Application access approval request denied by approver** | When an extension or application has been assigned to a user has been rejected via the workflow trigger.                                       | The user is being notified that their request for application access or an extension was not approved. This message directs them to follow up with their system administrator                                                                                                                           | User who has requested the application/role.                                                           |
| **Application access approval request granted**            | When an extension or application has been assigned to a user succesfully via the workflow trigger.                                             | The user is being notified that their request for application access or an extension has been successfully approved via the workflow approval process. This confirmation specifies the exact timeframe—including the start and end dates—during which the access will be valid.                         | User who has requested the application/role.                                                           |
| **Application assignment**                                 | When an application access assigned to a user.                                                                                                 | The user is being notified that access to a application has been successfully grantedand dynamically adjusts to confirm new assignments, extension approvals, or the start of provisioning, while clearly stating the validity period for the access.                                                   | User who has requested the application/role.                                                           |
| **Application scheduled deprovisioning**                   | When an application access assigned to a user is about to expire.                                                                              | The user is being notified that their access to a specific application is scheduled to be terminated and provides the exact date when the access will end.                                                                                                                                              | User who has requested the application/role.                                                           |
| **Campaign Aborted Email Notification**                    | When a campaign aborts.                                                                                                                        | Notifies relevant stakeholders that the campaign has been aborted.                                                                                                                                                                                                                                      | Configured Campaign Stakeholders in step 4 of the campaign configuration process                       |
| **Campaign End Email Notification**                        | When a campaign is ends manually/automatically.                                                                                                | The user is being notified that a specific access review campaign has officially concluded. This final summary provides the total number of assignments processed, including the exact counts for approvals, revocations, and any tasks that remained pending by the end date.                          | Configured Campaign Stakeholders in step 4 of the campaign configuration process                       |
| Campaign Start Email Notification                          | When a campaign is initiated manually/automatically.                                                                                           | The user is being notified that a specific access review campaign has officially launched and provides the key timeline, including the start date and the expected deadline for completion.                                                                                                             | All users present as approver in a campaign.                                                           |
| Delegation Assignee Notification                           | When a user is been assigned as a delegatee.                                                                                                   | When a user is designated as a delegate, they are notified via the workflow trigger that they have been granted temporary authority to act on behalf of another user.                                                                                                                                   | Delegatee User                                                                                         |
| Delegation User Notification                               | When an existing delegation has been updated.                                                                                                  | When a delegation of authority is modified, the system triggers a notification to inform the recipient that their access permissions have been reassigned for a specific period.                                                                                                                        | Delegating User                                                                                        |
| Flowable Reconciliation Mail                               | Flowable-based reconciliation event triggered                                                                                                  | Notifies configured recipients regarding reconciliation activity status                                                                                                                                                                                                                                 | Configured Recipients                                                                                  |
| Group Campaign Aborted Email Notification                  | When a group campaign has aborted.                                                                                                             | Notifies stakeholders of campaign termination                                                                                                                                                                                                                                                           | Configured Group Campaign Stakeholders                                                                 |
| Group Campaign End Email Notification                      | When a group campaign has ended.                                                                                                               | The user is being notified that a group access review campaign has officially concluded. This message provides a final summary of the results, including the total number of assignments that were approved, revoked, or left pending by the deadline.                                                  | Users whose names are mentioned in step 4 of the campaign configuration process.                       |
| Group Campaign Start Email Notification                    | When a group campaign has initiated.                                                                                                           | The user is being notified that a new group access review campaign has officially launched. This message provides the key details of the campaign, including the total number of assignments, the review mode, and the final deadline for completion.                                                   | All users present as approver in a campaign.                                                           |
| Login Adaptive Failed Notification                         | When a failed adaptive login attempt is done.                                                                                                  | The user is being notified that their account was accessed from a previously unrecognized device. This security alert provides the specific login ID, the IP address used, and the date of the activity so the user can verify the login.                                                               | The users whose adaptive mfa has failed.                                                               |
| Login Failed                                               | When a user performs a failed login attempt.                                                                                                   | The user is being notified of multiple failed login attempts on their account from a specific IP address. This security alert warns the user that their account has either been temporarily locked or is approaching a lockout, providing the number of attempts remaining before access is restricted. | The users whose login has failed.                                                                      |
| MFA Failed Notification                                    | When a user performs a failed MFA.                                                                                                             | The user is being notified of multiple failed MFA attempts on their account. This security alert provides the login ID, IP address, and date of the attempts, while also warning the user if their account is about to be locked or if a lockout has already occurred.                                  | The users whose mfa has failed.                                                                        |
| Mover Notification                                         | When a mover process is inititaed.                                                                                                             | The user is notified that a mover has been triggered and lists the applications that will be removed.                                                                                                                                                                                                   | The users whose mover process is initiated.                                                            |
| Password Expiry Notification                               | When a users password is about to expire in X no. of days.                                                                                     | The user is being notified about the status of their password. This message informs them that their password has either already expired or is about to expire, and it provides the exact date along with a request to update it immediately.                                                            | The users whose password is about to expire.                                                           |
| Reconciliation Aborted                                     | When a reconncilation has been aborted.                                                                                                        | The user is being notified that a reconciliation process was stopped or cancelled before it could finish and provides the exact reason for the interruption and the time the process was aborted.                                                                                                       | The users whose name is present in the applications notification section.                              |
| Reconciliation Completion                                  | When a reconncilation has completed.                                                                                                           | The user is being notified that a reconciliation process has successfully finished and provides the exact end time and a summary of the final results.                                                                                                                                                  | The users whose name is present in the applications notification section.                              |
| Reconciliation Failed                                      | When a reconncilation has failed.                                                                                                              | The user is being informed that the reconciliation process has failed and provides the exact reason for the failure and the time it occurred.                                                                                                                                                           | The users whose name is present in the applications notification section.                              |
| Reconciliation Initiation                                  | When a reconncilation has begun.                                                                                                               | The user is being notified that a reconciliation process has officially started and provides the start time and confirms that the task is currently in progress.                                                                                                                                        | The users whose name is present in the applications notification section.                              |
| Requestee Notification                                     | When the requested action by the requestor has been approved.                                                                                  | The user is being notified about the current status of an application request submitted by a specific requester. This message confirms whether the request was approved or updated                                                                                                                      | The user for whom the request for an application/role is made.                                         |
| Requestor Notification                                     | When a user requests for an action mentioned in workflow for another user.                                                                     | The user is informed about the current status of an application request initiated. It also includes a description of the event.                                                                                                                                                                         | The user has requested for an application/role for a user.                                             |
| Review Assignment Notification                             | <p>When the campaign approver has pending tasks.<br>This is triggered from under the Campaign namely, Pending notification waiting period.</p> | The user has pending campaign assignments that require a review before the specified end date. This notice provides the campaign details and current stage to ensure the required actions are completed on time.                                                                                        | Sent to the reviewer at the start of the campaign.                                                     |
| Reviewer Notification                                      | When the campaign approvers have not taken any actions on the assignments assigned to them.                                                    | The user has pending campaign assignments that require immediate review and action. This summary includes the campaign details and the total number of pending tasks that must be completed before the specified end date.                                                                              | Sent to the reviewer after the number of days configured in pending notification fields have got over. |
| Self Approval Notification                                 | When a self approval is perfomed from under the Workflow Section.                                                                              | When a self-approval request is triggered by a user's own action, the system sends a notification to confirm that the request has been successfully submitted and is being processed.                                                                                                                   | The user who self approved their own request.                                                          |
| User Activation                                            | When a new user is onboarded.                                                                                                                  | An admin added the user to the platform and provided their login credentials. The user must sign in using the provided link within the specified time limit before the access token expires.                                                                                                            | The user who is onboarded into the organization.                                                       |
| User Notification                                          | When a campaign is initiated manually/automatically.                                                                                           | When a reviewer has not yet completed their assigned campaign tasks, the system triggers this reminder to ensure the pending applications are reviewed before the deadline.                                                                                                                             | The reviewer who still has pending reviews in a campaign.                                              |
| User Threshold                                             | When the threshold count exceeds more than set in the User Threshold Config under the Configurations section.                                  | The user exceeded the threshold and must manually increase the limit to continue. Once the limit is adjusted, the process can be retried from the dashboard within 24 hours before the records are automatically archived.                                                                              | The users whose name is mentioned in the User threhold configuration.                                  |
| Workflow Notification                                      | When a workflow with expiry is set.                                                                                                            | When an approval task is pending, the designated reviewer is notified that a specific request requires their attention before the indicated expiration date.                                                                                                                                            | The approver who has to approve the request.                                                           |

*<mark style="color:green;">Please note: The above notifications are available out of the box. The system also allows custom notifications to be triggered for specific events using the Cymmetri Webhooks. The custom action trigger can call an existing Cymmetri notification template or a custom template can be included in the webhook code.</mark>*&#x20;

The default templates may be modified by the administrator using the following process:

1. Access the notification templates menu by clicking on the configuration menu on the left-hand side menu bar and then clicking on the Notification templates pop-up menu.

   <figure><img src="/files/Cv0vW7jGFCxZ6w5dSoyV" alt=""><figcaption></figcaption></figure>
2. Click on the eye icon to preview the corresponding template

<figure><img src="/files/SOjIfNZNkON2shFwaFlA" alt=""><figcaption></figcaption></figure>

3. Values in <> anchor tags and ${} reflect macros.
4. Click on the pencil icon shown above the image to edit the template.<br>

   <figure><img src="/files/iYD6RceiOGrrIwzJatBU" alt=""><figcaption></figcaption></figure>
5. We may treat this template as an email and edit the subject of the email.

   By default, the email notification will be sent to the corresponding affected end-user, but selecting the toggle option for “Send notification to Reporting Manager” will also copy the mail to the Reporting Manager of the affected end-user, allowing for offline follow-up for the notification.<br>

   <figure><img src="/files/OPV3duFMiAmMvmFJrotF" alt=""><figcaption></figcaption></figure>
6. The administrator may edit the HTML using the provided HTML editor to add/change any template button/text/background. The macros required for the particular template are already provided in the sample default notification template.
7. Click on the **Save** button to save the notification template.


# Tenant Branding

Tenant branding in Cymmetri allows you to personalize and enhance the visual identity of your environment. With tenant branding, you can customize the appearance of your platform, including logos, color schemes, and even tailored messages, aligning it with your organization's branding guidelines.&#x20;

This not only creates a cohesive and professional user experience but also reinforces your brand's presence throughout the Cymmetri environment. It's a powerful tool for organizations looking to maintain a consistent and recognizable image while utilizing Cymmetri's identity and management capabilities.

The Cymmetri platform allows a certain level of customization to your tenant from the administration panel. This includes the ability to modify the default Cymmetri branding scheme to your own Organization’s branding scheme.

1. Your Organization Name and Tagline
2. Your Organization Logo
3. Your Organization Branding Colors (Primary, Secondary, Accent Colors)&#x20;

### Configuring your tenant branding

1. To access the branding menu, first click on the Configuration menu on the left-hand side and then proceed by clicking on the Branding menu item.

   <figure><img src="/files/kUcWJI07f6rpxgMa1JwX" alt=""><figcaption></figcaption></figure>
2. Start the configuration by entering your Organization Name and Tag Line
3. Proceed by adding a **Welcome text** and **Welcome Tagline,** and select whether the Cymmetri help icon should be visible to the user or not

   <figure><img src="/files/v2o2aYa29Q60ro9gwW9E" alt=""><figcaption></figcaption></figure>
4. Proceed by adding your URL to the **Website** text box and clicking “Fetch Brand”.
5. If your organization’s branding is available, the logo and the corresponding color scheme will be displayed in the menu below.
6. If your branding is unavailable, you may configure it yourself by uploading your logo and editing your primary color, secondary color, and accent color.
7. Click on the **Save and Sync Server** button to make the branding configuration apply to the entire website.

<figure><img src="/files/cP6Gjn8JluMKPlvTJpCF" alt="" width="563"><figcaption></figcaption></figure>

The configuration will be applied in a few seconds to reflect your branding.

<figure><img src="/files/yYp76TKPvR8EVTKvPvNU" alt=""><figcaption></figcaption></figure>

In Cymmetri, the administrator now has the option to select the "Reset to default theme" button, allowing them to revert to the original theme.


# Custom Attributes

Custom Attributes may be added for all user entities in your Cymmetri Platform. This allows organizations to add custom user attributes that are used across the applications in the organization.&#x20;

For example, your organization has a custom attribute that captures and uses the local language of your employees and vendors to provide local services. This attribute may be stored in your Active Directory and may need to be synchronized to your organization’s other applications during the course of an employee or vendor’s employment.&#x20;

Cymmetri platform allows the administrator to define custom attributes on a tenant-wide level.&#x20;

Custom attributes can be used at various places, like when **creating a user**, **as a filter when searching for users**, and **are visible in the other sections of user info**

<figure><img src="/files/BDJv6ceXsRR5n9ROOCQE" alt=""><figcaption></figcaption></figure>

### Configuring Custom Attributes

1. To start configuring custom attributes, click on the Configurations menu on the left-hand side and then click on the Custom Attributes menu.
2. Click on the **Add New** button to start adding a custom attribute

<figure><img src="/files/A6eN8jPFY77LtiZriwuO" alt="" width="461"><figcaption></figcaption></figure>

2. **Fields to be updated:**

   1. *Name/ Key:* refers to the label assigned to the custom attribute.
   2. *Description:* allows you to provide additional details or notes about the custom attribute for reference and clarity.     &#x20;
   3. *Status:* Allows activation of the custom attribute. Only if it is set to active is the attribute available to use in the User Object.

   *Note: A custom attribute, once created, can only be set to inactive; it cannot be deleted.*


# API Client

API Client Refers to [API Extension](/getting-started/personalization/api-extension).


# Batch Tasks

A Batch Task in Cymmetri is a configurable, automated job designed to perform bulk operations by executing a specific backend API endpoint. These tasks can be scheduled to run at predefined intervals or be triggered manually. They are commonly used for operations like data synchronization, user lifecycle management (e.g., deactivating inactive accounts), and report generation.

#### Prerequisites:

Before you can configure a batch task, you must ensure the following are in place:

* **API Endpoint**: The backend API endpoint that the task will call must be fully developed and operational.
* **Permissions & Authentication**: The API endpoint must have the necessary permissions to perform its intended function, and Cymmetri must be configured with the proper credentials to authenticate with it.
* **Clear Business Logic**: The logic behind the task must be well-defined to ensure it performs the correct operation on the right data set.
* **Manual Testing**: The API endpoint should be manually tested to confirm it works as expected before being integrated into a batch task.

<figure><img src="/files/l4MmvOymj2ZzrJJfHx4y" alt=""><figcaption></figcaption></figure>

**Step 1: Navigate to Batch Tasks**

1. In the Cymmetri platform, go to the Configurations menu.
2. Select Batch Tasks.

<figure><img src="/files/XIXwgJRvuCk0EJAfg5Xd" alt=""><figcaption></figcaption></figure>

**Step 2: Add a New Task**

1. Click the Add Task button to create a new batch task configuration.

<figure><img src="/files/0vRGYsZNNUS72qUytart" alt=""><figcaption></figcaption></figure>

**Step 3: Define Task Details**

1. **Name**: Provide a unique, descriptive name for the task.

<figure><img src="/files/Ik9jDfmt92s6duhII7Nl" alt=""><figcaption></figcaption></figure>

2. **Description**: Enter a brief explanation of the task's purpose.

<figure><img src="/files/g95bRh9rITcALDyeALAU" alt=""><figcaption></figcaption></figure>

3. **Endpoint**: Specify the particular API operation the task will execute.

<figure><img src="/files/OWdcxnwRBzMv6dMLA6sH" alt=""><figcaption></figcaption></figure>

4. **Complete Batch Task URL**: Provide the full URL of the API endpoint.

<figure><img src="/files/ItAr18yvX3EVP66Pyy3P" alt=""><figcaption></figcaption></figure>

**Step 4: Configure Scheduling**

1. Use the toggle switch to enable or disable scheduling.

<figure><img src="/files/Y5tU5aTv6oJSNG9a3gei" alt=""><figcaption></figcaption></figure>

2. If enabled, configure the task's frequency. You can select from options such as daily, weekly, or monthly runs, or create a custom schedule using a CRON expression.

<figure><img src="/files/laLakkbu7YqdroUJWYGc" alt=""><figcaption></figcaption></figure>

3. To generate a custom schedule, use the Generate Cron Expression tool, then click Generate and Apply.

<figure><img src="/files/9vz1q0b9nLKDDmtyqmNn" alt=""><figcaption></figcaption></figure>

4. If disabled, the task will only run when manually triggered.
5. Click Save to finalize the task configuration.

<figure><img src="/files/rZ6z6FlColqnXb3ulFWF" alt=""><figcaption></figcaption></figure>

After a task runs, its status and execution details will be recorded in the Audit Log.

<figure><img src="/files/Baz5xoTKCSocTxfqpcUx" alt=""><figcaption></figcaption></figure>

**Step 5: Execute a Batch Task**

1. To manually run a task, find it in the list of batch tasks.

<figure><img src="/files/bfkS0DJ2uroSpPAZwdSl" alt=""><figcaption></figcaption></figure>

2. Click the edit icon next to the task's name.
3. Select the Run option.
4. To verify the execution, navigate to the Audit Log, where you can view the status and results of the executed batch task.

<figure><img src="/files/YRsraHIwGxiPRxrZY3Et" alt=""><figcaption></figcaption></figure>


# API Extension

Cymmetri framework to extend the out of box use cases and support custom requirements from the platform

### Reference API calls <a href="#id-1d6m2h68bkie" id="id-1d6m2h68bkie"></a>

The following are the APIs calls.

**Important Note:**

### RESTful API – Assigned application search user <a href="#id-3l075l2oyx6c" id="id-3l075l2oyx6c"></a>

**Purpose:** This API is used to create an application hook

**URL: http\://\<tenant\_domain>/api/user/listByApplication**

**Method: POST**

**Example Request:**

|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>curl --location --request POST '<http://api.cymmetri.in/usersrvc/api/user/listByApplication>' \</p><p>--header 'Content-Type: application/json' \</p><p>--header 'Authorization: Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJhZG1pbiIsImRlbGVnYXRlZSI6bnVsbCwiZGVsZWdhdGVlSWQiOm51bGwsImZpcnN0TG9naW4iOmZhbHNlLCJyb2xlcyI6WyJPUkdfQURNSU4iLCJVU0VSIl0sInRlbmFudElkIjoiZ2s0MCIsImV4cCI6MTY0NzAxNzEwNywidXNlcklkIjoiNjE3MDE1YTNjMDQ4MTc1NmI3OThhY2EyIiwiaWF0IjoxNjQ3MDExMTA3fQ.8j711\_L--eQHHfen2GPI1qWCmUWRd4n6O44HCZhuRSo' \</p><p>--data-raw '{</p><p>    "keyword":"shu",</p><p>    "pageNumber": "0",</p><p>    "pageSize": "10",</p><p>    "filter": {</p><p>        "applicationId": "617253cc2fb4b2125b237b75"</p><p>    },</p><p>    "sortDirection": "ASC",</p><p>    "sortOn": \[</p><p>        "id"</p><p>    ]</p><p>}'</p><p> </p> |

**Sample Response:**

**On success:**

`{`

`"success": true,`

`"data": {`

`"content": [`

`{`

`"id": "619ce9a69139ca14885a4717",`

`"displayName": "John Snow",`

`"firstName": "John",`

`"lastName": "Snow",`

`"email": null,`

`"mobile": null,`

`"designation": "Developer",`

`"status": "ACTIVE",`

`"profilePic": null,`

`"login": "john.snow",`

`"initialLoginPending": true,`

`"startDate": null,`

`"endDate": null,`

`"provStatus": {`

`"617253cc2fb4b2125b237b75": "SUCCESS_UPDATE"`

`}`

`}`

`],`

`"pageable": {`

`"sort": [`

`{`

`"direction": "ASC",`

`"property": "id",`

`"ignoreCase": false,`

`"nullHandling": "NATIVE",`

`"ascending": true,`

`"descending": false`

`}`

`],`

`"pageNumber": 0,`

`"pageSize": 10,`

`"offset": 0,`

`"paged": true,`

`"unpaged": false`

`},`

`"last": true,`

`"totalPages": 1,`

`"totalElements": 1,`

`"sort": [`

`{`

`"direction": "ASC",`

`"property": "id",`

`"ignoreCase": false,`

`"nullHandling": "NATIVE",`

`"ascending": true,`

`"descending": false`

`}`

`],`

`"first": true,`

`"number": 0,`

`"numberOfElements": 1,`

`"size": 10,`

`"empty": false`

`},`

`"timestamp": "02-Mar-2022 01:58:57",`

`"message": null,`

`"errorCode": null`

`}`

**`On failure:`**

**`Response 1#`**

`{`

`"data":`` `**`null`**`,`

`"success":`` `**`false`**`,`

`"errorCode": "PROVSRVC.APPLICATION_NOT_FOUND",`

`"message":`` `**`null`**`,`

`"timestamp": "02-Mar-2022 01:59:39"`

`}`

### RESTful API – Assigned application search group <a href="#pcql2x4ovudj" id="pcql2x4ovudj"></a>

**Purpose:** This API is used to get an application hook for the provided application id and type.

**URL: http\://\<tenant\_domain>/api/group/groupListByApplication**

**Method: POST**

**applicationId: Application id**

**Example Request:**

| <p>curl --location --request POST '<http://localhost:9080/api/group/groupListByApplication>' \</p><p>--header 'Tenant: gk16'</p><p>--data-raw '{</p><p>   "filter": {</p><p>       "applicationId": "617253cc2fb4b2125b237b75"</p><p>   },</p><p>   "keyword": "gold",</p><p>   "pageNumber": 0,</p><p>   "pageSize": 10,</p><p>   "sortDirection": "ASC",</p><p>   "sortOn": \[</p><p>       "name"</p><p>   ]</p><p>}'</p> |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |

**Sample Response:**

**On success:**

`{`

`"success": true,`

`"data": {`

`"offset": 0,`

`"pageSize": 10,`

`"totalElements": 1,`

`"totalPages": 1,`

`"elements": [`

`{`

`"id": "621cdbb7776c95564c0313ab",`

`"name": "Gold",`

`"type": "LocalGroup",`

`"description": "Gold group",`

`"ouId": "",`

`"ouName": null,`

`"parentGroupIds": null,`

`"directParentGroupId": null,`

`"userCount": 0,`

`"appCount": 1`

`}`

`],`

`"pageNumber": 0,`

`"sort": {`

`"orders": [`

`{`

`"direction": "ASC",`

`"property": "name"`

`}`

`],`

`"sorted": true`

`}`

`},`

`"timestamp": "03-Mar-2022 05:29:23",`

`"message": null,`

`"errorCode": null`

`}`

**On failure:**

**Response 1#**

`{`

`"data":`` `**`null`**`,`

`"success":`` `**`false`**`,`

`"errorCode": "PROVSRVC.APPLICATION_NOT_FOUND",`

`"message":`` `**`null`**`,`

`"timestamp": "03-Mar-2022 05:29:49"`

`}`

### RESTful API – Application reconciliation pull filter search <a href="#i0xgmz2qxrtb" id="i0xgmz2qxrtb"></a>

**Purpose:** This API is used to list reconciliation pulls for the provided application ID and keyword.

**URL: https\://\<tenant\_domain>/provsrvc/reconciliation/pull/search**

**Method: POST**

**applicationId: applicationId**

**keyword: keyword**

**Example Request:**

|                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>curl --location --request POST '<https://mru18.cymmetri.in/provsrvc/reconciliation/pull/search>' \</p><p>--header 'Tenant: mru18' \</p><p>--data-raw '{</p><p>    "filter": {</p><p>        "applicationId": "614b5d3489ad96554e89e2ab"</p><p>    },</p><p>    "keyword": "",</p><p>    "pageNumber": 0,</p><p>    "pageSize": 10,</p><p>    "sortDirection": "DESC",</p><p>    "sortOn": \[</p><p>        "updatedDateTime"</p><p>    ]</p><p>}'</p> |
|                                                                                                                                                                                                                                                                                                                                                                                                                                                          |

**Sample Response:**

**On success:**

`{`

`"success": true,`

`"data": {`

`"content": [`

`{`

`"id": "621cca3f9423002d41cbbed4",`

`"name": "AD-ADMIN-USERS",`

`"type": "USER",`

`"status": "ACTIVE",`

`"applicationId": "614b5d3489ad96554e89e2ab",`

`"targetSystemSearchQueryFilter": null,`

`"idmRepositoryField": "login",`

`"sourceAttributeName": "cn",`

`"reconType": "PULL",`

`"reconMode": "FILTERED_RECONCILIATION",`

`"reconConditions": {`

`"TARGET_DELETED_IDM_EXISTS": "IGNORE",`

`"TARGET_EXTSTS_IDM_EXISTS": "IGNORE",`

`"TARGET_EXTSTS_IDM_NOT_EXISTS": "PROVISION"`

`},`

`"lastRunDateTime": null,`

`"createdDateTime": "2022-02-28T13:12:31.07",`

`"updatedDateTime": "2022-03-02T12:45:31.069",`

`"version": 2`

`},`

`...`

`...`

`],`

`"pageable": {`

`"sort": [`

`{`

`"direction": "DESC",`

`"property": "updatedDateTime",`

`"ignoreCase": false,`

`"nullHandling": "NATIVE",`

`"ascending": false,`

`"descending": true`

`}`

`],`

`"pageNumber": 0,`

`"pageSize": 10,`

`"offset": 0,`

`"paged": true,`

`"unpaged": false`

`},`

`"last": true,`

`"totalPages": 1,`

`"totalElements": 3,`

`"first": true,`

`"sort": [`

`{`

`"direction": "DESC",`

`"property": "updatedDateTime",`

`"ignoreCase": false,`

`"nullHandling": "NATIVE",`

`"ascending": false,`

`"descending": true`

`}`

`],`

`"numberOfElements": 3,`

`"size": 10,`

`"number": 0,`

`"empty": false`

`},`

`"timestamp": "03-Mar-2022 08:41:03",`

`"message": null,`

`"errorCode": null`

`}`

**On failure:**

**Response 1#**

`{`

`"success": false,`

`"data": null,`

`"timestamp": "03-Mar-2022 09:06:43",`

`"message": null,`

`"errorCode": "INVALID_ARGUMENTS"`

`}`

**Response 2#**

`{`

`"success": false,`

`"data": null,`

`"timestamp": "03-Mar-2022 09:06:43",`

`"message": null,`

`"errorCode": "PROVSRVC.UNKNOWN"`

`}`

### RESTful API – Application reconciliation push filter search <a href="#oozxve3hcfpr" id="oozxve3hcfpr"></a>

**Purpose:** This API is used to list reconciliation push for provided application id and keyword.

**URL: http\://\<tenant\_domain>/reconciliation/push/search**

**Method: POST**

**applicationId: Application Id.**

**keyword : keyword**

**Example Request:**

|                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>curl --location --request POST '<https://mru18.cymmetri.in/provsrvc/reconciliation/pull/search>' \</p><p>--header 'Tenant: mru18' \</p><p>--data-raw '{</p><p>    "filter": {</p><p>        "applicationId": "614b5d3489ad96554e89e2ab"</p><p>    },</p><p>    "keyword": "",</p><p>    "pageNumber": 0,</p><p>    "pageSize": 10,</p><p>    "sortDirection": "DESC",</p><p>    "sortOn": \[</p><p>        "updatedDateTime"</p><p>    ]</p><p>}'</p> |

**Sample Response:**

**On success:**

`{`

`"success": true,`

`"data": {`

`"content": [`

`{`

`"id": "62207b1655a2d10f525dc2bf",`

`"name": "AD-Admin",`

`"type": "USER",`

`"status": "ACTIVE",`

`"applicationId": "614b5d3489ad96554e89e2ab",`

`"idmSearchQueryFilter": {`

`"location": null,`

`"reportingManager": null,`

`"department": null,`

`"designation": null,`

`"group": null,`

`"email": null,`

`"mobile": null,`

`"status": [],`

`"userType": null,`

`"locked": false`

`},`

`"idmRepositoryField": "login",`

`"sourceAttributeName": "cn",`

`"reconType": "PUSH",`

`"reconMode": "FILTERED_RECONCILIATION",`

`"reconConditions": {`

`"IDM_DELETED_TARGET_EXISTS": "IGNORE",`

`"IDM_EXTSTS_TARGET_EXISTS": "IGNORE",`

`"IDM_EXTSTS_TARGET_NOT_EXISTS": "PROVISION"`

`},`

`"lastRunDateTime": null,`

`"createdDateTime": "2022-03-03T08:23:50.963",`

`"updatedDateTime": "2022-03-03T08:23:50.963",`

`"version": 0`

`}`

`…`

`…`

`],`

`"pageable": {`

`"sort": [`

`{`

`"direction": "DESC",`

`"property": "updatedDateTime",`

`"ignoreCase": false,`

`"nullHandling": "NATIVE",`

`"ascending": false,`

`"descending": true`

`}`

`],`

`"pageNumber": 0,`

`"pageSize": 10,`

`"offset": 0,`

`"paged": true,`

`"unpaged": false`

`},`

`"last": true,`

`"totalPages": 1,`

`"totalElements": 3,`

`"first": true,`

`"sort": [`

`{`

`"direction": "DESC",`

`"property": "updatedDateTime",`

`"ignoreCase": false,`

`"nullHandling": "NATIVE",`

`"ascending": false,`

`"descending": true`

`}`

`],`

`"numberOfElements": 3,`

`"size": 10,`

`"number": 0,`

`"empty": false`

`},`

`"timestamp": "03-Mar-2022 08:40:09",`

`"message": null,`

`"errorCode": null`

`}`

**On failure:**

**Response 1#**

`{`

`"success": false,`

`"data": null,`

`"timestamp": "03-Mar-2022 09:06:43",`

`"message": null,`

`"errorCode": "INVALID_ARGUMENTS"`

`}`

**Response 2#**

`{`

`"success": false,`

`"data": null,`

`"timestamp": "03-Mar-2022 09:06:43",`

`"message": null,`

`"errorCode": "PROVSRVC.UNKNOWN"`

`}`

### RESTful API – Application role filter search <a href="#rxuqpye2qdhx" id="rxuqpye2qdhx"></a>

**Purpose:** This API is used to list application roles with provided application id and keyword.

**URL: http\://\<tenant\_domain>/applicationRole/findAppRolesByApplicationId**

**Method: POST**

**application id: applicationId**

**keyword: keyword**

**Example Request:**

|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>curl --location --request POST '<https://mru18.cymmetri.in/provsrvc/applicationRole/findAppRolesByApplicationId>' \</p><p>--header 'Tenant: mru18' \</p><p>--data-raw '{</p><p>    "filter": {</p><p>        "active": true,</p><p>        "applicationId": "614b5d3489ad96554e89e2ab"</p><p>    },</p><p>    "keyword": "",</p><p>    "pageNumber": 0,</p><p>    "pageSize": 10,</p><p>    "sortDirection": "ASC",</p><p>    "sortOn": \[</p><p>        "id"</p><p>    ]</p><p>}'</p> |

**Sample Response:**

**On success:**

`{`

`"success": true,`

`"data": {`

`"content": [`

`{`

`"id": "621f2996a36e574d3e7ab4a7",`

`"roleId": "ROLE_ID_101",`

`"roleName": "ADMIN",`

`"roleDescreption": "This role is for admin users.",`

`"applicationId": "614b5d3489ad96554e89e2ab",`

`"cosoType": "Admin",`

`"active": false,`

`"mappedBusinessRoles": [],`

`"createdDateTime": "2022-03-02T08:23:50.608",`

`"updatedDateTime": "2022-03-02T13:48:54.189",`

`"version": 3`

`},`

`...`

`...`

`],`

`"pageable": {`

`"sort": [`

`{`

`"direction": "ASC",`

`"property": "id",`

`"ignoreCase": false,`

`"nullHandling": "NATIVE",`

`"ascending": true,`

`"descending": false`

`}`

`],`

`"pageNumber": 0,`

`"pageSize": 10,`

`"offset": 0,`

`"paged": true,`

`"unpaged": false`

`},`

`"last": true,`

`"totalPages": 1,`

`"totalElements": 3,`

`"first": true,`

`"sort": [`

`{`

`"direction": "ASC",`

`"property": "id",`

`"ignoreCase": false,`

`"nullHandling": "NATIVE",`

`"ascending": true,`

`"descending": false`

`}`

`],`

`"numberOfElements": 3,`

`"size": 10,`

`"number": 0,`

`"empty": false`

`},`

`"timestamp": "03-Mar-2022 09:20:03",`

`"message": null,`

`"errorCode": null`

`}`

**On failure:**

**Response 1#**

`{`

`"success": false,`

`"data": null,`

`"timestamp": "03-Mar-2022 09:06:43",`

`"message": null,`

`"errorCode": "INVALID_ARGUMENTS"`

`}`

**Response 2#**

`{`

`"success": false,`

`"data": null,`

`"timestamp": "03-Mar-2022 09:06:43",`

`"message": null,`

`"errorCode": "PROVSRVC.UNKNOWN"`

`}`

### RESTful API – Application Policy Map filter search <a href="#toim3k6lghhz" id="toim3k6lghhz"></a>

**Purpose:** This API is used to search PolicymapTenant.

**URL: http\://\<tenant\_domain>/policyMapTenant/findAll**

**Method: POST**

**tenantApplicationId: Tenant Application Id**

**objectType: Mapping Object Type**

**internal: Internal Attribute**

**external: External Application Attribute**

**Example Request:**

|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>curl --location --request POST 'api.cymmetri.in/provsrvc/policyMapTenant/findAll' \</p><p>--data-raw '{</p><p>            "keyword": "lastName",</p><p>            "pageNumber": 0,</p><p>            "pageSize": 10,</p><p>            "filter": {</p><p>            "tenantApplicationId": "61dd1da8db654e41881b5273",</p><p>            "objectType": "USER"</p><p>            },</p><p>            "sortDirection": "DESC",</p><p>            "sortOn": \[</p><p>            "internal"</p><p>            ]</p><p>}'</p> |

**Sample Response:**

**On success:**

`{`

`"success": true,`

`"data": {`

`"content": [`

`{`

`"id": "61dd1da8db654e41881b5281",`

`"internal": "lastName",`

`"external": "sn",`

`"mandatory": false,`

`"script": null,`

`"createdDateTime": "2022-01-11T06:03:20.202",`

`"updatedDateTime": "2022-01-11T06:03:20.202",`

`"version": 0,`

`"default_val": "",`

`"tenant_applicationId": "61dd1da8db654e41881b5273",`

`"object_type": "USER",`

`"isCustom": false,`

`"scriptEnable": false`

`}`

`],`

`"pageable": {`

`"sort": [`

`{`

`"direction": "DESC",`

`"property": "internal",`

`"ignoreCase": false,`

`"nullHandling": "NATIVE",`

`"ascending": false,`

`"descending": true`

`}`

`],`

`"pageNumber": 0,`

`"pageSize": 10,`

`"offset": 0,`

`"paged": true,`

`"unpaged": false`

`},`

`"last": true,`

`"totalPages": 1,`

`"totalElements": 1,`

`"first": true,`

`"sort": [`

`{`

`"direction": "DESC",`

`"property": "internal",`

`"ignoreCase": false,`

`"nullHandling": "NATIVE",`

`"ascending": false,`

`"descending": true`

`}`

`],`

`"numberOfElements": 1,`

`"size": 10,`

`"number": 0,`

`"empty": false`

`},`

`"timestamp": "03-Mar-2022 07:13:09",`

`"message": null,`

`"errorCode": null`

`}`

### RESTful API – App description in selfservice application list API <a href="#kibsdjse253b" id="kibsdjse253b"></a>

**Purpose:** This API is used to get paginated lists with filters.

**URL: https\://\<tenant\_domain>/selfservice/api/selfservice/applications**

**Method: POST**

**Example Request:**

|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| <p>curl --location --request POST '<https://gk40.cymmetri.in/selfservice/api/selfservice/applications>' \</p><p>--header 'Connection: keep-alive' \</p><p>--header 'Pragma: no-cache' \</p><p>--header 'Cache-Control: no-cache' \</p><p>--header 'sec-ch-ua: " Not A;Brand";v="99", "Chromium";v="96", "Google Chrome";v="96"' \</p><p>--header 'Accept: application/json' \</p><p>--header 'content-type: application/json' \</p><p>--header 'Authorization: Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJhZG1pbiIsImRlbGVnYXRlZSI6bnVsbCwiZGVsZWdhdGVlSWQiOm51bGwsImZpcnN0TG9naW4iOmZhbHNlLCJyb2xlcyI6WyJPUkdfQURNSU4iLCJVU0VSIl0sInRlbmFudElkIjoiZ2s0MCIsImV4cCI6MTY0NzAxNDY2NywidXNlcklkIjoiNjE3MDE1YTNjMDQ4MTc1NmI3OThhY2EyIiwiaWF0IjoxNjQ3MDA4NjY3fQ.jP2BgjiOVUcdxhImVvdwy18puEylWSSOVHnWA\_2hhJU' \</p><p>--header 'sec-ch-ua-mobile: ?0' \</p><p>--header 'User-Agent: Mozilla/5.0 (X11; Linux x86\_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36' \</p><p>--header 'sec-ch-ua-platform: "Linux"' \</p><p>--header 'Origin: <https://gk40.cymmetri.in>' \</p><p>--header 'Sec-Fetch-Site: same-origin' \</p><p>--header 'Sec-Fetch-Mode: cors' \</p><p>--header 'Sec-Fetch-Dest: empty' \</p><p>--header 'Referer: <https://gk40.cymmetri.in/>' \</p><p>--header 'Accept-Language: en-GB,en-US;q=0.9,en;q=0.8' \</p><p>--header 'Cookie: deviceId=6e4caedd-beaf-444c-9312-21b219bb3709; Correlation=B194B86832FB4683ABC43EA6077944E2; Correlation=1E83B306404E4E46A2F6BE7D5A79C3BC; RefreshToken=fc6b1bcc-1c00-4663-b6ef-441051fb2e57; sessionId=75bdbb27-cf85-4102-9ba7-0cc5a84f8fb4' \</p><p>--data-raw '{</p><p>    "direction": "ASC",</p><p>    "keyword": "",</p><p>    "pageNumber": 0,</p><p>    "pageSize": 16,</p><p>    "sort": "NAME"</p><p>}'</p> |

**Sample Response:**

**On success:**

`{`

`"success": true,`

`"data": {`

`"offset": 0,`

`"pageSize": 16,`

`"totalElements": 5,`

`"totalPages": 1,`

`"elements": [`

`{`

`"endDate": null,`

`"deprovNotification": false,`

`"enabled": true,`

`"tagLine": "Directory service developed by Microsoft",`

`"id": "617253cc2fb4b2125b237b75",`

`"name": "Active Directory",`

`"appUrl": "",`

`"icon": "iVBORw0KGgoAAAANSUhEUgAAALoAAAC6CAYAAAAZDlfxAAAACXBIWXMAAAsSAAALEgHS3X78AAAgAElEQVR4nO2dCXQU17nnv1tb.....truncated"`

`}`

`],`

`"pageNumber": 0,`

`"sort": {`

`"orders": [`

`{`

`"direction": "ASC",`

`"property": "NAME"`

`}`

`],`

`"sorted": true`

`}`

`},`

`"timestamp": "03-Mar-2022 05:41:09",`

`"message": null,`

`"errorCode": null`

`}`

### RESTful API – New Joiner List API <a href="#id-5ezhz9n77z32" id="id-5ezhz9n77z32"></a>

**Purpose:** This API is used to get list of selfservice dashboard new Joiner list of logged in users.

**URL: http\://\<tenant\_url>/usersrvc/api/user/getSubOrdinates**

**Method: POST**

**Example Request: Need to pass filter as createdFrom and createdTo date time difference for seven day.**

|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>curl --location --request POST '<http://api.cymmetri.in/usersrvc/api/user/getSubOrdinates>' \</p><p>--header 'Content-Type: application/json' \</p><p>--header 'Tenant: gk17' \</p><p>--header 'UserId: 61e81227aa505f4393b93405' \</p><p>--data-raw '{</p><p>  "filter": {</p><p>    "createdFrom": "2022-01-04T10:26:56.030Z",</p><p>    "createdTo": "2022-03-04T10:26:56.030Z"</p><p>  },</p><p>  "keyword": "",</p><p>  "pageNumber": 0,</p><p>  "pageSize": 10,</p><p>  "sortDirection": "ASC",</p><p>  "sortOn": \[</p><p>    "id"</p><p>  ]</p><p>}'</p> |

**Sample Response:**

**On success:**

`{`

`"success": true,`

`"data": {`

`"content": [`

`{`

`"login": "nilesh",`

`"displayName": "Nilesh Dhepe",`

`"userId": "61e947c37dce7c5e40134f1f",`

`"profilePic": null,`

`"qualitativeRisk": null,`

`"sodViolations": null`

`},`

`{`

`"login": "workflow.one",`

`"displayName": "Test Workflow",`

`"userId": "61ee658de3a8361263cab0d1",`

`"profilePic": null,`

`"qualitativeRisk": null,`

`"sodViolations": null`

`},`

`{`

`"login": "workflow.two",`

`"displayName": "Test Workflow",`

`"userId": "61f7b3b50d84c22f79e1debd",`

`"profilePic": null,`

`"qualitativeRisk": null,`

`"sodViolations": null`

`},`

`{`

`"login": "mrunal",`

`"displayName": "Mrunal Chaple",`

`"userId": "61f8cda757a8e27934066a91",`

`"profilePic": null,`

`"qualitativeRisk": null,`

`"sodViolations": null`

`},`

`{`

`"login": "manoj.b",`

`"displayName": "Manoj Barapatre",`

`"userId": "61f8d81883126a511188e2ae",`

`"profilePic": null,`

`"qualitativeRisk": null,`

`"sodViolations": null`

`},`

`{`

`"login": "man.ba",`

`"displayName": "Manoj Bara",`

`"userId": "61f9160ed9800d4dbbc1baed",`

`"profilePic": null,`

`"qualitativeRisk": null,`

`"sodViolations": null`

`}`

`],`

`"pageable": {`

`"sort": [`

`{`

`"direction": "ASC",`

`"property": "id",`

`"ignoreCase": false,`

`"nullHandling": "NATIVE",`

`"ascending": true,`

`"descending": false`

`}`

`],`

`"pageNumber": 0,`

`"pageSize": 10,`

`"offset": 0,`

`"paged": true,`

`"unpaged": false`

`},`

`"last": true,`

`"totalElements": 6,`

`"totalPages": 1,`

`"first": true,`

`"number": 0,`

`"sort": [`

`{`

`"direction": "ASC",`

`"property": "id",`

`"ignoreCase": false,`

`"nullHandling": "NATIVE",`

`"ascending": true,`

`"descending": false`

`}`

`],`

`"numberOfElements": 6,`

`"size": 10,`

`"empty": false`

`},`

`"timestamp": "04-Mar-2022 10:39:22",`

`"message": null,`

`"errorCode": null`

`}`

**On failure:**

**Response 1#**

`{`

`"success": true,`

`"data": null,`

`"timestamp": "04-Mar-2022 10:39:22",`

`"message": null,`

`"errorCode": null`

`}`

### RESTful API – On board API - Get App incomplete config <a href="#sgx2w09i9mzf" id="sgx2w09i9mzf"></a>

**Purpose:** This API is used to get count of onboard application config incomplete.

**URL: http\://\<tenant\_url>/provsrvc/applicationTenant/getApplicationIncompleteConfig**

**Method: GET**

**Example Request:**

![](/files/xSonpegysNUYl42xAFnd)

|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>curl --location --request GET '<http://api.cymmetri.in/provsrvc/applicationTenant/getApplicationIncompleteConfigCount>' \</p><p>--header 'Tenant: gk17' \</p><p>--header 'Authorization: Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJnazE3IiwiZGVsZWdhdGVlIjpudWxsLCJkZWxlZ2F0ZWVJZCI6bnVsbCwiZmlyc3RMb2dpbiI6ZmFsc2UsInJvbGVzIjpbIk9SR19BRE1JTiIsIlVTRVIiXSwidGVuYW50SWQiOiJnazE3IiwiZXhwIjoxNjQ2NjQ2NjQ0LCJ1c2VySWQiOiI2MWU4MTIyN2FhNTA1ZjQzOTNiOTM0MDUiLCJpYXQiOjE2NDY2NDA2NDR9.snwC7XVRWM5S-gCP53fXXObh9aROFtZDtfOXQCUDPps'</p> |

**Sample Response:**

**On success**`{`

`"success": true,`

`"data": 3,`

`"timestamp": "07-Mar-2022 08:11:48",`

`"message": null,`

`"errorCode": null`

`}`

**On failure:**

**Response 1#**

`{`

`"success": true,`

`"data": 0,`

`"timestamp": "04-Mar-2022 10:39:22",`

`"message": null,`

`"errorCode": null`

`}`

### RESTful API – On board API - Get appCount, adminCount, UserCount <a href="#kpcfihgkzux7" id="kpcfihgkzux7"></a>

**Purpose:** This API is used to get count of application, admin and user.

**URL: http\://\<tenant\_url>/usersrvc/api/user/getOnboardCount**

**Method: GET**

**Example Request:**

![](/files/8qbeO0glvgTeuThZYied)

|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>curl --location --request GET '<http://api.cymmetri.in/usersrvc/api/user/getOnboardCount>' \</p><p>--header 'Content-Type: application/json' \</p><p>--header 'Tenant: n23' \</p><p>--header 'UserId: 6176c0b33c79f20dde6fd732' \</p><p>--header 'Authorization: Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJnazE3IiwiZGVsZWdhdGVlIjpudWxsLCJkZWxlZ2F0ZWVJZCI6bnVsbCwiZmlyc3RMb2dpbiI6ZmFsc2UsInJvbGVzIjpbIk9SR19BRE1JTiIsIlVTRVIiXSwidGVuYW50SWQiOiJnazE3IiwiZXhwIjoxNjQ2NjQ2NjQ0LCJ1c2VySWQiOiI2MWU4MTIyN2FhNTA1ZjQzOTNiOTM0MDUiLCJpYXQiOjE2NDY2NDA2NDR9.snwC7XVRWM5S-gCP53fXXObh9aROFtZDtfOXQCUDPps'</p> |

**Sample Response:**

**On success:**

`{`

`"success": true,`

`"data": {`

`"appCount": 9,`

`"adminCount": 1,`

`"userCount": 25`

`},`

`"timestamp": "07-Mar-2022 08:11:27",`

`"message": null,`

`"errorCode": null`

`}`

**On failure:**

**Response 1#**

`{`

`"success": true,`

`"data": {`

`"appCount": 0,`

`"adminCount": 0,`

`"userCount": 0`

`},`

`"timestamp": "07-Mar-2022 08:11:27",`

`"message": null,`

`"errorCode": null`

`}`

### RESTful API – System KPIs API <a href="#id-5o4nd5scoliy" id="id-5o4nd5scoliy"></a>

**Purpose:** This API is used to get the count of application,role,rule,workflow,password policy,active user,total user and unlogged user.

**URL:https\://\<tenant\_url>/usersrvc/api/user/getSystemKPICount**

**Method: GET**

**Example Request:**

![](/files/twCaHDq83pM4NZ3SASyF)

|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>curl --location --request GET '<https://macos.cymmetri.in/usersrvc/api/user/getSystemKPICount>' \</p><p>--header 'Accept: application/json' \</p><p>--header 'Authorization: Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJhZG1pbiIsImRlbGVnYXRlZSI6bnVsbCwiZGVsZWdhdGVlSWQiOm51bGwsImZpcnN0TG9naW4iOmZhbHNlLCJyb2xlcyI6WyJPUkdfQURNSU4iLCJVU0VSIl0sInRlbmFudElkIjoibWFjb3MiLCJleHAiOjE2NDcwMDg1MjUsInVzZXJJZCI6IjYxN2Y4YmIxZDE5MDViNjcyYzQ3N2QzMiIsImlhdCI6MTY0NzAwMjUyNX0.JzhcbfcQXxZoCYH5Mi\_HmRCHZf\_FVIr3OYrewl7vkjc'</p><p> </p> |

**Sample Response:**

**On success:**

`{`

`"success": true,`

`"data": {`

`"appCount": 80,`

`"roleCount": 5,`

`"activeUserCount": 128,`

`"totalUserCount": 131,`

`"unloggedUserCount": 106,`

`"passwordPolicyCount": 2,`

`"workflowCount": 3,`

`"ruleCount": 6`

`},`

`"timestamp": "11-Mar-2022 12:42:30",`

`"message": null,`

`"errorCode": null`

`}`

**On failure:**

**Response 1#**

`{`

`"success": true,`

`"data": {`

`"appCount": 0,`

`"roleCount": 0,`

`"activeUserCount": 0,`

`"totalUserCount": 0,`

`"unloggedUserCount": 0,`

`"passwordPolicyCount": 0,`

`"workflowCount": 0,`

`"ruleCount": 0`

`},`

`"timestamp": "11-Mar-2022 12:42:30",`

`"message": null,`

`"errorCode": null`

`}`

### RESTful API – Request, Claims and My Request Count <a href="#id-676d2l2fu3z6" id="id-676d2l2fu3z6"></a>

**Purpose:** This API is used to get count of requests, claims and my requests.

**URL: https\://\<tenant\_url>/workflowsrvc/api/workflowtaskassignment/user/request/claims/count**

**Method: GET**

**Example Request:**

|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>curl --location --request GET '<https://gk40.cymmetri.in/workflowsrvc/api/workflowtaskassignment/user/request/claims/count>' \</p><p>--header 'Tenant: gk40' \</p><p>--header 'Authorization: Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJtcnUxOCIsImRlbGVnYXRlZSI6bnVsbCwiZGVsZWdhdGVlSWQiOm51bGwsImZpcnN0TG9naW4iOmZhbHNlLCJyb2xlcyI6WyJPUkdfQURNSU4iLCJVU0VSIl0sInRlbmFudElkIjoibXJ1MTgiLCJleHAiOjE2NDY2NzE2MTYsInVzZXJJZCI6IjYxNGI1Yjc1ODVmODU0NGYxY2RkOTcxNSIsImlhdCI6MTY0NjY2NTYxNn0.bViQdrikfQD1xdI6Waf\_Sk6LOYQh-ilHVq4dMYfVt3E'</p><p> </p> |

**Sample Response:**

**On success:**

`{`

`"success": true,`

`"data": {`

`"requestCount": 12,`

`"clamisCount": 6,`

`"requestorCount": 0`

`},`

`"timestamp": "10-Mar-2022 07:07:48",`

`"message": null,`

`"errorCode": null`

`}`

**On failure:**

**Response 1#**

`{`

`"success": true,`

`"data": {`

`"requestCount": 0,`

`"clamisCount": 0,`

`"requestorCount": 0`

`},`

`"timestamp": "04-Mar-2022 10:39:22",`

`"message": null,`

`"errorCode": null`

`}`

### RESTful API – Applications assigned to user API search <a href="#jr7uplgxr4h7" id="jr7uplgxr4h7"></a>

**Purpose:** This API is used to search application assigned to user.

**URL: https\://\<tenant\_url>/usersrvc/api/user/listApplications**

**Method: POST**

**Example Request:**

![](/files/rrgqte7sFK1sVawA9UDi)

|                                                                                                                                                                                                                                                                                                       |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>curl --location --request POST '<https://s3.cymmetri.in/usersrvc/api/user/listApplications>' \</p><p>--data-raw '{</p><p>            "pageNumber": 0,</p><p>            "pageSize": 20,</p><p>            "userId": "61d7f610dd92d761faa278f2",</p><p>            "appName":"service"</p><p>}'</p> |

**Sample Response:**

**On success:**

`{`

`"success": true,`

`"data": {`

`"offset": 0,`

`"pageSize": 12,`

`"totalElements": 1,`

`"totalPages": 1,`

`"elements": [`

`{`

`"appId": "6226051994c38e414989eccd",`

`"appName": "ServiceNow",`

`"tagLine": "Workflow Automation Platform",`

`"status": "",`

`"appType": "GROUP",`

`"groupId": "61dea46ef515150ebe517b0d",`

`"endDate": null,`

`"provisionEnable": true,`

`"assignRoles": null`

`}`

`],`

`"pageNumber": 0,`

`"sort": null`

`},`

`"timestamp": "11-Mar-2022 01:06:33",`

`"message": null,`

`"errorCode": null`

`}`

### RESTful API – List of assigned & unassigned application <a href="#k6ecyz1ydmjh" id="k6ecyz1ydmjh"></a>

**Purpose:** This API is used to get assigned and unassigned application.

**URL: https\://\<tenant\_url>/provsrvc/applicationTenant/applicationListByPage**

**Method: POST**

**Example Request:**

![](/files/8wK5ssusjlV0jgTJ13d7)

|                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>curl --location --request POST '<https://s3.cymmetri.in/provsrvc/applicationTenant/applicationListByPage>' \</p><p>--data-raw '{</p><p>            "displayName": "",</p><p>            "order": "DESC",</p><p>            "pageNo": 0,</p><p>            "size": 10,</p><p>            "sortBy": "displayName",</p><p>            "tag": "",</p><p>            "userId":"61d7f610dd92d761faa278f2"</p><p>}'</p> |

**Sample Response:**

**On success:**

`{`

`"success": true,`

`"data": {`

`"content": [`

`{`

`"id": "61dbfdf6b30690468b0d4a79",`

`"appName": "Google Workplace",`

`"icon": null,`

`"tagLine": "Integrated Collaboration & Productivity Apps from Google",`

`"status": "ACTIVE",`

`"provisionEnable": false,`

`"ssoEnable": true,`

`"assigned": true`

`},`

`{`

`"id": "61dd1da8db654e41881b5273",`

`"appName": "Active Directory",`

`"icon": null,`

`"tagLine": "Directory service developed by Microsoft",`

`"status": "ACTIVE",`

`"provisionEnable": true,`

`"ssoEnable": false,`

`"assigned": true`

`},`

`{`

`"id": "6225f81edd7111640e094f8d",`

`"appName": "Google Workplace5",`

`"icon": null,`

`"tagLine": "Integrated Collaboration & Productivity Apps from Google",`

`"status": "ACTIVE",`

`"provisionEnable": true,`

`"ssoEnable": false,`

`"assigned": true`

`}`

`],`

`"pageable": {`

`"sort": [`

`{`

`"direction": "DESC",`

`"property": "displayName",`

`"ignoreCase": false,`

`"nullHandling": "NATIVE",`

`"ascending": false,`

`"descending": true`

`}`

`],`

`"pageNumber": 0,`

`"pageSize": 10,`

`"offset": 0,`

`"paged": true,`

`"unpaged": false`

`},`

`"totalPages": 2,`

`"totalElements": 12,`

`"last": false,`

`"first": true,`

`"sort": [`

`{`

`"direction": "DESC",`

`"property": "displayName",`

`"ignoreCase": false,`

`"nullHandling": "NATIVE",`

`"ascending": false,`

`"descending": true`

`}`

`],`

`"numberOfElements": 10,`

`"size": 10,`

`"number": 0,`

`"empty": false`

`},`

`"timestamp": "11-Mar-2022 02:10:38",`

`"message": null,`

`"errorCode": null`

`}`

### RESTful API – Application Access expiring new API <a href="#id-1j2w8o8k8ip" id="id-1j2w8o8k8ip"></a>

**Purpose:** This API is used to get list of application of user with there expiry days

**URL: https\://\<tenant\_url>/selfservice/api/selfservice/applicationswithexpiry**

**Method: POST**

**Example Request:**

![](/files/lQXRVCAdXUAMcp566jZ4)

|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| curl --location --request POST '<https://as100.cymmetri.in/selfservice/api/selfservice/applicationswithexpiry>' \ --header 'Connection: keep-alive' \ --header 'Pragma: no-cache' \ --header 'Cache-Control: no-cache' \ --header 'sec-ch-ua: "Google Chrome";v="93", " Not;A Brand";v="99", "Chromium";v="93"' \ --header 'Accept: application/json' \ --header 'content-type: application/json' \ --header 'Authorization: Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJhZG1pbiIsImRlbGVnYXRlZSI6bnVsbCwiZGVsZWdhdGVlSWQiOm51bGwsImZpcnN0TG9naW4iOmZhbHNlLCJyb2xlcyI6WyJPUkdfQURNSU4iLCJVU0VSIl0sInRlbmFudElkIjoiYXMxMDAiLCJleHAiOjE2NDcwMDk4NzgsInVzZXJJZCI6IjYyMTRkYjdiZDY2MWE1NzM4NmE3MWYxMCIsImlhdCI6MTY0NzAwMzg3OH0.LKZci0Yqeoyn4RHUIyYBFq7O5ATeDuCerZ0QdJ243gY' \ --header 'sec-ch-ua-mobile: ?0' \ --header 'User-Agent: Mozilla/5.0 (X11; Linux x86\_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.63 Safari/537.36' \ --header 'sec-ch-ua-platform: "Linux"' \ --header 'Origin: <https://as100.cymmetri.in>' \ --header 'Sec-Fetch-Site: same-origin' \ --header 'Sec-Fetch-Mode: cors' \ --header 'Sec-Fetch-Dest: empty' \ --header 'Referer: <https://as100.cymmetri.in/>' \ --header 'Accept-Language: en-GB,en-US;q=0.9,en;q=0.8' \ --header 'Cookie: deviceId=48ba110c-c93c-45ac-92dc-3c6e04e74473; app\_73e5c5f8-276b-47bb-a6a5-b6f82a779d79=e689a8da-faa7-46f5-9c7a-2800abdd206a; Correlation=C43A4277E7AB46178F0000BE4DD72F0C; RefreshToken=1ac7eea6-28a6-4bb8-997f-d7381a3dd7d1; sessionId=3417319f-789a-4849-8faa-bf180f4bec14; device=cf7bbf2a-161c-11ec-b3ec-39287c680726' \ --data-raw '{ "keyword": "", "pageNumber": 0, "pageSize": 10, "filter": {}, "sortDirection": "DESC", "sortOn": \[ "plannedStart" ] }' |

**Sample Response:**

**On success:**

`{`

`"success": true,`

`"data": {`

`"offset": 0,`

`"pageSize": 10,`

`"totalElements": 3,`

`"totalPages": 1,`

`"elements": [`

`{`

`"id": "62220c747dab08061e00ba7b",`

`"name": "Active Directory",`

`"icon": "iVBORw0KGgoAAAANSUhEUgAAALoAAAC6CAYAAAAZDlfxAAAACXBIWXMAAAsSAAALEgHS3X78AAAgAElEQVR4nO2dCXQU17nnv1tb71q7BUJIzW7Jxo5N6zlOsPD2COBlEsnbiZFf,`

`"period": 20,`

`"tagLine": "Directory service developed by Microsoft"`

`},`

`{`

`"id": "62260e904f6c552b8b489c20",`

`"name": "Google Workplace",`

`"icon": "iVBORw0KGgoAAAANSUhEUgAAALoAAAC6CAIAAACWbMCmAAAACXBIWXMAAAsSAAALEgHS3X78AAAgAElEQVR4nO2dd3wURf/Ht1xLcnfpvUB6uRRSKFKl9w6C+KgPj2B57D6gD/o8iOVBEaQIiCiIgoBKNSAgVXoPISG910u5S0+u7/xed3vZ27vsXW6T4A+fZ97/ZLM7uzs7+9mZ73xn5nsoAACBQOwDg+UEsR8oFwgLoFwgLIBygbAAygXCAigXCAugXCAsgHKBsADKBcICKBcIC6BcICyAcoGwAMoFwgIoFwgLoFwgLIBygbAAygXCAigXCAugXCAsgHKBsADKBcICKBcIC6BcICyAcoGwAMoFwgIoFwgLoFwgLIBygbAAygXCAigXCAugXCAsgHKBsADKBcICKBcIC6BcICyAcoGwAMoFwgIoFwgLoFwgLIBygbAAygXYQGUC4QFUC4QFkC5QFgA5QKxFwRB/g+Z9ki2AOTkrgAAAABJRU5ErkJggg==",`

`"period": 5,`

`"tagLine": "Integrated Collaboration & Productivity Apps from Google"`

`},`

`{`

`"id": "62260e994f6c552b8b489c28",`

`"name": "PowerShell",`

`"icon": "iVBORw0KGgoAAAANSUhEUgAAALoAAAC6CAYAAAAZDlfxAT/gAAAABJRU5ErkJggg==",`

`"period": 4,`

`"tagLine": "Command-line Shell from Microsoft"`

`}`

`],`

`"pageNumber": 0,`

`"sort": {`

`"orders": [`

`{`

`"direction": "DESC",`

`"property": "plannedStart"`

`}`

`],`

`"sorted": true`

`}`

`},`

`"timestamp": "11-Mar-2022 01:42:30",`

`"message": null,`

`"errorCode": null`

`}`

### RESTful API – Password Policy - maximum (optional)- minimum (required) password length <a href="#id-9u7bu81tyip1" id="id-9u7bu81tyip1"></a>

**Purpose:** This API is used to validate password against password policy

**URL: https\://\<tenant\_url>/authsrvc/passwordPolicy/pub/validate**

**Method: POST**

**Example Request:**

![](/files/eoaUapzadceBcRet04Nt)

|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| <p>curl '<https://as100.cymmetri.in/authsrvc/passwordPolicy/pub/validate>' \</p><p>  -H 'Connection: keep-alive' \</p><p>  -H 'Pragma: no-cache' \</p><p>  -H 'Cache-Control: no-cache' \</p><p>  -H 'sec-ch-ua: "Google Chrome";v="93", " Not;A Brand";v="99", "Chromium";v="93"' \</p><p>  -H 'content-type: application/json' \</p><p>  -H 'sec-ch-ua-mobile: ?0' \</p><p>  -H 'User-Agent: Mozilla/5.0 (X11; Linux x86\_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.63 Safari/537.36' \</p><p>  -H 'tenant: as100' \</p><p>  -H 'sec-ch-ua-platform: "Linux"' \</p><p>  -H 'Accept: */*' \</p><p>  -H 'Origin: <https://as100.cymmetri.in>' \</p><p>  -H 'Sec-Fetch-Site: same-origin' \</p><p>  -H 'Sec-Fetch-Mode: cors' \</p><p>  -H 'Sec-Fetch-Dest: empty' \</p><p>  -H 'Referer: <https://as100.cymmetri.in/>' \</p><p>  -H 'Accept-Language: en-GB,en-US;q=0.9,en;q=0.8' \</p><p>  -H 'Cookie: deviceId=fa83c4b1-7c85-467d-9b46-ffbc70efad97; Correlation=9928D5133AED419CBC01591B56483953; app\_73e5c5f8-276b-47bb-a6a5-b6f82a779d79=e689a8da-faa7-46f5-9c7a-2800abdd206a; device=cf7bbf2a-161c-11ec-b3ec-39287c680726' \</p><p>  --data-raw '{"password":"U2FsdGVkX191zbRQpSQz+rdxyAacEqD1G5Mx5wKtPV5ElwKZu7/TFHFLuCNH+v63G8k7sTFDa5gNYG9SQ+0ix4eZdTvLcJbELGm2yjUWjx2a6jH3JnP/USl2efCC9nDvufmqUhSbIPA0Nc1PZUqM+PPk+TpCFSoKtKwBPWeBa/LYjlYt11u++aTuVGsd/rOaWJxqINPRHIk6Ax89LfhM8+H6VKc4+ybfearoCJgHWCPE/X566hiYZJEKcMGe7u0OpUzGUMlyguBtfYlWlT7tcdP6x/rXlqs8vNTLk/HboYLv10UkB0ifsQ64c7fSQ/ofZKjQlqehpP4+SzIi4OiqRQikP9MOkKZWl9YJdGXZs+mUuzfEs9UGINMYBk1hSCq6xGb9mfE0vyFeVAyY/6oGgQ==","login":"totp","userId":"6214def0a251e06721ed8594"}' \</p><p>  --compressed</p> |

**Sample Response:**

**On success:**

`{"success":true,"data":null,"timestamp":"11-Mar-2022 01:40:38","message":null,"errorCode":null}`

**On failure:**

**Response 1#**

`{"success":false,"data":null,"timestamp":"11-Mar-2022 01:39:40","message":null,"errorCode":"AUTHSRVC.PASSWORD_COMPOSITION_RULE_VIOLATION"}`

### RESTful API – New Application count API (7 days) <a href="#id-1cpkdozkd9" id="id-1cpkdozkd9"></a>

**Purpose:** This API is used to get count of application

**URL: http\://\<tenant\_url>/api/selfservice/newApplicationsCount**

**Method: GET**

**Example Request:**

![](/files/Ssx8hXEADwVGZEGZuoIQ)

|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>curl --location --request GET '<http://localhost:8080/api/selfservice/newApplicationsCount>' \</p><p>--header 'Connection: keep-alive' \</p><p>--header 'Pragma: no-cache' \</p><p>--header 'Cache-Control: no-cache' \</p><p>--header 'sec-ch-ua: " Not A;Brand";v="99", "Chromium";v="99", "Google Chrome";v="99"' \</p><p>--header 'Accept: application/json' \</p><p>--header 'content-type: application/json' \</p><p>--header 'Authorization: Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJhZG1pbiIsImRlbGVnYXRlZSI6bnVsbCwiZGVsZWdhdGVlSWQiOm51bGwsImZpcnN0TG9naW4iOmZhbHNlLCJyb2xlcyI6WyJPUkdfQURNSU4iLCJVU0VSIl0sInRlbmFudElkIjoiZ2s0MCIsImV4cCI6MTY0Njc0OTkzMiwidXNlcklkIjoiNjE3MDE1YTNjMDQ4MTc1NmI3OThhY2EyIiwiaWF0IjoxNjQ2NzQzOTMyfQ.puFKgrNoHZtRl6P4LxzFd9KQM\_-EB-45DqqP4zywws8' \</p><p>--header 'sec-ch-ua-mobile: ?0' \</p><p>--header 'User-Agent: Mozilla/5.0 (X11; Linux x86\_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36' \</p><p>--header 'sec-ch-ua-platform: "Linux"' \</p><p>--header 'Sec-Fetch-Site: same-origin' \</p><p>--header 'Sec-Fetch-Mode: cors' \</p><p>--header 'Sec-Fetch-Dest: empty' \</p><p>--header 'Referer: <https://gk40.cymmetri.in/>' \</p><p>--header 'Accept-Language: en-GB,en-US;q=0.9,en;q=0.8' \</p><p>--header 'Cookie: deviceId=6e4caedd-beaf-444c-9312-21b219bb3709; Correlation=B194B86832FB4683ABC43EA6077944E2; app\_73e5c5f8-276b-47bb-a6a5-b6f82a779d79=e689a8da-faa7-46f5-9c7a-2800abdd206a; device=41b5bf50-9def-11ec-8665-953ee8af105c; Correlation=1B9449F921B043B9B513E99D253894CE; RefreshToken=b8ada8a1-d089-4a39-b3e1-72c04ce202fe; sessionId=130e95df-69a5-4462-a8b5-c04b53e97e64' \</p><p>--header 'Tenant: gk40' \</p><p>--header 'userId: 617015a3c0481756b798aca2'</p> |

**Sample Response:**

**On success:**

`{"success": true,"data": 1,"timestamp": "11-Mar-2022 02:13:39","message": null,"errorCode": null}`

### RESTful API – Campaigns/access review search by campaign name <a href="#pc702rjksp9m" id="pc702rjksp9m"></a>

**Purpose:** This API is used to get list of campaign

**URL: https\://\<tenant\_url>/igsrvc/api/ig/campaign/execution/history/list-summary/reviewer**

**Method: POST**

**Example Request:**

![](/files/tzyTIHgga7IAkIO8ncP7)

|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>curl --location --request POST '<https://gk40.cymmetri.in/igsrvc/api/ig/campaign/execution/history/list-summary/reviewer>' \</p><p>--header 'Connection: keep-alive' \</p><p>--header 'Pragma: no-cache' \</p><p>--header 'Cache-Control: no-cache' \</p><p>--header 'sec-ch-ua: " Not A;Brand";v="99", "Chromium";v="99", "Google Chrome";v="99"' \</p><p>--header 'Accept: application/json' \</p><p>--header 'content-type: application/json' \</p><p>--header 'Authorization: Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJhZG1pbiIsImRlbGVnYXRlZSI6bnVsbCwiZGVsZWdhdGVlSWQiOm51bGwsImZpcnN0TG9naW4iOmZhbHNlLCJyb2xlcyI6WyJPUkdfQURNSU4iLCJVU0VSIl0sInRlbmFudElkIjoiZ2s0MCIsImV4cCI6MTY0NzAxNDY2NywidXNlcklkIjoiNjE3MDE1YTNjMDQ4MTc1NmI3OThhY2EyIiwiaWF0IjoxNjQ3MDA4NjY3fQ.jP2BgjiOVUcdxhImVvdwy18puEylWSSOVHnWA\_2hhJU' \</p><p>--header 'sec-ch-ua-mobile: ?0' \</p><p>--header 'User-Agent: Mozilla/5.0 (X11; Linux x86\_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36' \</p><p>--header 'sec-ch-ua-platform: "Linux"' \</p><p>--header 'Origin: <https://gk40.cymmetri.in>' \</p><p>--header 'Sec-Fetch-Site: same-origin' \</p><p>--header 'Sec-Fetch-Mode: cors' \</p><p>--header 'Sec-Fetch-Dest: empty' \</p><p>--header 'Referer: <https://gk40.cymmetri.in/>' \</p><p>--header 'Accept-Language: en-GB,en-US;q=0.9,en;q=0.8' \</p><p>--header 'Cookie: deviceId=6e4caedd-beaf-444c-9312-21b219bb3709; Correlation=B194B86832FB4683ABC43EA6077944E2; Correlation=C27A4466A21046309B58FD53AEF4A2C5; RefreshToken=4ec80313-bed3-44e5-9081-33eb9ba301f2; sessionId=32ceee83-781e-45d6-9c2c-2acc8741a944' \</p><p>--data-raw '{</p><p>    "filter": {</p><p>        "campaignName": "Campaign For"</p><p>    },</p><p>    "keyword": "",    </p><p>    "pageNumber": 0,</p><p>    "pageSize": 10,</p><p>    "sortDirection": "ASC",</p><p>    "sortOn": \[</p><p>        "startDate"</p><p>    ]</p><p>}'</p> |

**Sample Response:**

**On success:**

`{`

`"data": {`

`"content": [`

`{`

`"executionId": "61a865c69c60c83eb2d2cf0e",`

`"name": "Campaign For Bug_w8z89q",`

`"description": "",`

`"campaignId": "61a8657c9c60c83eb2d2cf0c",`

`"revision": 1,`

`"iteration": 1,`

`"status": "COMPLETED",`

`"remarks": "",`

`"startMode": "MANUAL",`

`"startDate": "2021-12-02",`

`"endMode": "MANUAL",`

`"endDate": "2021-12-02",`

`"plannedEnd": "2021-12-05",`

`"totalAssignments": 41,`

`"pendingAssignments": 41,`

`"approvedAssignments": 0,`

`"rejectedAssignments": 0`

`},`

`{`

`"executionId": "6225c00ab21ac3024d5a1d91",`

`"name": "Campaign For Bug_w8z89q",`

`"description": "",`

`"campaignId": "61a8657c9c60c83eb2d2cf0c",`

`"revision": 1,`

`"iteration": 2,`

`"status": "COMPLETED",`

`"remarks": "",`

`"startMode": "MANUAL",`

`"startDate": "2022-03-07",`

`"endMode": "AUTO",`

`"endDate": "2022-03-10",`

`"plannedEnd": "2022-03-10",`

`"totalAssignments": 40,`

`"pendingAssignments": 40,`

`"approvedAssignments": 0,`

`"rejectedAssignments": 0`

`}`

`],`

`"pageable": {`

`"sort": [`

`{`

`"direction": "ASC",`

`"property": "startDate",`

`"ignoreCase": false,`

`"nullHandling": "NATIVE",`

`"ascending": true,`

`"descending": false`

`}`

`],`

`"pageNumber": 0,`

`"pageSize": 10,`

`"offset": 0,`

`"paged": true,`

`"unpaged": false`

`},`

`"totalPages": 1,`

`"totalElements": 2,`

`"last": true,`

`"first": true,`

`"sort": [`

`{`

`"direction": "ASC",`

`"property": "startDate",`

`"ignoreCase": false,`

`"nullHandling": "NATIVE",`

`"ascending": true,`

`"descending": false`

`}`

`],`

`"numberOfElements": 2,`

`"size": 10,`

`"number": 0,`

`"empty": false`

`},`

`"errorCode": null,`

`"message": null,`

`"success": true,`

`"timestamp": "11-Mar-2022 02:38:11"`

`}`

### API Response Codes <a href="#w1lohxsr0vh" id="w1lohxsr0vh"></a>

| **API**        | **Status**            | **Error Code** | **Message** |
| -------------- | --------------------- | -------------- | ----------- |
| **Create API** | 200                   | OK             |             |
| 500            | Internal Server Error |                |             |
| 401            | Unauthorized          |                |             |
| 403            | Forbidden             |                |             |
| 404            | Not Found             |                |             |
| **Update API** | 200                   | OK             |             |
| 500            | Internal Server Error |                |             |
| 401            | Unauthorized          |                |             |
| 403            | Forbidden             |                |             |
| 404            | Not Found             |                |             |


# Ticker

The Ticker feature is a powerful communication tool in the Cymmetri platform that allows administrators to broadcast real-time, time-sensitive, text-based messages to users. It's a key component for improving internal communication and enhancing security awareness.

This feature provides a robust channel for broadcasting important updates and alerts, including:

* Urgent Announcements: Instantly communicate system-wide announcements, such as new policies or security reminders.
* Maintenance Notifications: Inform users about scheduled system maintenance or downtime to minimize disruption.
* Targeted Messaging: Administrators can configure rules to broadcast messages to specific user groups or individuals, ensuring relevance and reducing notification fatigue.

Tickers are highly configurable, offering two primary display options to give administrators full control over their communication strategy.

<figure><img src="/files/DIX46TfDC6yqS4yHrIxP" alt=""><figcaption></figcaption></figure>

**Before Login**

This option is designed for broadcasting critical messages that every user must see before they can access the system. These tickers appear directly on the login page and are essential for communicating information like system-wide outages or mandatory security alerts.

To configure a "Before Login" ticker, administrators define the following parameters:

* **Name**: A unique, descriptive name to easily identify the ticker.
* **Start Date & End Date**: Specifies the time frame during which the ticker will be visible.
* **Show Tickers**: Set to Before Login to ensure the message is displayed on the login page.
* **Status**: The state of the ticker, either Active (visible) or Inactive (hidden).
* **Message**: The specific text content to be displayed.

<figure><img src="/files/vBZcfq4OQND6hLztg9xd" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/tsQGZESz6ZQoRrvhto9v" alt=""><figcaption></figcaption></figure>

**After Login**

This option is used for displaying messages on the user's dashboard after they have successfully logged in. It's suitable for general announcements, policy updates, or news that isn't a hard requirement for system access.

The configuration parameters are the same as the "Before Login" option, with one crucial difference: Show Tickers is set to After Login.

A key advantage of the "After Login" option is its support for conditional logic. Administrators can add rules to display messages only to specific users or groups based on attributes like department or role. This ensures communication is highly targeted and relevant.

<figure><img src="/files/K0pl6qDJH4w43CTbh0ml" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/Y7HSVBQC98sP5hkzHUjF" alt=""><figcaption></figcaption></figure>


# Catpcha

Cymmetri has integrated advanced CAPTCHA validation capabilities to bolster security against automated threats and bot-based attacks. The platform now supports two distinct methods, providing administrators with a flexible approach to securing user interactions.

#### Supported CAPTCHA Methods

* **hCaptcha**: This method is a privacy-focused and widely adopted alternative to traditional CAPTCHA. It requires users to perform a simple task (e.g., identifying objects in an image) to prove they are human, effectively blocking bots while maintaining user privacy.
* **Traditional CAPTCHA**: This classic method uses distorted text or numbers that users must correctly enter. While this method is effective, it can sometimes be more challenging for users to solve.

These integrations enable Cymmetri to enhance its security posture by providing a robust defense layer, ensuring that user registration and login processes are protected from malicious automated activity.

#### Administrator Configuration

To enable and configure CAPTCHA, administrators must navigate to the Configuration section and select Captcha Configuration.

<figure><img src="/files/aWshLxhaamOhIIGkCZmU" alt=""><figcaption></figcaption></figure>

From this menu, the administrator has two options:

1. **hCaptcha** Type: Selecting this option enables hCaptcha validation, which utilizes simple, interactive tasks for user verification.
2. **Traditional CAPTCHA**: Choosing this option will implement the classic method of using distorted text.

<figure><img src="/files/YVuNOHzlkZhuJRnEuSEq" alt=""><figcaption></figcaption></figure>

The administrator can then save the configuration.&#x20;

Below is an example of what the Traditional CAPTCHA looks like to an end-user.

<figure><img src="/files/FJLAcSVmpD3pYdgRtOos" alt=""><figcaption></figcaption></figure>


# Annotations

Annotation provides a centralized mechanism to define and select dynamic approvers for workflows, application access reviews, and group access reviews, enabling dynamic approval routing, which makes it easy to configure and manage.

The Annotation feature, found under the Configurations tab, allows you to designate specific users as approvers for critical identity management operations. By configuring an Annotation and selecting it within a Workflow (say, user creation) or an Access Review Campaign (for application/groups), all associated approval requests are routed directly to the Annotation-defined approver(s). Annotations enable the administrator to easily change the actual user without changing the annotation, which makes it a one-point change that gets applied at all various places where the annotation is used as an approver. With the flexibility of applying to both the application and group, it makes it easy to reuse the annotation and increases its usability.

Note:&#x20;

1. Annotation names must be lowercase and cannot contain any special characters.
2. An annotation with group and application cannot be configured together; it must be configured separately for the group as well as the application

### Step-by-Step Guide

#### A. Configuring Annotation for User Creation Workflow

This section outlines how to set up an Annotation and integrate it into a user creation workflow, directing approval requests to your chosen approver.

**I. Annotation Setup**

Navigate to Configurations: From your product's main navigation, go to Configurations.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXeLlFNik0HNZt8Yu6Hcsx95-shmbXlL8VJAuZ_uI4frmqrlp-lxjanwEzh_Kcn-AzK9tqjCNKogwD-iJDGguGqTzhCoX_n7V45dnwe7bZXOlYgw8eus0Q3ivbubRxo9ShmWkPGscw?key=BB-p-P6rMfCMOdxq1T9SXQ" alt=""><figcaption></figcaption></figure>

### Annotation for Group Review

This enhancement introduces the Group Review capability within the access review system. This feature provides administrators with a more flexible and targeted approach to initiating access reviews.

Administrators can now initiate comprehensive reviews based on the following criteria:

* All Groups: This option enables a comprehensive review of all user access permissions across every group within the system.
* Specific Multiple Groups: This provides a focused approach, enabling administrators to select and review permissions for a pre-defined set of groups.
* Specific Multiple Applications: This functionality allows for a granular review of user access rights associated with a select number of specific applications.

This new capability streamlines the access review process by enabling more precise and efficient auditing of user permissions, thereby reducing the time and effort required to ensure compliance and security.

#### Campaign Configuration

Navigate to Identity Governance (IGA): Access the main IGA module from the Cymmetri

<figure><img src="/files/bbWAcop1F1VgRc1DnudW" alt=""><figcaption></figcaption></figure>

1. Access Group Access Review: From the IGA menu, select the "Group Access Review" option to initiate the configuration process for a group-based campaign.
2. Go to Campaign: Navigate to the Campaign section within the Group Access Review interface.
3. Create or Edit Campaign:
4. Click "Add New" to create a new access review campaign.

Alternatively, select and Edit an existing campaign to modify its settings.

<figure><img src="/files/3oTkfB9YDpL9OoHWvpSM" alt=""><figcaption></figcaption></figure>

**Add Campaign Details**: Provide all necessary campaign details, such as the campaign name, description, and schedule.

<figure><img src="/files/mCOEIM5YJvQ5SBTkUGEu" alt=""><figcaption></figcaption></figure>

**Select Target Group**: In the second step of the campaign setup, choose Groups as the campaign target. Add the specific group that was previously associated with the designated Annotation.

<figure><img src="/files/7JK6M0bdjWC7KHL0rn1Z" alt=""><figcaption></figcaption></figure>

**Select Annotation**: In the third step, select the Annotation option. From the dropdown menu, choose the specific Annotation created for the group approval process (e.g., groupapprover). This action links the campaign to the predefined approver logic.

<figure><img src="/files/WZY37e6qtpH7fRkH4JEB" alt=""><figcaption></figcaption></figure>

**Save, Publish, and Run**: Complete the campaign setup by clicking Save, then Publish, and finally Run the campaign to initiate the access review.

<figure><img src="/files/y4ObzfXvUBFnLi5qv56w" alt=""><figcaption></figcaption></figure>

#### Access Review and Approval Process

1. **Approval Request Routing**: All access review requests for the targeted group will be automatically routed to the approver defined by the selected Annotation.
2. **Approver Action**: The designated approver should perform the following steps:
   1. Log in to Cymmetri using the credentials of the Annotation-assigned approver.
   2. Navigate to the Access Review tab.
   3. Within the Access Review section, go to the Active list to view all pending requests.

<figure><img src="/files/Tsv4r1jZq8KboOcWR5Xp" alt=""><figcaption></figcaption></figure>

d. Filter the view to display Group requests, if applicable.

e. Review all pending access review requests for the specified groups. The approver can then Approve or Reject each request based on their assessment of the user's need for continued access.

<figure><img src="/files/C11Y43zqAkLuPuBokbvZ" alt=""><figcaption></figcaption></figure>


# Group as an approver for Annotations


# Global Search

Global Search is a powerful, word-based search feature that empowers users to instantly navigate across various pages in Cymmetri by simply typing in relevant keywords. This functionality streamlines the process of locating specific information, making it significantly easier to access any content within Cymmetri with just a few keystrokes. By incorporating Global Search in Cymmetri, the time spent browsing through menus or sifting through irrelevant data is minimized, directly enhancing productivity and user experience.

The Global Search feature is available in the top bar, which makes it available on all pages as shown below:

<figure><img src="/files/QMWkCJgMm1xRlwzTW4mG" alt=""><figcaption></figcaption></figure>

For using the Global Search, the user needs to click on the search box. When clicked, it opens a search dialog box.&#x20;

<figure><img src="/files/JFzanevxi5I7kzL4YrS8" alt=""><figcaption></figcaption></figure>

*Note: The search dialog box can also be opened using Ctrl+K (in Windows) or Command+K (in Mac)*

<figure><img src="/files/iRutCun3U5atEH2qaiJJ" alt=""><figcaption></figcaption></figure>

Upon entering a term, you'll receive precise matches or helpful suggestions. Simply browse the list and select the desired page to view it, clicking anywhere outside the search modal instantly closes it, allowing you to seamlessly return to your previous page.

<figure><img src="/files/tZHdubprPxlvOztpniwV" alt=""><figcaption></figcaption></figure>

The page also provides certain shortcuts which can be used for ease:

**Esc:** Close the search Dialog box

**↓↑:** for Navigate up and down the search list

**Enter:** For opening the selected page

The Search box appears below in non-administrative logins:

<figure><img src="/files/nHaORcMkdtS0nvcYAtDU" alt=""><figcaption></figcaption></figure>


# Managing Users and Groups


# User Management

The User Management interface in Cymmetri provides an intuitive and efficient way to manage users within Cymmetri. The interface is designed to support both list and card views, allowing administrators to easily navigate through user profiles according to their preferences. To access the User Management page, navigate through: **Identity Hub** -> **User**

<figure><img src="/files/EfhjEbHwU62BmJczCEx6" alt=""><figcaption></figcaption></figure>

### Features

The UserManagement Page provides various features that ease user management.

* **View Modes**: Users can toggle between a list and a card view, providing flexibility in how information is displayed.
* **Search Functionality**: Quickly find users with the integrated search feature, saving time and improving manageability.
* **Advanced Filtering**: The granular filtering capability ensures that administrators can pinpoint users based on specific criteria, making user management tasks more streamlined. The list of users can be narrowed down using various filters, including:

  * **Account Status**
  * **User Status**
  * **Users' Login Status**
  * **Location**
  * **Department**
  * **Designation**
  * **Usertype**
  * **Custom Attributes**

  <figure><img src="/files/4Bzl5tyhmSu16O9vAPA5" alt=""><figcaption></figcaption></figure>

### User Information Display

For each user, the following information is prominently displayed:

* **Display Name**: The full name of the user as it appears in the organization.
* **Email**: The user's primary email address.
* **Mobile Number**: Contact number of the user.
* **User Status Indicator**: An intuitive green or red dot next to the display picture indicates whether a user is active or inactive, respectively.

<figure><img src="/files/vTsc0jPIK8pb0owqhAtZ" alt=""><figcaption></figcaption></figure>

### Contextual Actions

A context menu associated with each user profile offers a suite of actions, enabling administrators to manage user accounts directly from the interface. Available actions include:

* **Reset Password**: Securely reset a user's password.
* **Mark Inactive**: Change a user's status to inactive.
* **Assign Group**: Add the user to specific groups for access control and organizational purposes.
* **Assign Application**: Allocate applications to the user as per their role and requirements.
* **Edit Info**: Update user information such as email, mobile number, and other personal details.
* **Delete User**: Remove the user from the system entirely.

<figure><img src="/files/NNItLXbaPg2BNXvTk74C" alt=""><figcaption></figcaption></figure>


# User Detail

This page is designed to provide a comprehensive view of an individual user's information, facilitating easy access and management for administrators.

## User Profile Overview

The top section of the User Details Page showcases the following crucial user information:

<figure><img src="/files/u67htGMwN3EoCJvJYJkp" alt=""><figcaption></figcaption></figure>

#### Profile Picture

The user's profile picture is prominently displayed, offering a visual identification of the user. This feature aids in personalizing the user experience and making navigation more intuitive.

#### User's Status

Right next to the profile picture, users can find the current status of the user, which indicates whether the user is Active, Inactive, or Pending. This status helps in quickly understanding the user's engagement level.

#### Login ID

This is a unique identifier for the user within the system. It serves as a key piece of information for various administrative processes, including user tracking, support, and security checks.

#### Email ID

The user's Email ID is displayed, providing an essential communication link. It is used for sending notifications, password resets, and other critical communications.

#### Mobile Number

The user's mobile number is listed if provided. This number can be utilized for two-factor authentication, urgent alerts, or direct contact purposes.

This structured format ensures that an administrator or any authorized viewer can quickly access and understand a user's essential information without navigating through multiple pages.

#### **Risk Details**

The user's risk details are visible on the page to notify that the user is a high-risk user. On further clicking on that page, it shows the User's Risk metrics.

<figure><img src="/files/89grtkago5R2Fzyv9USC" alt=""><figcaption></figcaption></figure>

## User Info Page

This page provides a comprehensive overview of the user information managed within our system. The data is categorized into several sections to facilitate easy access and understanding of each user's profile. These sections are detailed below.

<figure><img src="/files/MDNmEWSSoTAJfXRYR5xx" alt=""><figcaption></figcaption></figure>

#### Basic Information

* **First Name**: The user's given name.
* **Middle Name**: The user's middle name, if applicable.
* **Last Name**: The user's family name.
* **Grade**: The user's grade (a set of values needs to be defined for this field in the Masters).
* **Designation**: The specific title or position the user holds.
* **Date of Birth**: The user's birth date.
* **Age**: The user's current age is calculated from the date of birth.
* **User Type**: Classification of the user based on the user types defined in the system.
* **Login ID**: The unique identifier used by the user to access the system.

#### Contact Information

* **Country**: The country where the user is located.
* **City**: The city within the country.
* **Mobile**: The user's mobile phone number.
* **Email**: The user's email address is used for electronic correspondence.
* **Landline**: The user's landline phone number, if applicable.
* **Address**: The user's full postal address.

#### Organization Information

* **Employee ID**: A unique identifier assigned to the user within the organization.
* **Department**: The department to which the user is assigned.
* **Start Date**: The date when the user commenced their current position.
* **End Date**: If applicable, the date when the user's current position will or has ended.
* **Manager**: The user's direct supervisor or manager.

#### Custom Attributes

Additionally, this page may display values for custom attributes specific to our organization. These attributes allow for the capture of information not covered by the standard categories but deemed necessary for our operations.

This comprehensive user information page ensures that all pertinent data regarding an individual within our organization is readily accessible, facilitating smooth operations, management decisions, and communication.

## Applications Page

This page is designed to streamline the management and assignment process of applications for users. It offers a section where you can easily view all your assigned applications along with their current status. Additionally, it allows for the straightforward assignment of new applications to your profile.

<figure><img src="/files/1SP7k8WlASYWRahISdsK" alt=""><figcaption></figcaption></figure>

* **Viewing Assigned Applications:** Upon accessing the page, you will be presented with a list of applications currently assigned to you. Each application tile gives a snapshot of the application's status, enabling you to quickly assess which applications require your attention.

* **Assigning Roles:** Application Roles can be assigned to the user using the Assign Role option. This option also allows the assignment of multiple roles to a user.

  <figure><img src="/files/Y1EIAJoZ0ySUhlew0gll" alt=""><figcaption></figcaption></figure>

* &#x20;**Unassign Assigned Applications:** Assigned applications can be removed using the delete option in the (⋮) menu.

  <figure><img src="/files/xZMEFUnJeJ03P0aAc3UA" alt=""><figcaption></figcaption></figure>

* **Assigning New Applications:** Should you need to add more applications to your list, the process is simple. Just click on the **Add New Button** located on the interface. This action opens up a selection window where you can choose additional applications that you wish to assign to the user.

<figure><img src="/files/zZUhfVFMg09nhov5C9Vl" alt=""><figcaption></figcaption></figure>

* **Searching for Applications:** To facilitate ease of access, a search function is incorporated into the interface. This feature allows you to quickly find specific applications by typing the name or part of it into the search bar, saving you time and effort from manually scrolling through the list of applications.

<figure><img src="/files/NxkXSUOttdPGoQu9dElh" alt=""><figcaption></figcaption></figure>

**Note:** *In instances where an application has not been successfully assigned, the interface provides direct actions to resolve the issue without needing to navigate away from the page. Each application tile includes an (*⋮) *menu with two options:*

* ***Retry:** If an application's assignment process encounters an issue, you can select this option to attempt assigning the application again.*
* ***Delete:** If the assignment issue remains unresolved or if you no longer wish to keep the application, you can choose to remove the application from your list entirely.*

## **Groups Page**

This page provides an overview of the groups to which a user is assigned, reflecting the current status of each.&#x20;

<figure><img src="/files/dxtnHPbEO776c0NS3xYv" alt=""><figcaption></figcaption></figure>

#### Viewing Assigned Groups and Their Status

Upon accessing the page, users are presented with a list of all the groups to which they are currently assigned. Each entry includes the **group's name, description**, **number of users in the group** and **number of applications assigned to the group**.

#### Adding New Groups

To enhance the user's role or access within the system, the **Add New Button** is prominently positioned. This option allows users to be added to more groups, expanding their access and functionalities within the application. The process is designed to be straightforward, guiding the user through a simple process to ensure accurate group assignments.

#### Editing Group&#x20;

This menu option, found within the ellipse (⋮) menu, takes you to the groups pag,e where you may edit any information related to the group

#### Removing Group Memberships

Equally important is the capacity to manage the departure from groups, which is facilitated by the Delete Group option. Also found within the ellipse (⋮) menu, this feature does not delete the group itself but rather unassigns the user from the selected group. This action ensures the user's access and permissions within the application are precisely tailored, maintaining security and relevance.

## &#x20;User Activity Log Page

This page shows the user-specific audit log for all the various actions and activities performed by the user. This may include all activities related to the user, as shown below

<figure><img src="/files/nwMKIrmBWqmvFqKMiQ5D" alt=""><figcaption></figcaption></figure>

## User's  Settings Page

**Status:**

You can change the status of users and accounts in our system to manage access and control.

#### For Users:

* **Locked**: Stops user access temporarily. This is used for security reasons or if there are too many failed login attempts.
* **Unlocked**: Gives access back to the user, allowing them to log in and use the system.

#### For Accounts:

* **Active**: The account is in use, and everything works normally.
* **Inactive**: Temporarily not in use, but can be activated again.
* **Delete**: The account is deleted and moved to suspended accounts

<figure><img src="/files/LCeeTsyI7HEF3MT7WYW6" alt=""><figcaption></figcaption></figure>

#### **Reset Password**

The administrator has three distinct options for configuring the password reset process, allowing them to choose a method that best fits the organization's security policies and workflow.

1. **Generate Password**: This option allows the user's manager to generate a random, one-time password.&#x20;
2. **Generate Password and Send to User's Email**: With this option, the manager triggers the password reset, and the system automatically generates a new password and sends it directly to the user's registered email address.&#x20;
3. **Send Reset Password Link to User's Email**: This is the most secure option. The manager initiates the process, but instead of a password, the system sends a secure, time-sensitive "Reset Password" link to the user's email. The user must click the link to create a new password.

   <figure><img src="/files/k8eMCnklY1Lygp4XCw9B" alt=""><figcaption></figcaption></figure>

**Generate Password**

<figure><img src="/files/PXtYzHUFwCx96wQfFLAH" alt=""><figcaption></figcaption></figure>

**Generate Password and Send to Users' Email**

<figure><img src="/files/IeVyrdg7SAMDgZyosVZU" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/F85UppKmZ1S4Dp4yWD3Z" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/bOizmnrtbYZt69sj6t2P" alt=""><figcaption></figcaption></figure>

**Send Reset Password link to Users Email**

<figure><img src="/files/RmXf4D9bVwER6T8DHXZz" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/7oCwx8uhUskVrgppq2qc" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/U5vsG8ulxaBL4Qix83E7" alt=""><figcaption></figcaption></figure>

#### **RBAC**

This section can be used to assign tenant-wide roles defined in the master to the user.

<figure><img src="/files/3UzN2gTDHaZGdaHKkswP" alt=""><figcaption></figcaption></figure>

**Secret Questions**

This section shows a list of secret questions selected by the user

<figure><img src="/files/To2sT7CS5jTslraEHEmq" alt=""><figcaption></figcaption></figure>

**Additional MFA**

Administrators can view the MFA mechanisms configured by the user, as well as remove the configured MFA if required for a specific user

<figure><img src="/files/AV5PYNt9v83UzLY4Icza" alt=""><figcaption></figcaption></figure>

### Trusted Devices by User

If Adaptive MFA is configured for users and a configuration for  Device Trust is done, Cymmetri maintains a list of Trusted devices that satisfy the conditions of the Device Trust configuration. This list of devices trusted based on the configuration done by the admin is listed on this page with the following information about each device: **Browser**, **OS**, **Created At**, **Trusted**, **Action**(remove device)

<figure><img src="/files/4Pf7EAtD6JihKtqKa7Rm" alt=""><figcaption></figcaption></figure>

### User's Sessions

This page provides Cymmetri administrators with the capability to monitor and manage all user sessions. It provides the following information: Browser, OS, Created By, IP Address, Created At, and Action (delete session). A user may have multiple session entries if the Multiple Session configuration is enabled.

<figure><img src="/files/dKAyh5JHzsR6U8ticzkS" alt=""><figcaption></figcaption></figure>

### Managed View

The Managed View page shows the user data based on various provisioning applications assigned to a user. This page shows the **Attribute Name, Managed System Value,** and **IDM Value**&#x20;

* **Attribute Name:** Attribute name as defined in the policy attribute page of the provisioning application
* **Managed System Value:** Value as saved in the provisioning application
* **IDM Value:** Value as saved in Cymmetri

<figure><img src="/files/3nSfCH2JFu10DisLNy8O" alt=""><figcaption></figcaption></figure>

### Delegation

In Cymmetri,  one of the features available to users is the ability to delegate self-service access. This capability enables users to assign their access rights and responsibilities to other users temporarily. Ideal for scenarios such as vacations, business trips, or whenever a user needs someone else to manage their duties without forfeiting their credentials or compromising security.

This page shows the delegation provided by the user; this may be currently in progress or the delegation that was last completed.

The page shows the status of the Delegation (INPROGRESS, COMPLETED), Designated To, Start Date, End Date, and the list of Excluded Applications(if any)

<figure><img src="/files/noy4inBe8y4T0cMRuVXB" alt=""><figcaption></figcaption></figure>


# Bulk User Actions

This feature allows administrators to perform multiple user management tasks simultaneously, streamlining the process of managing a large number of user accounts. The following actions can be performed in bulk, namely:

* Lock User
* Unlock User
* Activate User
* Deactivate User
* Delete User

**Lock User:** This action disables a user's access to all services and applications without deleting their account. A locked user cannot log in until their account is unlocked.

<figure><img src="/files/uru4UOBSIWuitvY5PTWQ" alt=""><figcaption></figcaption></figure>

**Unlock User:** This action restores a user's access to their account, allowing them to log in and access services.

<figure><img src="/files/vkwtwOnsP7MItuccth52" alt=""><figcaption></figcaption></figure>

**Activate User**: This action makes a user account active, allowing the user to access services. This is typically used for newly created accounts or accounts that were previously deactivated.

<figure><img src="/files/BXbb3QVpsZ4FgmAAaLD3" alt=""><figcaption></figcaption></figure>

**Deactivate User**: This action temporarily suspends a user's account, preventing them from logging in or accessing any services. The account and its data are retained and can be reactivated later.

<figure><img src="/files/3QAuqr7MqabDdor8Dfpu" alt=""><figcaption></figcaption></figure>

**Delete User:** This action permanently removes a user account and all associated data from the system. This action is irreversible.

<figure><img src="/files/D7lsuT2M0YK5FZXgB6uP" alt=""><figcaption></figcaption></figure>

#### Bulk Group Assignment

This feature allows administrators to assign multiple users to a local group in a single operation. The process is a two-step workflow to ensure accuracy and prevent accidental changes.

**Step 1: Review User Selection**

* The administrator selects a group of users to be assigned to a specific local group.
* A review screen is presented, displaying a list of the selected users.
* The administrator can add or remove users from this list before proceeding.

<div align="left"><figure><img src="/files/5REZkZf7f7eIo5XQaeyl" alt=""><figcaption></figcaption></figure></div>

**Step 2: Finalize Assignment**

* The administrator confirms the final list of users to be assigned to the group.
* The system then performs the assignment action for all users on the finalized list.
* A confirmation or action summary is typically displayed, showing the status of the bulk assignment.

**Bulk Action Dashboard**

A dedicated dashboard provides a summary of all recent bulk actions. This dashboard allows administrators to review:

* The type of action performed (e.g., "Lock User," "Assign Local Group").
* The total number of users affected by the action.
* The status of the action (e.g., "Completed," "In Progress," "Failed").
* A detailed log of each user's outcome, including any errors that may have occurred.

This dashboard provides a transparent overview of all bulk operations, ensuring accountability and easy troubleshooting.

<figure><img src="/files/mfeikk75MuzP1jOnrLXv" alt=""><figcaption></figcaption></figure>


# Create Users

While users may be imported and synchronized from other Identity providers, sometimes users may need to be added manually by the administrator.

### Steps to Create Users: <a href="#createusers-stepstocreateusers" id="createusers-stepstocreateusers"></a>

1. First, navigate to the **User** configuration page by clicking on the **Identity Hub > User** menu on the left-hand side panel.

   <figure><img src="/files/ww8JQVnpc9Cb1O7Y15uo" alt=""><figcaption></figcaption></figure>
2. Click on the “**+Add New**” button.

   <figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003438790/original/kkU5pBH4RBVGBfV_oQl4Ke_X5dGOgzrSaw.png?1649344742" alt=""><figcaption></figcaption></figure>
3. Enter the required information and scroll down to add further information.

   <figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003438799/original/FpPKM4nhyj-5o5_RfOPXcYS8iFjzBrVzyA.png?1649344770" alt=""><figcaption></figcaption></figure>
4. Click on the Save button to move to the next configuration page, and copy the automatically generated password.&#x20;

   <figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003449872/original/VoVNv2tnMZHwW0YLNENAo7xnidHRhN31hw.png?1649358033" alt=""><figcaption></figcaption></figure>
5. Optionally, a group can be assigned to the user.

   <figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003438854/original/97chf0NJoQWOFysPK-8MLjM27lzVOmILwg.png?1649344854" alt=""><figcaption></figcaption></figure>
6. And also, applications can be assigned to the user.

   <figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003438855/original/4HkaDvLL4gjnxyAnl6AEoW_7VCIUlSwMGg.png?1649344863" alt=""><figcaption></figcaption></figure>

Once all the above steps are completed successfully, the user is created with the assigned groups and assigned applications.


# Edit Users

The Edit User functionality allows administrators to modify user details within the Identity Hub.&#x20;

<figure><img src="/files/KAlDpFO1gDhpl9ufDoyW" alt=""><figcaption></figcaption></figure>

### Steps to Edit a User: <a href="#createusers-stepstocreateusers" id="createusers-stepstocreateusers"></a>

* Navigate to **Identity Hub -> Users**, select the specific user you wish to edit, then go to the **User Info** page and click on **Edit User**

  <figure><img src="/files/X5P3uyNK1WlkGjSWminV" alt=""><figcaption></figcaption></figure>
* The **Edit User** form will be displayed, where you can modify the user's information as needed.&#x20;

<figure><img src="/files/5TuAvCEHrvzWQrn7Pqn9" alt=""><figcaption></figcaption></figure>

* After making the necessary changes, click **Save** to update the user's details.

<figure><img src="/files/NRNirm6KSLBHJJvhjEWR" alt=""><figcaption></figcaption></figure>

* Saving the changes may also trigger updates in target applications, depending on the configuration. This ensures that any modifications made are synchronized across all relevant systems.


# Delete Users

In user lifecycle management, the transition of a user's status from Suspended to Archived initiates a critical de-provisioning sequence. This process is designed to ensure that all user entitlements are permanently revoked from target applications, a final action controlled by a configurable flag.

**User Creation and Initial Status**: The process begins with a user being created in the system, with their initial status set to Active.

<figure><img src="/files/9BdT4MbkdyM0aQI3rG2e" alt=""><figcaption></figcaption></figure>

**Suspension Initiation**: An administrator initiates the suspension of a user by selecting the "Delete User" option. This action changes the user's status to Suspended, thereby revoking their login privileges while retaining their account information.

<figure><img src="/files/bjVlYTWPngukUwUN3rfs" alt=""><figcaption></figcaption></figure>

**Movement to Suspended List**: The user's profile is then moved to the Suspended Users list, allowing administrators to differentiate between active and temporarily disabled accounts.

<figure><img src="/files/Q5txB7e9cgfIbzkFe4HL" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/L7WFHiRZhridukMu9yl8" alt=""><figcaption></figcaption></figure>

**Log Verification**: The administrator can verify this status change by reviewing the system logs. The logs will record the status transition from "ACTIVE" to "DELETE." This log entry also provides a clear record of the user's application status, indicating if any associated applications were also de-provisioned at this stage.

<figure><img src="/files/WXR1zDeo1jrkTJXBwzc4" alt=""><figcaption></figcaption></figure>

**Forced Deletion**: Should the administrator require immediate, permanent de-provisioning, the "FORCE DELETE" option can be used. This action bypasses the standard suspended state and triggers the final de-provisioning call immediately, ensuring that all entitlements are permanently removed.

<figure><img src="/files/VGBgKhzlsE293VwNTc39" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/AIcJpGwOLmnCN0BofsZy" alt=""><figcaption></figcaption></figure>

**Final Validation**: To confirm the user's complete de-provisioning, the administrator can once again validate the status in the system logs. The logs will confirm the final deletion and provide a complete audit trail of the user's lifecycle, from creation to final de-provisioning.


# Suspended Users

The admin can delete the user from the users tab in the identity hub section.

<figure><img src="/files/zIBEXHr8ByCvszjigyPb" alt=""><figcaption></figcaption></figure>

After the user is deleted, they are moved to the Suspended Users tab.

<figure><img src="/files/7uffRWdpE627hkVvS1aq" alt=""><figcaption></figcaption></figure>

In the section for suspended users, the administrator has two options: they can choose to

* **Resume User** - Which relocates the user back to the all users section OR
* **Force Delete** - This transfers the user to the archived users section, where retention of the user is not possible&#x20;

<figure><img src="/files/rlOzmW9heY6YuHXURAvk" alt=""><figcaption></figcaption></figure>


# Archived Users

This section stores and manages user accounts that have been archived or deactivated. These accounts are usually no longer active but are retained for historical or compliance purposes.

You can see the other condition when the users are moved to the archived users [here. ](/getting-started/personalization/general-config#suspend-config)

<figure><img src="/files/JPHu3I8Gp9aIUwIG2P1t" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/0TcRIEp8u7HbSGC7o3Fs" alt=""><figcaption></figcaption></figure>


# Create Groups

Administrator tasks pertaining to bulk users may be eased by creating groups of users.

### **Creating User Groups**

Access the group configuration page by clicking Identity Hub > Groups on the left-hand side.

Click on the “**+Add New**” button to start creating a new group

**Group Name:** Indicates the name of the group.

**Group Type:** For environments not using Active Directory, either Local or Remote Group may be chosen. In case Active Directory is being used for synchronization in the tenant, the appropriate type according to the group policy object must be chosen.

**Parent Group:** If a parent group is chosen, all the policies and rules applicable to the parent group will be assigned to this new group, in addition to the policies and rules specifically applied to this new group.

**Group Description:** Optionally, a description may be provided to the group.

<figure><img src="/files/rtK0hGBFCFM9qnwJTVak" alt=""><figcaption></figcaption></figure>

Once all the details have been entered, click on the **Save** button, and a new group is created.

<figure><img src="/files/I8qZU0YgeTDfRdYBxCGO" alt=""><figcaption></figcaption></figure>


# Importing Users

Users may be imported into the Cymmetri platform using the bulk Import Users feature.

*<mark style="color:green;">Please Note: User import process follows the synchronization policies as defined</mark>* [*<mark style="color:green;">here</mark>*](/lifecycle-management/application-management/reconciliation-how-to/configuring-reconciliation-process#synchronizing-scenarios-and-their-corresponding-outcomes)*<mark style="color:green;">.</mark>*

### Importing Users

For Importing Users in the Cymmetri platform administrator needs to click on **Identity Hub > User** menu and then click on the **Bulk Import > Import Users** button.

<figure><img src="/files/gaF3hT72lt7wkwB0w29r" alt=""><figcaption></figcaption></figure>

A screen pops up that lets you select the CSV file you want to upload to import the users, Upload the CSV file, you may also use the sample data file available and modify it to match your user details.

<figure><img src="/files/yveyfqkadGOyrzsWSi84" alt="" width="380"><figcaption></figcaption></figure>

Click on the **Upload File** button and select the file you wish to import

<figure><img src="/files/1FrikdkX8x9PojATT8Qf" alt=""><figcaption></figcaption></figure>

Once the file is selected ensure that the default parameters selected match your requirements else you may change these parameters as per your requirement and click on the **Next** button.

<figure><img src="/files/5FdifyovovdhOhY6LD3L" alt=""><figcaption></figcaption></figure>

Match the Column names from the CSV file with the Cymmetri User Attributes using this File Info dialog box.

<figure><img src="/files/jdPfoQcduGRF57F1xOao" alt=""><figcaption></figcaption></figure>

Scroll down and click on the **Import** button.\
\
\&#xNAN;***Note:** A "Skip user workflow" check box is available to skip execution of any user workflow configured for the creation of users, if not selected it may trigger user creation workflow, and the process of importing users may slow down due to the numerous approvals that the approver might have to do.*

Once Imported results of successfully Imported Users, Duplicate Users, or any error that occurred during import can be seen in **Logs > Import History** page

<figure><img src="/files/YWKl5jUuZx26VQTn9dzs" alt=""><figcaption></figcaption></figure>


# Assigning Users to Groups

## Assigning Users to a Group

Users once created in the Cymmetri platform can be assigned to a group. Assigning users to a group helps ease the administrative efforts to apply the same policies and assign applications to multiple users.

When assigning users to groups, various approaches can be used:

* Adding User to Group (from the Group Page)
* Assigning a Group to a User (from the User's Page)
* Bulk Assigning Users to a Group (Using Group Assignment on Group Page)

### Adding User to Group <a href="#assigninguserstoagroup-addingusertogroup" id="assigninguserstoagroup-addingusertogroup"></a>

First, the administrator needs to click on the group name and enter the configuration for the group.

<figure><img src="/files/oaUcrXpitLgzLukgWfMe" alt=""><figcaption></figcaption></figure>

Now, go to the Users Page and click on the **+Add** button to get a list of users to add to the group

<figure><img src="/files/OLzDEifqmmlf0NKpqdfP" alt=""><figcaption></figcaption></figure>

3\. Now, click on the assign button next to the user you wish to add to the group. Once assigned, the user can be seen on the Users page of the Group as shown below:

<figure><img src="/files/ojTHPwCOp23lqpQcP03a" alt=""><figcaption></figcaption></figure>

### Assigning a Group to a User

For this approach, the Administrator needs to go to **Identity Hub > User** page and then select the user from the list to whom the group needs to be assigned

<figure><img src="/files/pun8Ufya5bqCb0cxAxaR" alt=""><figcaption></figcaption></figure>

Go to the user's page, select the **Groups** menu, and click on the "**+Assign New**" button

<figure><img src="/files/b8bX7hr2yTzH1XJjqmSp" alt=""><figcaption></figcaption></figure>

This opens a pop-up window where a list of all groups is visible

<figure><img src="/files/drq4FX41h8PVylkI9sjL" alt=""><figcaption></figcaption></figure>

Click on the assign button, and the group is assigned to the user, or you may say the user becomes a part of the group

<figure><img src="/files/LQHUdZwFVM4eL0F7j0RN" alt=""><figcaption></figcaption></figure>

### Bulk Assigning Users to a Group

For this approach, the Administrator needs to go to **Identity Hub > Group** page and then click on the **Group Assignment** button

<figure><img src="/files/CmwhyhJJZyold24EAbrp" alt=""><figcaption></figcaption></figure>

A screen pops up that lets you select the CSV file you want to upload to import the users that need to be assigned to the group. This CSV file needs to have one column that contains the login ID of users. Upload the CSV file, you may also use the sample data file available and modify it to match your user's login ID.

<figure><img src="/files/c7yzvdgjEl4l5AozIvDe" alt=""><figcaption></figcaption></figure>

Once the file is selected and uploaded, next you need to select the group to which you want to assign the users.

<figure><img src="/files/rRV8z3UgUhmYcHF2cekB" alt=""><figcaption></figcaption></figure>

After selecting the group, the column in the CSV file needs to be mapped with the Cymmetri login column.

<figure><img src="/files/CUU4UfxYi5zl9Nd7zuxM" alt=""><figcaption></figcaption></figure>

Once mapped, click on the import button, and the users will be mapped to the assigned group, provided the login ID is correct

<figure><img src="/files/w9q8NUBTQ0cBNrxoxJRI" alt=""><figcaption></figcaption></figure>

Results of successfully Imported Users, Duplicate Users, or any errors that occurred during import can be seen in the **Logs > Import History** page

<figure><img src="/files/7eaNMNenUNO4biryCVDt" alt=""><figcaption></figcaption></figure>


# Delegation


# Setting up Delegation

Delegation as a process in the Cymmetri platform refers to the ability of any end-user to delegate their responsibilities to any other end-user on the platform.\
\
As such, delegation provides the ability to the delegatee to perform various actions, including Single Sign On, Application Requests, managing workflows by providing approvals, and performing Cymmetri administrative actions (if the delegator has the required permissions on the platform), among other actions. However, the login flow for the delegatee stays the same.

### **Configuring the delegation on your tenant**

Access the Delegation administration panel, by clicking on the **Configuration** left-hand side menu item and then clicking on the **Delegations** menu item.

For any user to be able to delegate their work to other users, the user should be added to the delegation users list; To Add Users to the delegation list so that they can delegate their activities, click on the Assign New button and select one or more users to add to this list.

User and Assignee Consent

The User and Assignee Consent sections allow organizations to align task delegation practices with their unique policies. This customizable feature empowers administrators to define specific consent texts, ensuring that both the user delegating a task and the delegatee receiving it acknowledge and agree to these terms.

The user consent will be displayed whenever the delegator (user) goes to their settings in their Workspace and assigns a delegation to an end-user (delegatee). This consent will be recorded in the Cymmetri backend for audit logging purposes.

Similarly, the assignee consent will be recorded when the end-user (delegatee/assignee) logs into the account for their manager (delegator/user).&#x20;

Here's how it works:

1. **Administrator Configuration:** Administrators can craft consent texts tailored to their organization's requirements. These texts typically outline the responsibilities, expectations, and any legal or compliance aspects associated with task delegation.
2. **User Perspective:** When a user decides to delegate a task to someone else, they will be presented with the customized consent text. The user must carefully review and accept the terms before proceeding with the delegation process. This step ensures that the user is aware of the implications of task delegation and is willing to proceed.
3. **Assignee Perspective:** On the other side, the delegatee who is about to receive the delegated task will also be presented with relevant consent text. They must thoroughly read and accept these terms before taking on the responsibility. This step helps establish clarity and accountability for the delegatee.

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003445550/original/hefolwbfbyRr9Jcr2nas6X6aNidRWvzmtA.png?1649351924" alt=""><figcaption></figcaption></figure>


# Delegating Work to Delegatee

For any user to be able to delegate their work to other users, the user should be added to the delegation users list; Check [here ](/identity-hub/managing-users-and-groups/delegation/setting-up-delegation)how to Add Users to the delegation list so that they can delegate their activities.

### Delegate Work to Delegatee

Following are the steps to delegate work to a delegatee:

The logged-in user needs to go to their Settings Page by clicking on the user's username on the top right

<figure><img src="/files/EOPS8wNygi8prVOd0vfa" alt=""><figcaption></figcaption></figure>

Once on the Settings Page user needs to click on the My Delegations menu

*Note: My Delegations menu will appear only if the logged-in user is added to the delegation users list.* [Here](/identity-hub/managing-users-and-groups/delegation/setting-up-delegation) *is how to Add Users to the delegation list.*

**Toggle Status:** Enable the Toggle Status to Active

**Start Date:** The date from which the user is delegated the work

**End Date:** The date up to which the access is delegated

**Delegated To:** The user (delegatee) to whom the work is delegated. This dropdown populates the list of all users to whom the task can be assigned

**Excluded Applications:** List of applications whose access is not provided to the delegatee

<figure><img src="/files/gn4rVyn5CXLvVVi9kydD" alt=""><figcaption></figcaption></figure>

Once all the details are filled the user is expected to accept the consent to be able to configure the delegation. The consent looks something similar to as shown below:

<figure><img src="/files/kDCTzfVlutePIMF9HWG9" alt="" width="431"><figcaption></figcaption></figure>

Once confirmed the user needs to click on the I agree check box and save the delegation.

<figure><img src="/files/iFBy2aGH48BD4o08dw1J" alt="" width="443"><figcaption></figcaption></figure>

Once saved the delegatee can see and accept the delegation in their My Delegation Page under Settings.


# Accepting Delegation

Upon receiving a delegation request, the user is notified via email and within the platform.&#x20;

To view the delegated task the delegatee can go to **Settings->Delegation** to Me to see details about the delegated tasks and the user who has assigned the task

<figure><img src="/files/4aljLskhjibJW8Xji4w8" alt=""><figcaption></figcaption></figure>

The user needs to click on the Accept button to accept the delegation. On clicking the Accept button an Assignee(delegatee) Consent is shown which the users need to read and confirm. The Consent also shows details of the delegator and the duration of the delegation.

<figure><img src="/files/961JuomAFQukwyhZeoOg" alt="" width="440"><figcaption></figcaption></figure>

Once the user accepts the delegation the user sees a login button, to login into cymmetri as the delegator

<figure><img src="/files/eoByniMKiqHYrHEECt2F" alt=""><figcaption></figcaption></figure>

On clicking the login button the delegatee is redirected to the delegator's My Workspace Dashboard.&#x20;

<figure><img src="/files/jReeuJgsBEGQeFOIhcTZ" alt=""><figcaption></figcaption></figure>

The delegatee can access and perform actions on all the applications assigned to them and if any application is excluded during delegation they are not visible to the delegatee.

<figure><img src="/files/jqo9FSSMIABZvdIJEM0l" alt=""><figcaption></figcaption></figure>


# All Users Session

## All Users Session

This page provides Cymmetri administrators with the capability to monitor and manage all user sessions across the entire platform.&#x20;

<figure><img src="/files/mBLaIzMDeOoFtSCcfj9k" alt=""><figcaption></figcaption></figure>

This functionality allows administrators to gain insights into ongoing user activities, view active sessions, and, if necessary, terminate or manage these sessions for security, compliance, or administrative purposes.&#x20;

The admin can terminate all the user sessions at once or select them individually. The page also has a search option for the admin to search the desired user session.


# Self Registration

Self-registration empowers users with greater control over their accounts, reducing the administrative burden on IT and security teams. These enhancements focus on a secure and streamlined self-registration process and improved password management.

#### New Features:

* Configurable Self-Registration: Cymmetri now supports self-registration, allowing new users to create their accounts securely. This process is governed by pre-defined parameters and policies, ensuring that all new accounts meet your organization's security and compliance standards from the outset.
* Activation and Password Management:
* Activation Link: Once a new user self-registers, the system automatically sends them an activation link. This link allows them to set their own secure password, finalizing their account setup.
* Password Reset Link: For existing users, administrators, or managers can now easily send a password reset link. This empowers users to securely reset their login credentials independently, eliminating the need for manual password changes by support staff.

These updates automate key user management tasks, providing a more efficient and secure experience for both users and administrators.

<figure><img src="/files/bwhpItpdM3jiRIxVKHCo" alt=""><figcaption></figcaption></figure>

To enable and manage these features, administrators must perform the following configuration steps:

1. Access Configuration Settings: Navigate to Configuration → Self Registration Config within the Cymmetri interface.
2. Choose Password Generation Method: The administrator has two primary options for password management:
3. Generate Activation Link: This option, as described above, sends a link to the user, allowing them to create their own password.
4. Generate Password: This alternative automatically generates a temporary password that the user must use to log in for the first time before being prompted to change it.
5. Configure Hooks and Registration Fields:
6. Pre-Hook and Post-Hook: The administrator must set up both pre-hook and post-hook configurations. These are custom scripts or actions that can be run before or after a new user account is created, allowing for custom validation or integration with other systems.
7. User Registration Fields: The administrator must define the fields that will be displayed to users during the self-registration process (e.g., First Name, Last Name, Email, Department).

Add Custom Fields: For increased flexibility, the administrator can add new User Registration Fields by clicking + Add Registration Field, allowing for the collection of additional information relevant to the organization.

<figure><img src="/files/1emEJpTnH9yA1prWNG6X" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/yd6o4sAA0veSpQE2Lx35" alt=""><figcaption></figcaption></figure>


# Authentication


# Identity Provider


# Internal IDP


# Introduction

Cymmetri's Internal Identity Provider (IDP) is a powerful authentication solution that supports seamless integration with various Identity Providers (IDPs).&#x20;

We will explore the configuration options for three types of IDPs:&#x20;

* Cymmetri,&#x20;
* Active Directory, and&#x20;
* LDAP.&#x20;

The flexibility of the Cymmetri Internal IDP allows you to manage multiple IDPs of the same type, making it easy to adapt to diverse environments with different Active Directory/ LDAP instances.  Cymmetri's  Internal IDP aims to provide a centralized and adaptable authentication solution for your environment, supporting various IDP types.

To access Internal Identity Providers navigate to **Authentication-> Identity Provider->Internal IDP**

<figure><img src="/files/uVXVn7z4op30Irnbr3Pv" alt=""><figcaption></figcaption></figure>

To customize the applicability of different IDPs, administrators need to configure [Authentication Rules](/identity-hub/authentication/authentication-rules). These rules enable the configuration of various conditions. When these conditions are met, the corresponding authentication mechanism or IDP is used for user authentication.


# Internal Identity Provider Configuration: Cymmetri

To access Internal Identity Providers navigate to **Authentication-> Identity Provider->Internal IDP.**

<figure><img src="/files/j7jFPT02r3z8zbKv5TwS" alt=""><figcaption></figcaption></figure>

Since Cymmetri is a default Internal IDP no configuration is needed for it. An administrator may still have an option to disable Cymmetri Authentication which can be done by editing the Cymmetri Authentication Internal IDP mechanism.

<figure><img src="/files/RhnOvyLMorobVBun2ThH" alt=""><figcaption></figcaption></figure>

An administrator may also change the Display Name and/ or Description as shown in the screen above.


# Internal Identity Provider Configuration: Active Directory

Active Directory (AD) is a robust Identity Provider (IDP) in enterprise environments. It authenticates and authorizes users, facilitating seamless access to resources. AD centralizes user management, streamlining security protocols and ensuring efficient user provisioning.

Active Directory can be utilized in Cymmetri as an Identity Provider (IDP), leveraging existing AD user accounts to access Cymmetri, as the platform supports the LDAP protocol.

For configuring AD as an Identity Provider, the primary service needed is the **Adapter Service.**

### The Adapter Service

The Adapter Service or Auth Adapter Service is exposed as a rest service that runs on HTTPS and acts as an adapter to facilitate authentication using the LDAP protocol which is often employed for authentication purposes in various systems and every adapter service instance is called by the **secret** generated while installation/configuration of adapter service.

The rest endpoints are called by cymmetri-cloud AuthenticationService to connect to On-Prem AD/Ldap or cloud AD/Ldap. The AdaptorService is used to test connections, authenticate, change, and reset the password of a user.

### Configuration

For configuring Active Directory as an internal IDP  navigate to **Authentication -> Identity Provider -> Internal IDP.** Here you may either configure the already created **AD Authentication** instance or **+Add New.**

<figure><img src="/files/Tvz3WJpatzxRG4BM34VX" alt=""><figcaption></figcaption></figure>

In either case, a screen opens where you need to provide the below-mentioned details.

* **Name**: AD Authentication
* **IDP Type**: Active Directory
* **Description:** A general description of the IDP type
* **Status:** Active
* **Adapter Service Domain:** Location (IP) of the server on which the Adapter Service is deployed
* **Adapter Service Secret:** The **secret** generated while installing/configuring of adapter service
* **Base DN:** Active Directory root domain name
* **Search Scope:** A search scope for locating users in Active Directory

  <figure><img src="/files/6hWIL3yKiGmkPh4w8uPt" alt=""><figcaption></figcaption></figure>

Once all the details are entered Save the changes and Test the Connection using the **Test Connection** button.

For enabling Active Directory to be used as an IDP for a specific set of users an Authentication Rule needs to be configured. [Here ](/identity-hub/authentication/authentication-rules)you can see the steps on how to configure Authentication Rules.

Once the rule is configured, whenever a user matches the rule conditions, their credentials are verified against those stored in the Active Directory. Upon successful verification, the user is granted access to log in to Cymmetri.


# Internal Identity Provider Configuration: LDAP

Lightweight Directory Access Protocol (LDAP) serves as an important Identity Provider (IDP) in enterprise environments. It authenticates and authorizes users, facilitating seamless access to resources. LDAP is commonly used as a directory service for managing user identities and authentication information within an organization.

LDAP can be utilized in Cymmetri as an Identity Provider (IDP), leveraging existing user accounts to access Cymmetri, as the platform supports the LDAP protocol.

For configuring LDAP as an Identity Provider one of the primary services needed is the **Adapter Service.**

### The Adapter Service

The Adapter Service or Auth Adapter Service is exposed as a rest service that runs on HTTPS acts as an adapter to facilitate authentication using the LDAP protocol which is often employed for authentication purposes in various systems and every adapter service instance is called by the **secret** generated while installation/configuration of adapter service.

The rest endpoints are called by cymmetri-cloud AuthenticationService to connect to On-Prem AD/Ldap or cloud AD/Ldap. The AdaptorService is used to test connections, authenticate, change, and reset the password of a user.

### Configuration

For configuring Active Directory as an internal IDP  navigate to **Authentication -> Identity Provider -> Internal IDP.** Here you may either configure the already created **LDAP Authentication** instance or **+Add New**

<figure><img src="/files/hhigIr73zGHBIKAF1HTZ" alt=""><figcaption></figcaption></figure>

In either case, a screen opens where you need to provide the below-mentioned details

* **Name**: LDAP Authentication
* **IDP Type**: Open LDAP
* **Description:** A general description of the IDP type
* **Status:** Active
* **Adapter Service Domain:** Location (IP) of the server on which the Adapter Service is deployed
* **Adapter Service Secret:** The **secret** generated while installing/configuring of adapter service
* **Base DN:** LDAP root domain name
* **Search Scope:** A search scope for locating users in LDAP

  <figure><img src="/files/qCq3XEJbAOkyrAyQSYJ4" alt=""><figcaption></figcaption></figure>

Once all the details are entered Save the changes and Test the Connection using the **Test Connection** button.

For enabling Open LDAP to be used as an IDP for a specific set of users an Authentication Rule needs to be configured. [Here ](/identity-hub/authentication/authentication-rules)you can see the steps on how to configure Authentication Rules.

Once the rule is configured, whenever a user matches the rule conditions, their credentials are verified against those stored in LDAP. Upon successful verification, the user is granted access to log in to Cymmetri.


# External IDP


# Introduction

Cymmetri's External Identity Provider (IdP) feature allows you to authenticate user identities using different IdPs for various user types. This flexible configuration enables you to streamline access for both internal employees and external users, such as consultants, vendors, and their employees. In this documentation, we will guide you through the process of configuring an External IdP within Cymmetri's identity and access management system.

For internal employees, you can configure Cymmetri's Internal IdP mechanisms like Active Directory or LDAP. This allows seamless authentication for your organization's employees.

Whereas external users, such as consultants, vendors, and their employees, can be verified using popular External IdPs like Google, Azure, Salesforce, or any other supported IdP. This approach simplifies access for external parties while maintaining security and control.

<figure><img src="/files/bKOiB0BP1h5eCPCSDVPg" alt=""><figcaption></figcaption></figure>

### Configuring External Identity Providers

To configure an External IdP in Cymmetri, the administrator needs to provide the following information:

1. **Name**: A descriptive name for the External IdP configuration.
2. **IDP Type**: The type or provider of the IdP (e.g., Google, Azure, Salesforce).
3. **Entity ID**: The unique identifier for the IdP entity.
4. **SSO Service URL**: The URL where Single Sign-On (SSO) requests should be sent.
5. **Destination**: The location where authentication responses should be directed.
6. **Protocol Binding**: The protocol used for communication with the IdP (e.g., HTTP Post, HTTP Redirect).
7. **Name ID Policy and Value**: This policy defines the format and content of the identifier that represents the authenticated user. For example:
   * **Policy**: email
   * **Value**: email
8. **Certificate**: The certificate used for secure communication between Cymmetri and the External IdP.

In the upcoming sections we will learn step-by-step implementation of the various External IDP mechanisms:

#### Google:

Google serves as a robust external Identity Provider (IDP) through its Identity Platform. Leveraging various authentication mechanisms, it facilitates secure user authentication for Cymmetri. This allows users to sign in with their Google credentials, ensuring a seamless and familiar login experience. Google's IDP mechanism is adopted for its reliability and user-friendly authentication processes, thus making it a preferred choice for integration into Cymmetri as an External IDP.

#### Azure Active Directory (Azure AD):

Azure AD serves as a robust external IDP, facilitating secure access into Cymmetri. Employing industry standards like OAuth 2.0 and SAML, it enables Single Sign-On (SSO) and multi-factor authentication. Azure AD seamlessly integrates with Cymmetri providing easy identity management and ensuring compliance with modern security standards.

#### Salesforce:

Salesforce as an external Identity Provider (IDP) offers robust authentication and access control solutions. Utilizing industry-standard protocols like SAML and OAuth, Salesforce IDP ensures secure Single Sign-On (SSO) experiences.&#x20;

Configuring External Identity Providers in Cymmetri gives you the flexibility to authenticate user identities using different IdPs tailored to specific user types. Whether it's for internal employees or external collaborators, Cymmetri's External IdP feature ensures secure and convenient access to your organization's resources.


# External Identity Provider Configuration - Google IDP

### Google Configuration:

1. Log in to your Google admin account and go to the **Admin Section** as shown below:

   <figure><img src="/files/de4pqJpwad8DTRNrR0ce" alt=""><figcaption></figcaption></figure>

Once in the admin section click on **Apps** > **Overview**

<figure><img src="/files/QThAvoVqxAAGBKLgfYR1" alt=""><figcaption></figcaption></figure>

In the overview page click on the **Web and mobile apps** tile to add a new custom app

<figure><img src="/files/9SFNmuZqw1ruvDSCNL5I" alt=""><figcaption></figcaption></figure>

On the Web and mobile apps page click on the **Add app** dropdown and then select **Add custom SAML app** to add the Cymmetri tenant as a custom app

<figure><img src="/files/F0GNdtoDFYvF6sRKlxm5" alt=""><figcaption></figcaption></figure>

Provide a relevant **App Name**, Optionally a **description** for the application can be provided. An **App Icon** can also be attached if required. Once entered click on the **Continue** button

<figure><img src="/files/jQXXjp8pDV0FBSJsC6Xx" alt=""><figcaption></figcaption></figure>

On the Google Identity Provider Detail page download the metadata file by clicking on the **DOWNLOAD METADATA** button. This metadata file needs to be used to get Entity ID, SSO URL, and Certificate. Administrators can download the certificate here or later as shown [here](#download-idp-certificate). Once downloaded click on **Continue**.

<figure><img src="/files/nFmvz3reJIVas2yI6pQZ" alt=""><figcaption></figcaption></figure>

Once the IDP metadata and certificate are obtained the Service Provider(i.e. Cymmetri) details need to be provided. We need to provide the **ACS URL** and the **Entity ID** these details can be obtained from Cymmetri as shown here. No change needs to be done for the Name ID format and Name ID, it can be kept to **UNSPECIFIED** and **Basic Information > Primary email**. Once done click on **Continue**

<figure><img src="/files/WxB7nWg9j9mB4HuJaJgu" alt=""><figcaption></figcaption></figure>

Attributes can be added on this screen which could then be sent as a SAML response to Cymmetri. These values can be used to create a user in Cymmetri if JIT provisioning is enabled on Cymmetri's side

Group membership information can also be sent by configuring groups here and if the user belongs to the configured group. Once attributes and groups are configured click on **FINISH.**

<figure><img src="/files/f33VZjNHq66xqItRAwtP" alt=""><figcaption></figcaption></figure>

Once you click on the FINISH button the below screen appears that shows the configuration details. It also shows various shortcuts to **Test SAML Login, Download Metadata, Edit Details, and Delete the App**

<figure><img src="/files/WpZ4PSfqxijKYHbklehp" alt=""><figcaption></figcaption></figure>

### Download IDP Certificate

If the administrator does not download the certificate while configuring the custom application, it can be later downloaded. For the same the administrator needs to go to **Security>Authentication>SSO with SAML applications.** This will open the Security Settings page from where either the IDP details like SSO URL and Entity ID can be copied and the IDP Certificate can be downloaded. These details can be used to configure the IDP in Cymmetri.

<figure><img src="/files/7ViIelbYjB8Gw0ydGCHp" alt=""><figcaption></figcaption></figure>

### **Cymmetri Configuration**

Once Google IDP is configured, the administrator must proceed with the configuration on the Cymmetri side. To achieve this, the administrator needs to set up Cymmetri as a Service Provider and also incorporate Google as an external IDP.

The page [here ](/identity-hub/authentication/service-provider)shows how to configure a Service Provider.

Once the Service Provider is configured, we need to configure Google as an external IDP.

Administrator needs to go to **Authentication->Identity Provider->External IDP.** Here you may either configure the already created **google-idp** instance or **+Add New**

<figure><img src="/files/h4PREKxYNjuHg46gg2uH" alt=""><figcaption></figcaption></figure>

In either cases a screen opens where you need to provide the below mentioned details

* **Name**: Google IdP
* **IDP Type**: Google
* **Entity ID**: <https://accounts.google.com/o/saml2?idpid=xxxxxxxxxxxx>
* **SSO Service URL**: <https://accounts.google.com/o/saml2/idp?idpid=xxxxxxxxxxxx>
* **Destination**: https\://\<hostname>/spsamlsrvc/samlSP/SingleSignOn
* **Protocol Binding**: HTTP Post (can also be set to HTTP Redirect if it is set so in Google IDP)
* **Name ID Policy**:
  * **Policy**: Email (This may change based on what is configured in Google IDP)
  * **Value**: Email (This may change based on what is configured in Google IDP)
* **Certificate**: Certificate downloaded from Google IDP
* **Logout Request URL:** Need to mention the SingleLogoutService url from the metadata file if SLO (Single Logout) is configured in Google.
* **Logout Protocol Binding:**&#x48;TTP Post (can also be set to HTTP Redirect if it is set so in Google IDP)
* **Service Provider Id:** cymmetri (Need to the select the configured Service Provider as shown above)

  <figure><img src="/files/PTsxkEJRtCf7iQq3z08e" alt=""><figcaption></figcaption></figure>

Once all the details are entered Save the changes.

For enabling Google IDP to be used as an IDP for specific set of users an Authentication Rule needs to be configured. [Here ](/identity-hub/authentication/authentication-rules)you can see the steps on how to configure Authentication Rules.

Once the rule is configured whenever a user matches with the rule conditions the user is redirected to Google screen and the user needs to provide his/her Google credentials to be able to login into Cymmetri.


# External Identity Provider Configuration - Azure IDP

#### Service Provider Configuration

The page [here ](/identity-hub/authentication/service-provider)shows how to configure a Service Provider.

#### Microsoft Entra Configuration

Now Login to the Microsoft Entra portal, <https://entra.microsoft.com/>

<figure><img src="/files/PhkcPsxqR9zo1N7TMOZB" alt=""><figcaption></figcaption></figure>

Navigate to Enterprise applications and select New Application.

<figure><img src="/files/3mqFNnjcDZeFiSfUurX4" alt=""><figcaption></figcaption></figure>

Click on Create your own application, Enter the Application Name and click on the Create button.

<figure><img src="/files/BGAdFYjzcVyBQUaeoAt5" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/GL85rTZUPq1LMtFFQ7AM" alt=""><figcaption></figcaption></figure>

Once the application is created click on the Single Sign On  menu and Set up Single Sign-On with SAML

<figure><img src="/files/K01dgiFm66bRCU0LO7g5" alt=""><figcaption></figcaption></figure>

Download a metadata file from Cymmetri- Service Provider page (how to create service provider is shown above)

<figure><img src="/files/hH59AZhWlzOEy06XHvsz" alt=""><figcaption></figcaption></figure>

Upload the downloaded metadata file here:

<figure><img src="/files/7E9PpaXGtSW7lsjInaAE" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/STTG1igq92Rhstojo7lg" alt=""><figcaption></figcaption></figure>

The Identifier (Entity ID) and Assertion Consumer Service URL from the XML file downloaded in  previous step are populated, then save the configuration.

<figure><img src="/files/5YSQhmEDyK41KF3uatRE" alt=""><figcaption></figcaption></figure>

Download the Certificate (Base64) from SAML Certificates.

<figure><img src="/files/NWXOZqA8GehwrhlN5b9y" alt=""><figcaption></figcaption></figure>

#### Assigning Users to the Application

Assigning users to applications in Microsoft Entra Enterprise Application that we just created to allow users to use Azure(Microsoft Entra) as an External Identity provider&#x20;

Navigate to Enterprise applications and select the application you created above

Go to Users and Groups, and select Add user/group and add the user.

<figure><img src="/files/5X2gyOfmpaeVPlIvYbYN" alt=""><figcaption></figcaption></figure>

#### Cymmetri IDP Configuration

Navigate to External IDP in Identity Provider.

<figure><img src="/files/1WXaQ2E8RryFOStmUozz" alt=""><figcaption></figcaption></figure>

Select Azure-IDP.

<figure><img src="/files/beuK1M8OJTJ40rz5g7AD" alt=""><figcaption></figcaption></figure>

Configure Azure AD for Creating Identity provider configuration

<figure><img src="/files/kq3dna6as1UMKDLvqLpE" alt=""><figcaption></figcaption></figure>

Next, Continue the configuration of Identity Provider In Cymmetri Administration Console, copy Microsoft Entra Identifier from Set up,  navigate to azure-idp in Cymmetri, and paste it in Entity ID.&#x20;

<figure><img src="/files/TkL2oV2CiMn47o0g4ec8" alt=""><figcaption></figcaption></figure>

Similarly, copy the login URL and paste it into the Single Sign On Service URL in Cymmetri.

Replace the text "\<host-name>" as the URL of the Cymmetri deployment (e.g., [https://aktestidp.ux.cymmetri.in](https://aktestidp.ux.cymmetri.in/) in the *destination* field - "https\://*\<hostName>*/spsamlsrvc/samlSP/SingleSignOnService"  as "<https://aktestidp.ux.cymmetri.in/>spsamlsrvc/samlSP/SingleSignOnService".

Open the Base64 certificate downloaded in step 12, copy it, and then paste it into the x509Certifcate field in Cymmetri.

<figure><img src="/files/ZyZWVOcnA2fe3GnV4K4c" alt=""><figcaption></figcaption></figure>

Select the created service provider in the Service Provider Id field dropdown and save the changes.

<figure><img src="/files/mBv9gxZX6NVSDlmzIBYD" alt=""><figcaption></figcaption></figure>

For enabling Azure IDP to be used as an IDP for a specific set of users an Authentication Rule needs to be configured. [Here ](/identity-hub/authentication/authentication-rules)you can see the steps on how to configure Authentication Rules.

#### Configuring JIT provisioning in Cymmetri&#x20;

If JIT provisioning needs to be enabled for Azure AD(Microsoft Entra) as external Identity provider, we may set it up using the steps below.&#x20;

Navigate to JIT in external identity provider and enable JIT Configuration.

<figure><img src="/files/oALhasek440S0cLowpZa" alt=""><figcaption></figcaption></figure>

The following fields are mandatory in Cymmetri - firstName, lastName, login, userType, displayName, and email.

<figure><img src="/files/5YTaRkhkLAkDh7wVtpYM" alt=""><figcaption></figcaption></figure>

For Azure JIT configuration, the following mapping needs to be done -&#x20;

| Label            | Application Field                                                 | Cymmetri Field |
| ---------------- | ----------------------------------------------------------------- | -------------- |
| First Name       | <http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname> | firstName      |
| Last Name        | <http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname>   | lastName       |
| Login (Username) | <http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name>      | login          |
| User Type        | any string                                                        | userType       |
| Display Name     | <http://schemas.microsoft.com/identity/claims/displayname>        | displayName    |
| Email Address    | <http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name>      | email          |

#### Checking the Azure Authentication

Login to cymmetri using Azure Email Address

<figure><img src="/files/ndcMV3GMYz6yKze1W5g9" alt=""><figcaption></figcaption></figure>

The user will be redirected to the Azure portal to enter the Azure credentials.

<figure><img src="/files/fAMWFHVsBqLcmgBh8dYn" alt=""><figcaption></figcaption></figure>

Once the credentials have been entered properly in the Azure portal, the user will be redirected back to Cymmetri and will be logged in successfully.&#x20;

<figure><img src="/files/DRzqfuCm5LFYzoNOcWbd" alt=""><figcaption></figcaption></figure>


# External Identity Provider Configuration - Salesforce IDP

'

*Note: The link below shows steps as suggested by Salesforce to configure Salesforce as an Identity Provider:* [*https://help.salesforce.com/s/articleView?id=sf.sso\_sfdc\_idp\_saml\_parent.htm\&type=5*](https://help.salesforce.com/s/articleView?id=sf.sso_sfdc_idp_saml_parent.htm\&type=5)

Here below the same steps are demonstrated to use Salesforce as an Identity Provider and Cymmetri as a Service Provider.

### Configuring Salesforce&#x20;

For configuring Salesforce to be used as an IDP the Salesforce Administrator needs to login to Salesforce as shown below:

<figure><img src="/files/snSYw2VPU2t9KIOPd3Yu" alt=""><figcaption></figcaption></figure>

Once logged in the administrator needs to click on **Setup** on the top right and then in the search bar on the right side search for **Identity Providers.** Once found click on **Security Controls -> Identity Provider** menu&#x20;

<figure><img src="/files/2W209B23Uy2hRKMB37Ev" alt=""><figcaption></figcaption></figure>

When the Identity Provider page opens click on the **Enable Identity Provider** button to enable Salesforce as an Identity Provider so that it can be used for authentication in Cymmetri.

<figure><img src="/files/BTBLkiTOkfs13XKbKJwZ" alt=""><figcaption></figcaption></figure>

When the Enable Identity Provider button is clicked it opens a page that asks you to choose a certificate. Select the default certificate here and click **Save**.

<figure><img src="/files/DRBmp52qdFockFAj6QyG" alt=""><figcaption></figcaption></figure>

When saved it shows a warning message as below just click the **OK** button and continue.

<figure><img src="/files/RELjDCEnEpzCjg41w14P" alt=""><figcaption></figcaption></figure>

Once confirmed the screen as shown below appears you may download the certificate and the metadata file here using the **Download Certificate** and **Download Metadata** buttons. These files can be downloaded later during the end of the process which can be seen later in the documentation below.

<figure><img src="/files/ggVrFhiwJG3BmmPa5LHL" alt=""><figcaption></figcaption></figure>

The metadata file appears as below, this data is used later to configure the External IDP in Cymmetri.

<figure><img src="/files/eIwkrR066yeZexfHfDax" alt=""><figcaption></figcaption></figure>

The certificate file appears as below this is also needed when configuring the External IDP in Cymmetri.

<figure><img src="/files/MNDHtHv3Nz3NLzQ1XrKb" alt=""><figcaption></figcaption></figure>

Once the files are downloaded next to add the Service Provider the salesforce administrator needs to click on **Service Providers are now created via Connected Apps. Click here** link. The mentioned link allows to create a Connected App for Cymmetri which acts as a service provider in Salesforce.

<figure><img src="/files/YAnGOLoWrWAbeyL2fzEC" alt=""><figcaption></figcaption></figure>

The link above leads to the page below where a new connected app can be added. The following details need to be mentioned to add a connected app:

* **Connected App Name:** App Name *(Cymmetri in this case)*
* **API Name:** Auto-populated based on the Connected App Name field, can be changed
* **Contact Email:** a valid contact email

*Note: Other fields shown in the image below are optional and hence can be skipped.*

<figure><img src="/files/LVm8ggdyKAcqw6R1NQjo" alt=""><figcaption></figcaption></figure>

Next on the same page, there is a section called Web App Settings here click on **Enable SAML** to enable the SAML settings. Once enabled all the below-mentioned details need to be provided.

* **Entity Id:** A unique identifier for a SAML entity, such as a Service Provider (SP) or Identity Provider (IDP), within a federated authentication environment.
* **ACS URL (Assertion Consumer Service URL):** The endpoint where a service provider expects to receive SAML assertions from an identity provider, facilitating single sign-on (SSO) in a federated system.
* **Enable Single Logout:** A configuration option indicating whether the system supports single logout functionality, allowing users to log out of all connected services in a federated environment with one action.
* **Single Logout URL:** The endpoint to which a SAML entity sends logout requests as part of the single logout process when a user logs out of the federated system.
* **Single Logout Binding:** The protocol or method used to transmit single logout requests and responses between SAML entities, often specified as either HTTP Redirect or HTTP POST.
* **Subject Type:** Specifies the type of subject identifier used in SAML assertions, such as transient, persistent, or bearer, indicating how the identity of the user is communicated between the identity provider and the service provider.
* **Name ID Format:** Defines the format of the NameID element in SAML assertions, determining how the user's identity is represented, such as email address, X.509 certificate, or unspecified.
* **Issuer:** Identifies the entity that issues a SAML assertion, typically the identity provider, and is included in the SAML assertion to establish trust between the entities in a federated system.
* **IDP Certificate:** The public key certificate associated with the identity provider, used by the service provider to verify the authenticity and integrity of SAML assertions and messages.
* **Signing Algorithm for SAML Messages:** Specifies the cryptographic algorithm used to sign SAML messages, ensuring the integrity and authenticity of the information exchanged between identity providers and service providers in a federated

  <figure><img src="/files/IogOma1hV98LUpctPTiK" alt=""><figcaption></figcaption></figure>

The above-mentioned details can be obtained by adding a service provider in Cymmetri as shown below. To know more about how to add a service provider in Cymmetri click [here](broken://pages/6rI3p7Z7ttGw9nNBrDRU). Once created these details can be used in Salesforce as shown above.

<figure><img src="/files/MJigZ3W76XvSF2miXW7K" alt=""><figcaption></figcaption></figure>

Once all details are successfully added and saved the screen below appears which shows the configuration details.

<figure><img src="/files/5cWqzZzpNDmU1K7DwAUX" alt=""><figcaption></figcaption></figure>

Administrators can click on the **Manage** button (as shown above) to view SAML Service Provider Settings and SAML Login Information. Administrators can also download metadata files here.

<figure><img src="/files/Nb9LhIlLtimjM5Gxa5U1" alt=""><figcaption></figcaption></figure>

The downloaded metadata file appears as below. The details mentioned in the metadata file are used to configure an External IDP in Cymmetri.

<figure><img src="/files/21VnPDwcCA05gvcZeAvm" alt=""><figcaption></figcaption></figure>

Based on the diverse profiles of users in Salesforce, the administrator needs to enable Connected App Access for these profiles. Here in this example access has been enabled for the System Administrator; similarly, it should be enabled for all profiles of various users who are intended to access Cymmetri.

For enabling the connected app administrator needs to go to **Setup->Manage Users-> Profiles**, then select the profile for which the connected app needs to be enabled

<figure><img src="/files/BRLGsIpcc50EaAq8mqMH" alt=""><figcaption></figcaption></figure>

Once the profile is selected click on the **Edit** button and look for the **Connected App Access** section.

<figure><img src="/files/ih7ETedPxF2oKPKTAPPv" alt=""><figcaption></figcaption></figure>

In the Connected App Access section look for the custom app you created(Cymmetri in this case) and click the checkbox to enable the access.

<figure><img src="/files/MyJg01N95UtGreUK95K3" alt=""><figcaption></figcaption></figure>

Once all the configurations on the Salesforce end are done, the administrator must proceed with the configuration on the Cymmetri side. To achieve this, the administrator needs to go to **Authentication->Identity Provider->External IDP.** Here you may either configure the already created **salesforce-idp** instance or **+Add New**

<figure><img src="/files/gCrHaUKLEspRl68d17CD" alt=""><figcaption></figcaption></figure>

In either case, a screen opens where you need to provide the below-mentioned details

* **Name**: salesforce-idp
* **IDP Type**: Salesforce
* **Entity ID**: Need to mention the EntityID from the metadata file downloaded from Salesforce
* **SSO Service URL**: Need to mention the SingleSignonService URL from the metadata file downloaded from Salesforce
* **Destination**: https\://\<hostname>/spsamlsrvc/samlSP/SingleSignOn
* **Protocol Binding**: HTTP Post (can also be set to HTTP Redirect if it is set so in Salesforce)
* **Name ID Policy**:
  * **Policy**: Unspecified(This may change based on what is configured in Salesforce)
  * **Value**: Login(This may change based on what is configured in Salesforce)
* **Certificate**: Certificate downloaded from Salesforce&#x20;
* **Logout Request URL:** Need to mention the SingleLogoutService URL from the metadata file downloaded from Salesforce
* **Logout Protocol Binding:** HTTP Post (can also be set to HTTP Redirect if it is set so in Salesforce)
* **Service Provider Id:** cymmetri (Need to the select the configured Service Provider as shown above)

  <figure><img src="/files/nsj4XBTqLITATC5x7yBh" alt=""><figcaption></figcaption></figure>

Once the external IDP is configured next we need to configure Authentication Rules as explained [here ](broken://pages/f4EIvwhQlEXpgpcq3Pad)and as shown below. Conditions mentioned here may vary based on actual scenario in which the IDP needs to be applicable.

<figure><img src="/files/V2qBJX4iVhADyn5Pu8Ew" alt=""><figcaption></figcaption></figure>

Now the user can login into Cymmetri using Salesforce. The user needs to provide his/her username and click on **Next.**

<figure><img src="/files/ijJlgjKwF8csECrsXzjN" alt=""><figcaption></figcaption></figure>

The user is then redirected to Salesforce login page where the user needs to enter their Salesforce credentials and click on **Log in**

<figure><img src="/files/XPWZa8lUTDCQUWUNHOW1" alt=""><figcaption></figcaption></figure>

Once the salesforce credentials are successfully validated the user is redirected to Cymmetri home page.

<figure><img src="/files/dfnS092XPEu7Y148Kh4f" alt=""><figcaption></figcaption></figure>


# Service Provider

#### Configuring Cymmetri as a Service Provider

Administrator needs to go to **Authentication->Service Provider**

<figure><img src="/files/eBxixT9gLZbh4aF0gQ2a" alt=""><figcaption></figcaption></figure>

Then click on **+Add New** button, On the screen that appears most of the data is prefilled. Yet if the administrator needs the data can be changed as per need. Once done click on Save. The prepopulated data appears as below:

<figure><img src="/files/6cM8kwplQ6FD2e5qEs2n" alt=""><figcaption></figcaption></figure>

Once saved the Service Provider(Cymmetri) appears as below:

<figure><img src="/files/xfucn1AVbkl1JqrctFUN" alt=""><figcaption></figcaption></figure>

The service provider is created at this step, download the metadata(xml file)  of the same.


# Authentication Rules

Within Cymmetri, the authentication process is highly customizable through the definition of authentication rules. While the platform provides a default authentication rule, administrators have the ability to define custom authentication rules that align with the specific business needs and the variety of identity providers at their disposal.

For instance, let's consider a scenario where an organization has distinct user types, such as regular employees, contractors, and administrators. The administrators might require to authenticate employees with Active Directory as the identity provider and use Cymmetri's own authentication engine to verify the identity of vendors and contractors. With Cymmetri's flexibility, administrators can create authentication rules that cater to these varying requirements, ensuring a tailored and secure authentication experience based on user roles and organizational needs.

<figure><img src="/files/X50qTl86C6FjT6LLSVRw" alt=""><figcaption></figcaption></figure>

Admins can find authentication rules in Authentication tab in Cymmetri.&#x20;

To create a new authentication rule, admin must simply click on the "Add New" button on the top right corner of the page.&#x20;

<figure><img src="/files/WoCUYINHDX8llv5jtVB9" alt=""><figcaption></figcaption></figure>

The admin must fill in the following details

1. The name of the rule&#x20;
2. Identity provider radio button ( Enable for External IDP  or Disable for Internal IDP)
3. Identity provider&#x20;
4. Description of the rule&#x20;
5. Active Radio Button

**Conditions**&#x20;

The administrator has the capability to establish rules based on conditions like: Department, designation, User Type, country, and Login Pattern.&#x20;

Subsequently, the administrator defines regular expressions for conditions, specifying whether they should be equal to, not equal to, and assigns corresponding values.&#x20;

Cymmetri facilitates the creation of multiple conditions for an authentication rule and provides the option to group these conditions using AND or OR logic.

<figure><img src="/files/IGYHzv7lK94lxtZLnJZx" alt=""><figcaption></figcaption></figure>

In the image presented above, an exemplar authentication rule is showcased. This rule is structured to authenticate a user in Cymmetri through Active Directory if two conditions are met: the user's department must be equal to "Compliance," and the user type should be "Employee."&#x20;

Similarly If you wish to set the Identity provider for users having email address ending with "@cymmetri.com" then you may select condition as LoginPattern > Regular Expression and its value as (.)\*(@cymmetri.com)+$; and save the details.

<figure><img src="/files/NvtUIwxEoKTfXV9HcQKm" alt=""><figcaption></figcaption></figure>

This demonstrates how authentication rules can be precisely configured to suit specific criteria and streamline the authentication process based on defined conditions.


# Password Policy

## What is a Password Policy?

A password policy is a set of rules and requirements established by an organization or system to govern how users create and manage their passwords.&#x20;

The purpose of a password policy is to enhance security by promoting the use of strong, unique passwords and minimizing the risk of unauthorized access.

In Cymmetri, only the admin can create a password policy bby navigating to the authentication section and then in password policy.&#x20;

Upon landing the user can view a default Cymmetri password policy which cant be deleted or deactivated.

<figure><img src="/files/MAT13y1iSsjdKOTE1J59" alt=""><figcaption></figcaption></figure>

To create a new password policy, the admin clicks on the add new button on the top right corner of the page.&#x20;

The user has to fill in the password policy form with the below details

1. **Policy Name** - Name of the policy
2. **Description**
3. **Conditional attribute type** - Default - User (Non modifiable)
4. **Conditional attribute Name** - Default - User Type (Non modifiable)
5. **Conditional attribute value  -** ( Consultant, Employee, Vendor)

   <figure><img src="/files/U2m1TvVicK0vV0Pk6yoj" alt=""><figcaption></figcaption></figure>

After saving the detail, a new password policy is created. The next step is to define the password policy. This is done by clicking on the edit button in front of the record.&#x20;

The admin can define the composition of the password. By rejecting

1. Password equals Password&#x20;
2. Password which equals to LoginID&#x20;
3. Password which equals to first or Last Name
4. Blacklisted Password&#x20;

   <figure><img src="/files/QFJRQha62DZzo2upes7r" alt=""><figcaption></figcaption></figure>

The admin can also establish the following parameters

1. Numeric characters minimum count
2. Password Length
3. Special characters count
4. Password History versions
5. Alpha characters&#x20;
6. Uppercase characters
7. Lowercase characters
8. Characters not allowed in the password&#x20;

In the "change" subsection the admin can also define:

1. Password expiration days
2. Password expiration warning from (no of days)
3. Whether to change password on reset

   <figure><img src="/files/alxEwPnvCKq3PzarQlyg" alt=""><figcaption></figcaption></figure>

## Blacklisted Password

The administrator also has the capability to set prohibited passwords, preventing users from using those specific passwords.

<figure><img src="/files/K8naCOO2gVaiBlxZ4xnj" alt=""><figcaption></figcaption></figure>


# Global Auth Policy

The Global Auth Policy allows to configure various user login parameters as shown below:

<figure><img src="/files/6NtajUhajoTMMZ0T4gP6" alt=""><figcaption></figcaption></figure>

**Auth Failed Count:** The Auth Failed Count parameter signifies after how many failed login attempts will the user account be locked.

**Unlock after Minutes:** The Unlock after Minutes parameter signifies after how many minutes will a locked account be automatically unlocked.

**Token Expiry Minutes:** The Token Expiry Minutes parameter signifies after how many minutes will the session token expire.

**Refresh Token Expiry Minutes:** The Refresh Token Expiry Minutes parameter signifies after how many minutes will the refresh token expire.

### User Session

Cymmetri allows users to have multiple sessions simulatenously i.e. they can login simulatenously from various locations and keep all the sessions alive. It also provides control to the user to revoke any specific or all the sessions

<figure><img src="/files/w5eRfVjRIIydIbNMiJSX" alt=""><figcaption></figcaption></figure>


# Adaptive

Adaptive authentication is an advanced security measure that assesses various factors and context elements in real-time to determine the level of risk associated with a user's access attempt.&#x20;

Based on this risk assessment, the authentication system can dynamically adapt its level of scrutiny and request additional verification steps if needed. This approach enhances security while minimizing disruption for legitimate users.

In Cymmetri there are various adaptive checks that the admin can enable for additional factor of authentication.

<figure><img src="/files/h8tv7WAzy9oT8NNXn7SX" alt=""><figcaption></figcaption></figure>

1. **Device Trust Check** - If enabled, Cymmetri will check if the device being used to perform action on the Cymmetri portal, has been trusted by the user
2. **User Behavior** - Cymmetri determines whether the behavior of user matches with the known behavior pattern of the user over time
3. **Blacklisted IP** - Maintains a blacklist of IP addresses that are known to be sources of unauthorized access, hacking attempts, or other malicious activities
4. **Blacklisted Location -** Cymmetri maintains a list of locations from which the administrator wishes to restrict access of the portal
5. **Short Lived Domain -** Cymmetri checks the email address domain of the user with a database of known providers of short-term or disposable email addresses
6. **Impossible travel scenario -** Tracks the change in location of user attempting an action over a short period of time and flagging if, system deems the pattern to be impossible.

The admin can enable these checks as per the business use case

To navigate to the adaptive settings page, click on the "Go to settings" button on the top right corner of the page.&#x20;

### **IP Address Checks**

Administrators can include an IP address in the blacklist by following these steps:

Enable the "IP address Check" radio button at the top of the page, input the IP address into the "Blacklisted IP address" field, and press enter. The specified IP will be added to the list. To synchronize the list with the database, click the "Sync Now" button.

<figure><img src="/files/irSkFMVlK6m0KTPgTnos" alt=""><figcaption></figcaption></figure>

You can select additional actions when module detects an anomaly. They are the following:

* **Ask additional MFA and notify** - If an MFA rule has been established and adaptive authentication is activated for it in the MFA section, when a user attempts to log in with a blacklisted IP address, the user will be prompted for additional factor(s) for authentication as defined by the rule. Additionally, the user will receive email notifications regarding the login activity.

<figure><img src="/files/yKNKCxAJfWKYNDBq9wsf" alt=""><figcaption><p>Push Notification as MFA for Blacklisted IP check on Login</p></figcaption></figure>

<figure><img src="/files/vejhmh7mQaKDr7sMwEas" alt=""><figcaption><p>Email on user's registered Email ID </p></figcaption></figure>

* **Only Notify** - This option solely sends a notification to the user about the login activity.
* **Block user and notify** - This option not only blocks the user upon a login attempt with a blacklisted IP but also notifies the user on their registered email ID.

### **Device Trust**

Define how Cymmetri determines if a device is trusted for the user and allows to define behavior of authentication in Cymmetri, in case of untrusted device

The admin can define

1. No of successful authentication attempts
2. Number of devices per user&#x20;
3. Number of days&#x20;
4. Additional action when module detects anomaly

<figure><img src="/files/9IR2oSrSQfwD4O1q5089" alt=""><figcaption></figcaption></figure>

* **Location based checks**

Organizations can maintain a list of blacklisted locations as part of their adaptive authentication strategy to enhance security measures and mitigate potential risks

The admin can select the blacklisted location on this page. Also additional actions on these checks can be selected.

<figure><img src="/files/0Swb0hZ9Km6o3KDDgotF" alt=""><figcaption></figcaption></figure>

* **Impossible Travel Scenario**

Track the changes of location from which the user attempts to perform actions on the portal over a short period of time and flags an action attempt

The admin can configure the:

1. Check Windows(in hrs)
2. Average Distance (in Km)

<figure><img src="/files/c94f63OzLpaaOswqqPcg" alt=""><figcaption></figcaption></figure>

* **Short lived Domain Checks**

Checks the .email address domain of the user with a database of known providers of short-time or disposable email addresses

The admin can Sync the database where the domains are stored and updated

<figure><img src="/files/7ZgRKqGG8A1jCZfhLrD5" alt=""><figcaption></figcaption></figure>

* **User behavior checks**

Cymmetri determines whether the behavior of user matches with the known behavior pattern of the user over time

The admin can select the required checks to verify the consumer behavior:

1. Unusual time of Login
2. Unusual number of Login failures
3. Unusual keystrokes pattern

<figure><img src="/files/HLLjO0OtlPIGVHDp2Azl" alt=""><figcaption></figcaption></figure>

The admin can enable, configure and save these adaptive checks individually as and when required.


# Attribute Setting

In Cymmetri, the Attribute Setting is a tool for user attribute management.

It provides administrators with granular control over attribute visibility during user creation or updation processes. This feature empowers administrators to enable or disable both predefined and custom attributes effortlessly.&#x20;

When an attribute is disabled, that associated field doesn't appear anywhere in the user creation or updation pages, streamlining the user management experience.&#x20;

<figure><img src="/files/reY4tA6afaMHPfspKOMw" alt=""><figcaption></figcaption></figure>


# Password Filter

### Introduction <a href="#introduction-to-templates" id="introduction-to-templates"></a>

The Cymmetri Architecture without the password filter utility allows for one-way synchronization of passwords from Cymmetri to managed applications like Active Directory. Active Directory passwords may therefore be updated, once the user password is updated in Cymmetri.&#x20;

However, to keep both the Cymmetri database and Active Directory user passwords in synchronization, there is a need for Cymmetri database to receive password change notification from the Active Directory, when the password is directly updated in Active Directory.&#x20;

Active Directory provides for the use of Password Filter which can intercept the request for password change and can make an API call to Cymmetri to update the password in Cymmetri database as well.

### Flow Diagram <a href="#creating-templates" id="creating-templates"></a>

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84020662351/original/btLBcZ0aPK_aIaTaG6GM4zPVT0ytpr0FuQ.png?1669705796)

### Flow Description <a href="#creating-templates" id="creating-templates"></a>

1. Cymmetri Password Filter dll will be deployed in the Active directory environment and system variables (environment variables) are configured to allow the password filter to connect to the Cymmetri deployment.
2. Active Directory server needs to be restarted once the configuration is performed.
3. Once the user changes the password on a domain-connected computer using Ctrl+Alt+Delete utility OR if the Active Directory administrator resets the user's password using Active Directory tools, the password filter will be triggered.
4. The password filter DLL will receive the username and the plaintext password from the Active Directory, once the password change has been applied on the Active Directory.
5. The password filter DLL will encrypt the password using RSA encryption with a public key and will send the encrypted password and the username to the Cymmetri deployment using a REST API call over HTTPS.
6. The Cymmetri deployment receives the username and encrypted password, it decrypts the password using private key.
7. Once the password is decrypted, the Cymmetri deployment updates the password in Cymmetri database for the given user.&#x20;
8. If the user is assigned multiple applications for provisioning, the action of updating user's password in Cymmetri database will trigger password update for the user in other provisioned applications. However, Active directory application will not receive this password update, to avoid loops.

### Configuration <a href="#using-templates" id="using-templates"></a>

<table><thead><tr><th width="334">Key</th><th>Value</th></tr></thead><tbody><tr><td>CYMMETRI_APP_ID</td><td>&#x3C;application-id-of-active-directory-in-Cymmetri></td></tr><tr><td>CYMMETRI_CLIENT_TOKEN</td><td>Authorization: Bearer &#x3C;token-from-api-client><br></td></tr><tr><td>CYMMETRI_ENDPOINT_URL</td><td>https://&#x3C;cymmetri-domain>/apiext/api/password/filter/updateUserPassword</td></tr><tr><td>CYMMETRI_PUBLIC_KEY_FILE</td><td>&#x3C;path of public key file in Active Directory Server></td></tr></tbody></table>

## Steps for deploying Password Filter DLL&#x20;

1. Download the dll file and the public key file from here -\
   CPFv308.dll - <https://drive.google.com/file/d/15uPQYnJr7HUWnxHLPSpYtsWGKkm5HnLC/view?usp=share\\_link\\>
   public.pem - <https://drive.google.com/file/d/1OdBLal4RTA5bMqABJEq3zQeLxNzSOE0R/view?usp=share\\_link>

2. Place the CPFv308.dll file in the C:\Windows\System32 folder.

3. Run regedit and go to the following path: HKEY\_LOCAL\_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa

4. You must now see a page similar to this:

   <figure><img src="https://lh6.googleusercontent.com/dYzqlA4N32Bc_JPXUuYs7EnlRamo-lsyOYVCLY_sY2qGTjDu24XadgxQ15VwOHZ2WZBFG8xiLMfaV5Eeau4QrKGhCfFkfFXibLaMO1EnQM-hIymJ4r4DhKGJEpDjpEoXJfFVfj2HQ3dFrkfJMB7YVxg" alt=""><figcaption></figcaption></figure>

5. Select the element Notification Packages and double click it

   <figure><img src="https://lh4.googleusercontent.com/WYuaUzaIQlObouTS0D9v2kU1FFcxcnpAnBGvK6_4TTYHv1AsM-DlkTS0jhYSA509p0OsWdlvbeGIrXD98Zg8kpG1VIalu4c0PeQaXjefqlic82a6yPw_0EKa54Kdi9uOnU6U4nbhua45wKDMYakFm2o" alt=""><figcaption></figcaption></figure>

6. Add the line “CPFv308” and Click on OK to save the registry entry.

7. Exit the registry editor.

8. Save the public.pem file to any directory and note the name of the directory. Ex - C:\Users\Administrator\Desktop\public.pem

9. For testing the deployment, Login into the Cymmetri portal as an administrator and note the application ID of the Active Directory application configured for provisioning. Ex - 69125912519fb123

10. Also, create a new API client.

<figure><img src="https://lh4.googleusercontent.com/g76HqdGKIYLf3uccC7E0dXtf2HQvSMynGViA7-721L9joMjT664fbJlkzLJfN4DjdC1QNnlEn7P9_7STe3bSSrM1JEVwrqQlRhv-RBAQZ3e2e8OuAma71qBqRE2s9-qFIDgypChlCB9flFVnONsPf7Y" alt=""><figcaption></figcaption></figure>

11. Click on renew secret and note the bearer token generated.

<figure><img src="https://lh3.googleusercontent.com/vLHimXcBvPVimbgn2L3_k3AI4KDxty3iJL_vrIMXeKLxv7D98RoTS9RSPR0Nied2Y5f4E21Y720Dwuq4bM9TJH2KgI0lW-zpJKnVWJkdU99ufwGcPISgHkw_JDv7Ag5_QXdRLr2ZenTL301XPdOCo2c" alt=""><figcaption></figcaption></figure>

Ex - eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJOZXcgQVBJIENsaWVudCIsInRlbmFudCI6IjI3NyJ9.L\_q7I4MFcZSFXetdSvzD7hxvfcSrUUaJEkwhUTfHgus

12. Go to Control Panel > System > Advanced System Settings and click on environment variables.
13. Add the following System variables.
    1. Key = CYMMETRI\_APP\_ID; Value = \<application-id-of-active-directory>; Example = 6015991fdfeab12c
    2. Key = CYMMETRI\_CLIENT\_TOKEN; Value = Authorization Bearer \<token-from-api-client>; Example = Authorization: Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJOZXcgQVBJIENsaWVudCIsInRlbmFudCI6IjI3NyJ9.L\_q7I4MFcZSFXetdSvzD7hxvfcSrUUaJEkwhUTfHgus
    3. Key = CYMMETRI\_ENDPOINT\_URL; Value = \<domain>/apiext/api/password/filter/updateUserPassword; Example = <https://277.newqa.cymmetri.in/apiext/api/password/filter/updateUserPassword>
    4. Key = CYMMETRI\_PUBLIC\_KEY\_FILE; Value = \<path of public.pem file>; Example = C:\Users\Administrator\Desktop\public.pem
14. Save the environment variables.
15. Create a folder as C:\passfilter\_logs to store the logs.
16. Take a restart of the Active Directory Server.

### Configuring Password Filter in Cymmetri

1. Navigate to the Configuration Menu.
2. Look for the Password Filter option in the Configuration Menu.
3. Once on the page click on "+Add New" button
4. This will open the configuration page, You should find a toggle button to enable the Password Filter. Turn it on to enable the filter.
5. Once the Password Filter is enabled, you'll need to choose the filter type.There are two options: "Include" and "Exclude."
   1. "Include" means that only the applications selected in the included applications dropdown will receive synced passwords and have their passwords changed correspondingly.
   2. "Exclude" means that all applications except the ones selected in the excluded applications dropdown will receive synced passwords and have their passwords changed correspondingly.
6. Next you select the Filtered Application this is usually the managed application where the password changed has happened which in this case is Active Directory
7. Next, determine which type of authenticator you want to use for password synchronization.
   * You typically have three options: Cymmetri Authenticator, AD (Active Directory) Authenticator, or LDAP (Lightweight Directory Access Protocol) Authenticator.
   * Choose the appropriate authenticator based on your requirements and configuration.
8. After completing the above steps, make sure to save your configuration settings.Click on the "Save" button to save your changes.

   <figure><img src="/files/IvhfrZYFEtcBFqXOoYfi" alt=""><figcaption></figcaption></figure>


# Logs


# Audit Log

In Cymmetri, the Audit Logs serve as a vital tool to maintain transparency, accountability, and security in your identity and access setup. This feature meticulously records a detailed account of various activities, ensuring a comprehensive overview of critical events and system changes.

Cymmetri uses a high performance columnar database management system designed for online analytical processing (OLAP). Its architecture and features make it well-suited for maintaining audit logs with strong protection and tamper resistance.

Below are key capabilities that contribute to these aspects:

## **Protection  from alteration of logs data**

Audit logs are critical in any security framework as they provide a reliable trail of all activities within a system. Ensuring that these logs are tamper-proof is vital to maintaining the integrity, accountability, and transparency of the data. Cymmetri, a robust identity management platform, implements several best practices and technological safeguards to ensure that audit logs remain tamper-proof. Here’s how Cymmetri achieves this:&#x20;

### 1. Immutable Log Storage

Cymmetri uses immutable storage for audit logs, meaning once data is written, it cannot be altered or deleted. This ensures that even privileged users or attackers cannot manipulate the logs. The immutable nature of the storage ensures that records are permanent and always available for audits.&#x20;

### 2. Cryptographic Hashing

Each audit log entry in Cymmetri is hashed using cryptographic algorithms, such as SHA-256, before being written to the storage. Hashing creates a unique digital fingerprint of the log entry, making any changes immediately detectable. If the contents of an entry were altered in any way, the hash would no longer match, thus providing tamper-evident logs.&#x20;

### 3. Chain-Based Logging

To add an extra layer of tamper-proofing, Cymmetri leverages chain technology for audit logs. Each log entry is chained to the previous one using cryptographic hashes. This makes it impossible to alter any individual log without breaking the entire chain. chain ensures both immutability and accountability since every change or addition to the log becomes part of a transparent, verifiable sequence.&#x20;

### 4. Role-Based Access Control (RBAC)

Cymmetri strictly enforces role-based access controls to restrict who can view and interact with the audit logs. Only authorized personnel have the rights to access the logs, and the system records all accesses, creating an additional layer of oversight. This minimizes the risk of tampering from internal threats or misconfigurations.&#x20;

### 5. Logging Redundancy and Backup

Cymmetri ensures that audit logs are stored in multiple secure locations using distributed databases or cloud storage. This redundancy guarantees that even if one storage instance is compromised, the logs in other locations remain intact. Regular backups further protect the integrity of logs by ensuring that a historical record is always available.&#x20;

### 6. Time-Stamping

Each audit log entry is time-stamped with a high degree of precision to ensure traceability and integrity. The timestamps are included in the cryptographic hashes, making it impossible to modify both the content and the timing of the log entries. This creates a reliable chain of events that can be used to track down and investigate suspicious activities.

&#x20;Cymmetri’s tamper-proof audit logs combine state-of-the-art technologies like cryptographic hashing, immutable storage, and chain to ensure that the integrity of the audit trail remains intact. With features like RBAC, redundancy, time-stamping, and real- monitoring, Cymmetri offers a highly secure logging framework that prevents any unauthorized modifications, ensuring full accountability across its systems.

For administrators looking to review system-related logs in Cymmetri, the process is simple. Just head to the "Audit Logs" tab within the Logs section. Here, you'll find a wealth of information, covering everything from user logins to requests for accessing applications.

### Audit References

Cymmetri Audit Log maintains all events processed via Cymmetri. The events are tracked based on per object event log as per the Cymmetri logging framework. Events that become part of the the log are-

1. Human driven events processed by the system. Example- a Cymmetri Admin changing an application configuration.&#x20;
2. Scheduled events processed by the system. Example- Deprovisioning job to disable Cymmetri users.
3. Events triggering associated processes as set up in the system. Example- Authentication service will verify the authentication rule to check for Passwordless or MFA based login journey.&#x20;

Cymmetri goes the extra mile by capturing each and every system event, offering administrators a thorough understanding of what's happening within the platform.

<figure><img src="/files/m6FHRhi1Gh5rQ4zB152A" alt=""><figcaption></figcaption></figure>

For a closer look at a specific log entry, administrators can click on the eye icon next to it. This action provides a detailed response, offering insights into the exact activities that took place.

<figure><img src="/files/gbvcnKzSyWh4t7zglwHC" alt=""><figcaption></figcaption></figure>

The admin can also filter the logs based on:

1. The actor who performed the event
2. The performed event
3. Start and end date of the events&#x20;
4. Target and target type
5. Status of the event - all, success, and failed

<figure><img src="/files/ZbFmo50iCAdxQkzEgpfu" alt=""><figcaption></figcaption></figure>

Cymmetri provides a reference view for the changes occurred during an audit event.

<figure><img src="/files/qhKoXSIIUuZH2nONMzTm" alt=""><figcaption><p>Artefact - Audit log indicating a value updated in the log with time timestamp</p></figcaption></figure>

In essence, Cymmetri's Audit Logs empower administrators with the tools they need to keep a close eye on system activities, ensuring a secure and well-documented identity and access management environment.


# Import History

The "Import History" tab in Cymmetri provides a comprehensive record of all data imports, ensuring transparency and accountability in managing user and system information. This feature is designed to offer administrators insights into the history of data imports, facilitating effective tracking and auditing.

To check the import history in Cymmetri, go to the "Import History" tab within the Logs section. This area keeps track of all bulk import events, including imports for user and application assignments.

In this section, administrators can find a detailed history of import events, including:

1. **File Name:** The name of the file that was imported.
2. **Status:** The status of the import activity, indicating whether it was successful or if there were any issues.
3. **Import Type:** Specifies the type of import, such as user or application assignment import.
4. &#x20;**Created By:** Shows who initiated or performed the import.&#x20;
5. **Created At:** Indicates the timestamp of when the import occurred.

<figure><img src="/files/RZB35Kw6qY9nrIqezHTT" alt=""><figcaption></figcaption></figure>

For a closer look at the import history, administrators can click on the eye icon next to a specific record. This detailed view provides insights into the imported record statuses, including:

**Created Successfully in Cymmetri:** Indicates records that were successfully created within the Cymmetri system during the import.

**Duplicated in the System While Importing:** Highlights instances where records already existed in the system, preventing duplication during the import process.

**Error Occurrence During Import with Remarks:** Flags any errors that occurred during the import, accompanied by remarks detailing the nature of the issue.

<figure><img src="/files/wjVdp6V1BFlC2fez1qph" alt=""><figcaption></figcaption></figure>


# Scheduler History

In Cymmetri the "Scheduler History" feature plays a crucial role in maintaining visibility and control over scheduled tasks and operations. This functionality is designed to offer administrators insights into the history of scheduled events, providing transparency, accountability, and efficient management of routine processes.

In the "Scheduler History" tab, accessible within the Logs section of Cymmetri, administrators can delve into the details of scheduled tasks, gaining insights into various aspects of the scheduler's operation. The information presented includes:

Event of the Scheduler: Specifies the type of scheduler event that took place.

1. **Event of the Scheduler:** Specifies the type of scheduler event that took place.
2. **Description:** Provides a brief description of the scheduled task or operation.
3. **Operation Performed on the Scheduled Period:** Outlines the specific action executed during the scheduled period.
4. **Planned At:** Indicates when the scheduler was initially planned or scheduled.
5. **Sub Event:** Offers details about any sub-events associated with the scheduler operation.
6. **Executed At:** Specifies the timestamp when the scheduler was executed.
7. **Execution Status:** Highlights the status of the scheduler execution, indicating whether it was successful or encountered issues.
8. **Remarks (If Any):** Includes any additional remarks or notes related to the scheduler operation, offering insights into the execution process.

<figure><img src="/files/udkyKQEWA5tDGqw3xuiK" alt=""><figcaption></figcaption></figure>

### Failed Jobs

The scheduler history provides various filters to identify status of failed jobs as shown below:

<figure><img src="/files/ObpHLnWv2QoMS45PrTSL" alt=""><figcaption></figcaption></figure>

These failed jobs are sent out as alerts to specified users as per the [notifications template](/getting-started/personalization/personalize-notification-templates)

### Reconciliation History

Reconciliation History provides a centralized dashboard for all system reconciliation jobs in one page. The relevant admin user can view the summary of all the tasks in progress, completed or aborted.&#x20;

<figure><img src="/files/mDlxMgYHZwG98O2R4Omv" alt=""><figcaption></figcaption></figure>

The tasks that have failed can be manually processed to run again by clicking on the retry button next to the failed history.&#x20;

The Reconciliation job will also alert the specified Cymmetri user of the tasks over email. The configuration is two-fold-

1. Global notification
2. Specific application notification

Cymmetri includes the ability to retry failed records based on the failed event. Administrators can configure the maximum number of retry attempts and set up notifications according to these settings.&#x20;

Cymmetri will send the alerts for all job status events to the specified user or email.

<figure><img src="/files/pCKYZs0VFk80BccNfsgs" alt=""><figcaption></figcaption></figure>


# Reconciliation History

The Cymmetri platform provides a centralized view for monitoring and auditing all reconciliation activities under the Audit Logs menu. This functionality offers administrators both a high-level summary and detailed drill-down views of each reconciliation job.

The Reconciliation History table, accessible via Audit Logs → Reconciliation History, has been enhanced to display the key reconciliation summary metrics directly in the table view.

This enhancement allows administrators to quickly assess the health and outcome of each reconciliation run without navigating to a separate detail page. The at-a-glance summary typically includes:

* **Pending Records**: Count of records awaiting processing.
* **Synced Records**: Count of records successfully synchronized (created, updated, or deleted).
* **Error Records**: Count of records that failed during the synchronization process.
* **Total Records**: The total number of records processed or considered in the run.

<figure><img src="/files/FyXLvi4pFjWi7ReT0gWk" alt=""><figcaption></figcaption></figure>

#### Detailed Reconciliation View (View History)

For a deeper analysis of a specific reconciliation run, administrators can select the View History option. This detailed view provides granular data organized across several key categories:

| **Modes**      | Sync field, Source attribute, Job completion time             | Specifies the primary attribute used for matching records, the source attribute used for data, and the final timestamp of the job's completion. |
| -------------- | ------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------- |
| **Conditions** | User does not exist in the Target System & exists in Cymmetri | Identifies users flagged for provisioning to the target system.                                                                                 |
| <p><br></p>    | User exists in Cymmetri & Target System                       | Identifies users flagged for profile update or validation across both systems.                                                                  |
| <p><br></p>    | User exists in Target System & does not exist in Cymmetri     | Identifies orphaned accounts in the target system, flagged for de-provisioning or review.                                                       |
| **Summary**    | Pending Records, Synced Records, Error Records, Total Records | The final statistical outcome of the reconciliation job.                                                                                        |

<figure><img src="/files/XXJfQWrvg1KBG4J5fR8a" alt=""><figcaption></figcaption></figure>

### Role Reconciliation Dashboard

The Role Reconciliation Dashboard is a specialized sub-page within the Recon History section dedicated to auditing and managing user role entitlements.

This dashboard provides administrators with the following granular details for each user involved in a role reconciliation activity:

| **Login**            | The unique login identifier of the user.                                                                                                                                    |
| -------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Already Assigned** | The set of roles that the user held before the current reconciliation process was executed.                                                                                 |
| **Fetched**          | The roles for this user that were successfully retrieved from the target application during the reconciliation run.                                                         |
| **Newly Assigned**   | Roles that have been provisioned to the user as a direct result of the reconciliation logic.                                                                                |
| **To Be Removed**    | Roles identified by the reconciliation logic as needing to be revoked from the user's profile.                                                                              |
| **Status**           | The current state of a role assignment, indicating if the role has been removed, is currently under administrator review, or has been confirmed for continued assignment.   |
| **Actions**          | Interactive options allowing the administrator to drill down for further details on the specific role or to initiate a manual action (e.g., overriding the removal status). |

<figure><img src="/files/1rCJ7zHSKxgV9Q3FToOl" alt=""><figcaption></figcaption></figure>

To establish a new reconciliation job, please refer to the dedicated documentation on [Reconciliation Configuration.](/lifecycle-management/application-management/reconciliation-how-to)


# Application Management


# Support for Application Management

In this section, we will provide you with detailed information about the types of applications and connectors supported by Cymmetri

### Supported Pre-configured Applications

#### Cloud Based Applications

Cymmetri seamlessly integrates with various cloud-based applications to help you efficiently manage user access and entitlements. The following are the pre-configured cloud-based applications that Cymmetri supports:

1. **Azure**: Manage user access and entitlements within your Microsoft Azure environment effortlessly.
2. **Google Workplace**: Simplify access management for Google Workspace applications, including Gmail, Google Drive, and more.
3. **ServiceNow**: Effectively control access to your ServiceNow instance to enhance security and compliance.
4. **Salesforce**: Streamline Salesforce user access management for better control and auditing.
5. **SCIM v2.0 (Salesforce)**: Utilize the System for Cross-domain Identity Management (SCIM) 2.0 protocol specifically for Salesforce integration.
6. **Github (Using SCIM 2.0 connector)**: Manage user access to GitHub repositories efficiently through our SCIM 2.0 connector.

#### On-Premises Applications

Cymmetri extends its support beyond cloud-based applications to include various on-premises applications. Here are the on-premises applications supported by Cymmetri:

1. **Active Directory**: Efficiently manage user access to your Windows Active Directory resources.
2. **OpenLDAP**: Simplify access control for your LDAP directory services with Cymmetri's integration.
3. **Lotus Notes**: Streamline user access management for Lotus Notes applications.
4. **Powershell**: Integrate and manage access to PowerShell scripts and resources seamlessly.
5. **CSV Directory**: Effectively manage user access within CSV-based directory services.

### Supported Connectors

Cymmetri offers versatile connector support to ensure seamless integration with a wide range of applications. Here are the supported connectors categorized by deployment type:

#### Using Cloud Connector

Cymmetri's Cloud Connectors are designed to simplify access management for various cloud-based applications. Supported cloud connectors include:

1. **Azure**: Easily manage access to Microsoft Azure resources with our cloud connector.
2. **Google Workplace**: Streamline access management for Google Workspace applications using our cloud connector.
3. **ServiceNow**: Control access to your ServiceNow instance efficiently with our cloud connector.
4. **Salesforce**: Seamlessly manage user access to Salesforce through our cloud connector.
5. **SCIM 1.1**: Leverage the SCIM 1.1 protocol for connector support, ensuring compatibility with various cloud services.
6. **SCIM 2.0 (Basic, Bearer, Fixed Bearer)**: Our platform supports multiple SCIM 2.0 authentication methods to accommodate diverse integration needs.

#### Using Locally Deployed Connector

For on-premises applications and custom integration scenarios, Cymmetri offers locally deployed connectors, providing flexibility and control. Supported locally deployed connectors include:

1. **Active Directory**: Manage access to Windows Active Directory resources seamlessly using our  connector.
2. **Custom Script for Databases**: Custom Script based connectors using groovy scripts for database applications, tailored to your specific requirements.
3. **LDAP**: Integrate and manage access to LDAP-based directory services through our connector.
4. **Lotus Notes**: Simplify user access management for Lotus Notes applications with our connector.
5. **Powershell**: Seamlessly integrate and manage access to PowerShell resources using our connector.
6. **REST API**: Extend your integration capabilities with Cymmetri's support for RESTful API connectors leveraging the flexibility of Groovy and UI based scripts.

Cymmetri's comprehensive support for both pre-configured applications and versatile connectors ensures that you have the tools needed to efficiently manage user access and entitlements across a diverse range of applications and environments. For detailed setup instructions and configuration guidelines, please refer to the specific documentation for each application and connector.


# Getting Started


# Introduction to Application Management

Understand how to add and manage your cloud and on-premise applications through your Cymmetri Identity platform deployment. Your Cymmetri Identity deployment allows you to manage your cloud-based applications and on-premise applications from a single administration console.\ <br>

#### Adding Applications

Understand how to add the applications used by your organization to be managed in your Cymmetri Identity platform deployment. Use the FAQ to learn how to add applications to be managed in the deployment.

#### &#x20;Single Sign On

Single Sign On is the process of ensuring that once an end user is logged onto the Cymmetri Identity platform, they should be able to seamlessly move their session to any of your applications managed by your Cymmetri Identity platform deployment. Use the FAQ to learn how to configure Single Sign On for your application.

#### &#x20;Managing the Application Sign-On Policy

Modern IAM deployments wishing to have progressive authentication may require some critical application integrations within your deployment to perform additional authentication while performing Single Sign On for the end user. Use the FAQ to learn how to configure the Application Sign On Policy.

#### &#x20;Provisioning

Provisioning refers to the process of creating, modifying, and, in general, pushing the user account information stored on the Cymmetri Identity platform to the applications managed by your Cymmetri Identity platform deployment. Use the FAQ to learn how to configure User Account Provisioning.

#### &#x20;Reconciliation

Reconciliation of User accounts is a primary activity in Identity Governance, which allows for synchronisation between the user account information on the managed application and the Cymmetri Identity platform deployments, including provisioning, modifying, deprovisioning, and modifying user account attributes based on various synchronisation states. Use the FAQ to learn how to configure the Identity Reconciliation Process.

#### &#x20;Assigning Application

Once an application has been added to the Cymmetri Identity platform deployment and the necessary configurations for Single Sign On, Provisioning, and Reconciliation have been performed, an application may be assigned to an individual user or to a group of users. Use the FAQ to learn how to assign an application to a user.


# Adding Applications to be managed by Cymmetri

### Accessing the Applications Menu

Applications menu in the administration page displays the various options pertaining to the Application Management Process.

Applications menu can be accessed as mentioned below:

**Identity Hub**

1. Login as either an Organization Administrator, Domain Administrator,  or Application Administrator.&#x20;
2. Click on the Identity Hub icon on the left side bar.
3. Click on the Applications text on the slide out bar.

   <figure><img src="/files/UeJHiU6Ot5Oc1tpIlmPl" alt=""><figcaption></figcaption></figure>

### Understanding the applications supported by Cymmetri

Applications supported by the Cymmetri platform fall majorly into three categories -&#x20;

1. **Pre-configured Applications**\
   These are the applications that have already been configured by the Cymmetri platform for provisioning on cloud or on-premises.&#x20;
2. **Custom Applications for Provisioning**\
   These are the applications that you wish to manage through Cymmetri and support the generic connectors that the Cymmetri platform provides.&#x20;
3. **Custom Applications for Single SignOn only**\
   When you need to add an application for the sole purpose of enabling Single Sign-On (SSO), Cymmetri offers the capability to add a custom application that can be configured for SSO using the supported mechanisms.

### Adding Application

Once you have chosen the application to be added from the above categories, you are ready to add a new application.

<figure><img src="/files/MVTQpmJ2dZ4Spcz4uGya" alt=""><figcaption></figcaption></figure>

1\. Click on the “Add New” button on the top-right corner in the Applications page.

<figure><img src="/files/TK4WIrWnWhszJLJhgDUt" alt=""><figcaption></figcaption></figure>

2\. In the Add New Application screen, you may search for your desired application (e.g., Active Directory or some authorative source like Darwin Box or Oracle HCM), or your desired connector (e.g., REST) or choose the “Custom” application type from the available application catalogue.

<figure><img src="/files/NWi4wln21rd1gd5j24AE" alt=""><figcaption></figcaption></figure>

And also support for other standard categories of applications as shown below:

<figure><img src="/files/KuYgPhPdrYOklTFuUyWA" alt=""><figcaption></figcaption></figure>

3\. Now click on the tile shown in the list below to open the right slide out menu for renaming application as shown below.

<figure><img src="/files/ZfidJrc3Gc3K46N3tAqM" alt=""><figcaption></figcaption></figure>

4\. Add your custom label (if you wish) in the text box and click on the “Add Application” button.

<figure><img src="/files/HOCcBaGaqTcbs6w7LFnf" alt=""><figcaption></figcaption></figure>

### Conclusion

Application has been successfully added to your listing now. You may click on the configure now button to start configuring the application.&#x20;


# Assigning Applications to End Users

Once the managed application has been added to your Cymmetri Identity platform tenant, you will be able to assign applications to your end-users.

## Application Assignment

There are three ways in which applications can be assigned to users:

1. Admin may assign an application directly to a user.
2. Admin may map an application to a group; and the user is added to the group or is already part of the group.
3. End User may request an application and is granted access to the application.
4. Bulk Assignment of application to a set of users

Let us understand the flow for each of the above mentioned scenarios:

### 1. Admin assigns an application directly to the end user

Users with admin roles such as Organization Admin, Domain Admin, or Application Admin on the Cymmetri platform can assign managed applications to end-users .

* First, we need to add the application to the Cymmetri platform&#x20;
* Next, we move to configure the application to assign it to an end user.&#x20;
* Click on the application tile to configure it.

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452584/original/xiYYVZYw6l-DaQrYB5-MfcsEwLWHz_IyTQ.png?1649361741)

The flow for assignment goes as follows -&#x20;

\ <br>

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452593/original/OeB-MQUg9xDm_Lut2kePYwlqqDDAB5vIAA.png?1649361758" alt=""><figcaption><p>Assignment Flow 1</p></figcaption></figure>

**Description:**

1. Admin clicks on the application tile, and starts the configuration.
2. Click on the Assignments tab on the left hand side menu.<br>

   <figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452599/original/nbuQEr1_YjbmPYpqc7LoRXnv4LSehpVcXA.png?1649361774" alt=""><figcaption></figcaption></figure>
3. Click on the “Assign New” button on the Users menu.\ <br>

   ![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452608/original/sxN2BHQBNXwusaI7jzq-mioYIrOsOMowfQ.png?1649361803)
4. Search for a user in the search text box, and once the user is found, click on the “Assign” button.\
   \
   ![](/files/ysIEQlJpykHtPO8CCUms)<br>
5. Here we need to decide whether we want to provide a Lifetime Access or a Time Based Access
   1. Lifetime Access: Users have access to the application without any time restrictions.
   2. Time Based Access: Users have access to the application only for the specified range of time. We need to provide a Start Date & Time and an End Date & Time for Time Based Access.
6. Now click on Save to register a request for the application assignment. If no Workflow is configured for the said application the application is immediately assigned to the user.
7. If a workflow for application provisioning is configured then the workflow is been initiated.&#x20;
8. The workflow approver will then receive a request to approve the user assignment in their inbox.

   <figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452811/original/Tw_Bfj8y-MCIRAw47JHl6ihya55-WB098g.png?1649362021" alt=""><figcaption></figcaption></figure>
9. Now the approver may approve or reject the user assignment

   <figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452822/original/k9DcpEWagBvk1GTXFm2hL0CQBfIijv5B0g.png?1649362035" alt=""><figcaption></figcaption></figure>
10. The approver may change the start and end date, if required; refer to the dynamic form attributes passed during the application assignment.
11. To continue the flow click on Accept button.
12. Now the next level of approver will be able to see the previous levels of approval, and similar to the previous level of approval, the approver may change the start and end date, if required; refer to the dynamic form attributes passed during the application assignment.<br>

    <figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452839/original/szqPQHWWV4Dr4usjPr9vApQUe8eOcRHGYQ.png?1649362063" alt=""><figcaption></figcaption></figure>
13. Click “Accept” to proceed.
14. After the last level approver has also approved the assignment, the backend processes will run the application provisioning flow.
15. Once the user has been provisioned in the application, they will be able to see it in their list of applications.

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452855/original/yIiCVFhX-xmZBLAib632fRt2FOo2gfsddg.png?1649362113)

### 2. Admin assigns an application directly to a group

Users with admin roles, such as Organization Admin, Domain Admin, or Application Admin, in a Cymmetri Identity platform deployment, will have the ability to assign entire groups of users to managed applications.

1. First, we need to add the application to the Cymmetri platform&#x20;
2. Next, we move to configure the application to assign it to a group.&#x20;
3. Click on the application tile to configure it.

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452871/original/HJ0p2g84Uq3t2iZjw-Njl0f_1F5Xt2NTjA.png?1649362175)

The flow for assigning a group to an application goes as follows:

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452874/original/jBAmY21QlWvt6p9pYzv_LE5YdAejqJA4hg.png?1649362184)

#### Description:

1. Click on the application tile, and start the configuration.
2. Click on the Assignments tab on the left hand side menu.

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452877/original/wuX1T9aiREcmEA2Nr79IPjpIDruIl2fDyw.png?1649362194)

&#x20; 3\. Click on the “Assign New” button in the Groups section.

<img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452927/original/FyPDfWvkssrdf2fjxUZx23scPYrpHsxboQ.png?1649362230" alt="" width="375">

4\. Search for the group you wish to assign the application to and click on the assign button.

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452938/original/5xNHapIgNY2Oe4HsNYIMNFkOMtl6VOKcBw.png?1649362253" alt="" width="375"><figcaption></figcaption></figure>

5\. Checking for the users who belong to the group, we can see that the application has been assigned.

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452940/original/yIQBsDwXIReecmD9CzTG6Jn5PyEkMnuPXA.png?1649362261" alt=""><figcaption></figcaption></figure>

6\. Viewing the application tiles, we can see if the user was directly assigned the application or received access by the virtue of being part of a group.

### 3. User requests for an application

Users on the Cymmetri platform can request access to a managed applications as a Self-Service feature.

The flow for an end-user to request for an application is as follows:

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452944/original/A7QgI3tEFdKgPlJmwJ6QpDQAqYO3Hw1qVw.png?1649362276)

#### Description:

1. Visit the “My Workspace” menu.
2. Click on the “My Access” left-hand side menu.&#x20;

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452946/original/9iDRCJViyzRPycWajWXJTO5RleOCaBfiDA.png?1649362286)

3\. Now Click on the “+ Request” button on the top-right button.

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452994/original/NJpHoh2kU4Unhqv-CI8trs3K4KwUc4KN9g.png?1649362313" alt=""><figcaption></figcaption></figure>

4\. Click on the Application Icon to start the request process\
\
![](/files/ysIEQlJpykHtPO8CCUms)<br>

1. Here we need to decide whether we want to provide a Lifetime Access or a Time Based Access
   1. Lifetime Access: Users have access to the application without any time restrictions.
   2. Time Based Access: Users have access to the application only for the specified range of time. We need to provide a Start Date & Time and an End Date & Time for Time Based Access.
2. Now click on Save to register a request for the application assignment. If no Workflow is configured for the said application the application is immediately assigned to the user.
3. If a workflow for application provisioning is configured then the workflow is been initiated.&#x20;
4. The workflow approver will then receive a request to approve the user assignment in their inbox.

   <figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452811/original/Tw_Bfj8y-MCIRAw47JHl6ihya55-WB098g.png?1649362021" alt=""><figcaption></figcaption></figure>
5. Now the approver may approve or reject the user assignment

   <figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452822/original/k9DcpEWagBvk1GTXFm2hL0CQBfIijv5B0g.png?1649362035" alt=""><figcaption></figcaption></figure>
6. The approver may change the start and end date, if required; refer to the dynamic form attributes passed during the application assignment.
7. To continue the flow click on Accept button.
8. Now the next level of approver will be able to see the previous levels of approval, and similar to the previous level of approval, the approver may change the start and end date, if required; refer to the dynamic form attributes passed during the application assignment.<br>

   <figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452839/original/szqPQHWWV4Dr4usjPr9vApQUe8eOcRHGYQ.png?1649362063" alt=""><figcaption></figcaption></figure>
9. Click “Accept” to proceed.
10. After the last level approver has also approved the assignment, the backend processes will run the application provisioning flow.
11. Once the user has been provisioned in the application, they will be able to see it in their list of applications.

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003452855/original/yIiCVFhX-xmZBLAib632fRt2FOo2gfsddg.png?1649362113)

### 4. Bulk Assignment of application to a set of users

An administrator can bulk assign an application to a set of users. This an be achieved by uploading a .csv file which contains user information like.,  loginId, appUserId and  roleId.\
\
For bulk assigning applications to users in Cymmetri platform administrator needs to

1. Click on **Identity Hub > Applications** menu and then click on the **Applications Assignments** button.

<figure><img src="/files/mpvk8tZ7a7YaGCsQAMFF" alt=""><figcaption></figcaption></figure>

2. A screen pops up that lets you select the csv file you want to upload that contains the list of users to whom the application needs to be assigned, Upload the csv file, you may also use the sample data file available and modify it to match your user details.

<figure><img src="/files/q75Kh5FmIhqNZhBXB4RP" alt=""><figcaption></figcaption></figure>

3. Click on the **Upload File** button and select the file you wish to import

<figure><img src="/files/mESuKgtCI5ZouC2kLtIr" alt=""><figcaption></figcaption></figure>

4. Once the file is selected ensure that the default parameters select match your requirement else you may change these parameters as per your requirement.
5. Once you have ensured the parameters are correct next select the application that needs to be assigned and click on **Next** button.

<figure><img src="/files/BfinqfkLKWM8CESyjapJ" alt=""><figcaption></figcaption></figure>

6. Match the Column names from the CSV file with the corresponding attributes using this File Info dialog box and click on the **Import** button.

<figure><img src="/files/B1EgbCQAjkCS6y5DKCtn" alt=""><figcaption></figcaption></figure>

***Note:** The "Link Application" check box is available to provision the user in the target application*&#x20;

7. Once Imported results of successfully Imported Users, Duplicate Users or any error that occurred during import can be see in **Logs > Import History** page

<figure><img src="/files/KNB6xgjD3fZM5yPK3Rdv" alt=""><figcaption></figcaption></figure>

8. If any workflow is configured on the application provisioning then the corresponding workflow is triggered after the successful completeion of assignment as shown below:

<figure><img src="/files/TWTDirVcRibvLuxgrXCS" alt=""><figcaption></figcaption></figure>


# Application Detail

The Application Detail Page provides comprehensive management features for applications within the system. It includes various sub-pages for configuring assignments, sign-on protocols, policies, provisioning settings, roles, and more. Below we outline the functionalities and configurations available on each sub-page.

<figure><img src="/files/R9AhwkZYLAAJMBqmryTT" alt=""><figcaption></figcaption></figure>

### **Assignments**

This page allows administrators to assign users and groups to an application. Users or group members can access the application if it is configured for Single Sign-On (SSO) or get provisioned in the application if it is a provisioning application.

* **Features**:

  * Assign users and groups to the application.
  * View and manage existing assignments.

  <figure><img src="/files/qyFUOwkRt25namkCGT2X" alt=""><figcaption></figcaption></figure>

### **SignOn**

Configures the application for sign-on using various protocols.

<figure><img src="/files/8JXOhHdPel0c3TenV711" alt=""><figcaption></figcaption></figure>

* **Supported Protocols**:
  * **SAML**: Configure SAML-based single sign-on.
  * **OpenID**: Set up OpenID Connect for authentication.
  * **Reverse Proxy**: Configure reverse proxy settings for sign-on.
  * **API SSO**: Set up API-based single sign-on.
* **Features**:
  * Protocol selection and configuration.
  * Test and validate sign-on settings.
  * Manage sign-on settings for different environments.

### **SignOn Policy**

Configure Multi-Factor Authentication (MFA) for the application’s SSO settings.

* **Features**:

  * Configure MFA prompts and policies.
  * Manage MFA settings to ensure secure access.

  <figure><img src="/files/ULvXFwtiEqcRPd6qoAlS" alt=""><figcaption></figcaption></figure>

### **Provisioning**

Configure application provisioning with various settings organized into tabs.

* **Tabs**:
  * **User Configuration**: Define application attributes and settings for provisioning.
  * **Server Configuration**: Set up connector server parameters.
  * **Operations**: View provisioning operations supported
  * **Hook Configurations**: Configure hooks for triggering provisioning actions.
* **Features**:

  * Manage and configure provisioning details.
  * View and edit provisioning settings.
  * Monitor provisioning operations.

  <figure><img src="/files/1bXTzD3zGHtgAIOQ1RFS" alt=""><figcaption></figcaption></figure>

### **Roles**

&#x20;Create and manage application roles and import roles from CSV files.

* **Features**:

  * Create new roles.
  * Import roles via CSV for bulk role creation.
  * Manage and edit existing roles.
  * Ensure roles are correctly provisioned in target applications.

  <figure><img src="/files/ZdQoAzQ57Eovz9nwJfT8" alt=""><figcaption></figcaption></figure>

### **Policy Map**

Configure mapping between the provisioning source application and Cymmetri user fields.

* **Features**:

  * Define and manage field mappings for data synchronization.
  * View data mappings for User Pull Reconciliation.
  * Ensure accurate data exchange between systems.

  <figure><img src="/files/5ksXhpeEhfAatjk6WneA" alt=""><figcaption></figcaption></figure>

### **Settings**

Configure general settings for the application. This section allows you to modify application label and description. You may also configure other settings as shown below:

<figure><img src="/files/PtZNRDYDM6qB5vjilUWw" alt=""><figcaption></figcaption></figure>

#### **Application Risk Level:**&#x20;

This section lets you set application's risk which enables for identifying overall risks for users. The Risk level can be set to **High, Medium, Low** and **Unknown**

<figure><img src="/files/A38MCCF1eVIL51U3A2l2" alt=""><figcaption></figcaption></figure>

#### **Visibility settings:**

Administrator may configure visibility settings as shown below

* **Show to User:** This setting when enabled lets the user see an application assigned to them.
* **User can request:** This setting when enabled lets the user to request an application which is not assigned to the user.

<figure><img src="/files/ioZ1emvhNYLfVu3qbmna" alt=""><figcaption></figcaption></figure>

#### **Role settings:**&#x20;

Administrator may configure various role settings as shown below:

* **Multiple role assignments:** which allows a user to have multiple roles in the said application and&#x20;
* **Mandatory roles:** This setting mandates that when the application is assigned atleast one role is assigned to the user
* Add notes for end users and administrators.

### **Policy Attribute**

This page lets you configure all the attributes from the provisioning source whose data needs to be synced on either sides.

<figure><img src="/files/vuJgH7fOKkvxNIzJFsCC" alt="" width="563"><figcaption></figcaption></figure>

### **Reconciliation**

Configure reconciliation settings for data synchronization.

* **Features**:

  * Set up pull reconciliations to retrieve data from the source application.
  * Configure push reconciliations to update data in the source application.
  * Manage reconciliation schedules and tasks.

  <figure><img src="/files/Gm2YC1js9DuLTN8xM4IG" alt=""><figcaption></figcaption></figure>

### **Forms**

Configure dynamic forms used in workflows for additional data collection.

* **Features**:

  * Create and manage dynamic forms.
  * Configure forms to collect data during workflow processes.
  * View and edit form data as required by administrators and users&#x20;

  <figure><img src="/files/zkRVkRpsBqTlfLHxF8oQ" alt=""><figcaption></figcaption></figure>

### **Tags & Meta**

Manage tags and meta information for applications.

* **Features**:

  * Create and assign tags for categorization and search.
  * Add and manage meta information for various purposes.
  * Use tags and meta data to enhance application organization, search and categorization

  <figure><img src="/files/WL43y0oeuh8fvFvKrxhL" alt=""><figcaption></figcaption></figure>

### **360 Degree Recon**

* **Description**: Provides a comprehensive reconciliation view for data synchronization across the system.
* **Features**:

  * View detailed reconciliation data and statuses.
  * Analyze and resolve reconciliation issues.

  <figure><img src="/files/i409LjjEK5voZaIWyUSx" alt=""><figcaption></figcaption></figure>


# Dynamic Forms

Dynamic Forms enable administrators to request additional fields from either administrators or end-users when assigning applications. These additional user fields are then collected and used for provisioning the user into the managed application.

### Creating a dynamic form:

For creating a dynamic form the administrator needs to configure the managed application. For e.g. **Identity Hub->Applications->Service Now(Application may change )->Forms**

Load the default form by clicking on the “Load Sample Data” button

<figure><img src="/files/l4bNsR6jiN86VL7vF0wf" alt=""><figcaption></figcaption></figure>

Edit the default form in the **JSON Schema** section, In the JSON Schema section the administrator can define the form structure with the type of element, and its various properties like type, title, default value etc., a preview of the form is shown on the right hand side.

Let us create a simple form that can capture&#x20;

1. “Preferred Username” \[text field] and&#x20;
2. “Request Additional Modules” \[Radio] with two options “Administrator” and “Read Only”.

The code below shows how to create a simple form described above:

<pre class="language-json" data-overflow="wrap"><code class="lang-json">{ 
<strong>  "type": "object", 
</strong>  "required": [ 
    "preferredName" 
  ], 
<strong>  "properties": { 
</strong>    "preferredName": { 
    "type": "string", 
    "title": "Preferred Username", 
    "default": "" 
  }, 
  "additionalModules": { 
    "type": "string", 
    "title": "Additional Modules", 
<strong>    "enum": [ 
</strong><strong>      "admin", 
</strong>      "readonly" 
    ], 
    "enumNames": [
       "Administrator",
       "Read-Only" 
    ], 
    "default": "" 
    } 
<strong>  }
</strong>}
</code></pre>

<figure><img src="/files/SuJuJqqpXfoIAfAQeuVp" alt=""><figcaption></figcaption></figure>

The **UI Schema** is like a set of json properties that are used to configure how the form should look and behave. It lets you tweak things like the length of a text box or whether a choice should be shown as radio buttons or checkboxes. In the example code, we're using the UI Schema to make the "preferredName" field have a placeholder and also set a maximum length. For "additionalModules," we're using widget property to make it show up as a radio button.

```
{
  "preferredName": {
    "placeholder": "Enter preferred name",
    "maxLength":5
  },
  "additionalModules": {
    "ui:widget": "radio"
  }
}
```

The **Preview Form Data** displays how the data entered in the UI will be gathered and shows the structure in which the data will be sent to the API.

<figure><img src="/files/kwr5isElUsVsslNKe362" alt=""><figcaption></figcaption></figure>

The preview of the form looks as below after making the changes:

<figure><img src="/files/B51k2047I977dYQAY94y" alt="" width="370"><figcaption></figcaption></figure>

Once configured the administrator can Click on the Save button.

<img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003453247/original/rv1xlOomrNqjVWATvEPk4P9nDxtxUF8n9Q.png?1649362681" alt="" width="375">

Once saved a confirm box appears to enable the form; the administrator needs to click on the **Confirm** button in the popup to enable the form for the application.

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003453249/original/oLJcRIFKG72bSjV6y7MMxG-lMKAgsFwcWQ.png?1649362689)

### Form Options

There are four options in that can be configured after enabling forms in Cymmetri

![](/files/srMgvYWyaAo3SNaAgLa2)

1. **Form View**: If enabled, the user has the option to see the application request form within the My Access section.
2. **Form Edit**: If enabled, the user has the option to edit the application request form within the My Access section, this will make changes in the respective fields in the target application.
3. **Role Assignment:** If activated, the user will be displayed the request form for applications that are already assigned to them when attempting to request additional roles.
4. **Role Unassignment:** If activated, the user will be displayed the form for applications when he/she is raising requests for role removal.


# Managing Manual Application Assignments

Cymmetri can work with systems that handle user account provisioning manually, such as help desk or service request platforms. These systems typically rely on human intervention to create, modify, or deactivate user accounts, and Cymmetri can communicate or integrate with them to streamline these processes.

For example: If a company hires a new employee, the help desk team manually creates an account for the employee. Cymmetri connects with this help desk system to track or manage the account creation process.

<figure><img src="/files/GylGphy9adE1t71AJRNH" alt=""><figcaption></figcaption></figure>

### Manual Application Provisioning Workflow


# Configuring Connector Server

Connectors can be deployed in two ways:

* **Local connectors** are deployed to a Cymmetri instance. This is the usual way how connectors are used. The connector is executed inside a Cymmetri instance, has the same lifecycle (start/stop), etc. Cymmetri can detect local connectors automatically and overall the connector management is easier.
* **Remote connectors** are executed in a different process or on a different node than Cymmetri instance. Remote connectors are deployed to a connector server. There may be need to use a remote connector e.g. to access a file on a remote system (e.g. in case of CSV connector) or because of platform incompatibilities (e.g. .NET connectors)

Connector is **not** developed as local or remote. The placement of the connector is a deployment-time decision. There is just one connector package that can be deployed locally or remotely.

A connector server is required when a connector bundle is not directly executed within your application. By using one or more connector servers, the connector architecture thus permits your application to communicate with externally deployed bundles.

Connector servers are available for both Java and .NET.

A **Java connector server** is useful when you do not wish to execute a Java connector bundle in the same VM as your application. It may be beneficial to run a Java connector on a different host for performance improvements if the bundle works faster when deployed on the same host as the native managed resource. Additionally, one may wish to use a Java connector server under a Java remote connector server in order to eliminate the possibility of an application VM crash due to a fault in a JNI-based connector.

The use of **.NET connector server** is especially useful when an application is written in Java, but a connector bundle is written using C#. Since a Java application (e.g. J2EE application) cannot load C# classes, it is necessary to instead deploy the C# bundles under a .NET connector server. The Java application can communicate with the C# connector server over the network, and the C# connector server serves as a proxy to provide to any authenticated application access to the C# bundles deployed within the C# connector server.

## Java Connector Server

### Installing a Java Connector Server

Minimum Requirements:

* Java 1.6 or later for 1.4.X.Y / Java 1.8 for 1.5.X.Y
* Refer to your Java connectors to determine if there are any additional requirements&#x20;

#### Create your execution environment

* Download the Connector Server package
  * [1.3.3.1](https://repo1.maven.org/maven2/org/connid/connector-server-zip/1.3.3.1/connector-server-zip-1.3.3.1.zip)
  * [1.4.5.1](https://repo1.maven.org/maven2/net/tirasa/connid/connector-server-zip/1.4.5.1/connector-server-zip-1.4.5.1.zip)
  * [1.5.0.1](https://repo1.maven.org/maven2/net/tirasa/connid/connector-server-zip/1.5.0.1/connector-server-zip-1.5.0.1.zip)
  * [1.5.1.0](https://repo1.maven.org/maven2/net/tirasa/connid/connector-server-zip/1.5.1.0/connector-server-zip-1.5.1.0.zip)
* Unzip it in a directory of your choice (e.g. `/usr/jconnserv`) on the host where you wish to run the Java connector server

#### Test your execution environment

From the directory created above, run the Java connector server with no arguments to see the list of command-line options:

* Linux / MacOS: `./bin/ConnectorServer.sh`
* Windows: `\bin\ConnectorServer.bat`

You should see the following output:

```
Usage: 
  Main -run -properties 
  Main -setkey -key  -properties 
  Main -setDefaults -properties 
```

#### Configure your Java connector server

* Run the connector server with the `setkey` option as described below to set your desired key into your properties file
  * Linux/ MacOS: `./bin/ConnectorServer.sh -setkey <key> -properties conf/ConnectorServer.properties`
  * Windows:  `bin\ConnectorServer.bat /setkey <key> /properties conf\ConnectorServer.properties`
* For all other properties (e.g. port), edit the `conf/connectorserver.properties` manually. The available properties are described in the `connectorserver.properties` file.

### Running your Java connector server

Run the server by launching with the -run option:

* Linux / MacOS: `./bin/ConnectorServer.sh -run -properties conf/ConnectorServer.properties`
* Windows:  `bin\ConnectorServer.bat /run -properties conf\ConnectorServer.properties`

### Installing Connectors on a Java Connector Server

To deploy a Java connector:

* Copy the Java connector bundle jar file into the `bundles` directory in your Java connector server directory
* If necessary, add to the classpath any 3rd party jars required by any Java connector
* Restart the Java connector server

### Using SSL to communicate with connector servers

The following steps are necessary to successfully communicate with a connector server using SSL:

* Deploy an SSL certificate to the connector server's system.
* Configure your connector server to provide SSL sockets.
* Configure your application to communicate with the communicate with the connector server via SSL.

#### Configure your application to use SSL

Refer to your application manual for specific notes on how to configure connections to connector servers. You will need to indicate to your application that an SSL connection is required when establishing a connection for each SSL-enabled connector server.

Additionally, if any of the SSL certificates used by your connector servers is issued by a non-standard certificate authority, your application must be configured to respect the additional authorities. Refer to your application manual for notes regarding certificate authorities.

Java applications may solve the non-standard certificate authority issue by expecting that the following Java system properties are passed when launching the application:

* javax.net.ssl.trustStorePassword\
  For example, `-Djavax.net.ssl.trustStorePassword=changeit`
* javax.net.ssl.trustStore\
  For example, `-Djavax.net.ssl.trustStore=/usr/myApp_cacerts`

Or, instead, the non-standard certificate authorities may be imported to the standard ${JAVA\_HOME}/lib/security/cacerts.

## .NET Connector Server

### Installing a .NET Connector Server

Minimum Requirements:

* Windows Server 2003 or 2008
* .NET Framework 3.5 or higher
* Refer to your .NET connector to determine if there are any additional requirements

Execute **ServiceInstall.msi**. Just follow the wizard. It will walk you through the whole process step by step. Upon completion, the Connector Server will be installed as a windows service.

### Configuring the .NET Connector Server

Start the Microsoft Services Console. Check to see if the Connector Server is currently running. If so, stop it. From a command prompt, set the key for the connector Server. This is done by changing to the directory where the connector server was installed (by default: \Program Files\Identity Connectors\Connector Server) and executing the following command:

```
ConnectorServer /setkey <newkey>
```

where \<newkey> is the value for the new key. This key is required by any client that connects to this Connector Server.

Look through the configuration file and inspect all settings. The most common things to change would be the port, trace, and ssl settings.

#### Additional Notes about configuration

The port, address, and SSL settings are in the tag called `AppSettings`, and look like this:

```
<add key="connectorserver.port" value="8759" />
<add key="connectorserver.usessl" value="false" />

<add key="connectorserver.certificatestorename" value="ConnectorServerSSLCertificate" />
<add key="connectorserver.ifaddress" value="0.0.0.0" />
```

The port can be set by changing the value of connectorserver.port. The listening socket can be bound to a particular address, or can be left as 0.0.0.0. To setup to use SSL, you must set the value of connectorserver.usessl to true, and then set the value ofconnectorserver.certifacatestorename to your the certificate store name.

You will need to record for use later the following information regarding your connector server installation:

* Host name or IP address
* Connector server port
* Connector server key
* Whether SSL is enabled

#### Changing Trace Settings

Trace settings are in the configuration file. The settings look like this:

```
<system.diagnostics>
  <trace autoflush="true" indentsize="4">
     <listeners>
       <remove name="Default" />
       <add name="myListener" type="System.Diagnostics.TextWriterTraceListener"
  initializeData="c:\connectorserver2.log" traceOutputOptions="DateTime">        
         <filter type="System.Diagnostics.EventTypeFilter" initializeData="Information" />
       </add>
    </listeners>
  </trace>
</system.diagnostics>
```

The Connector Server uses the the standard .NET trace mechanism. For more information about the tracing options, see Microsoft's .NET documentation for System.Diagnostics.

The default settings are a good starting point, but for less tracing, you can change the EventTypeFilter's initializeData to "Warning" or "Error". For very verbose logging you can set the value to "Verbose" or "All". The amount of logging performed has a direct effect on the performance of the Connector Servers, so be careful of the setting.

Any configuration changes will require the connector server to be stopped and restarted.

### Running the .NET Connector Server

The best way to run the Connector Server is as a Windows service. When installing, the Connector Server is installed as a Windows service. This should be fine for most installations.

If for some reason, this is not adequate, the connector server may be installed or uninstalled as a Windows service by using the /install or /uninstall arguments on the command line. To run the Connector Server interactively, issue the command:

```
ConnectorServer /run
```

#### Installing Connectors on a .NET Connector Server

To install new connectors, change to the directory where the Connector Server was installed, and unzip the zip file containing the connector there. Restart the Connector Server.

#### Running Multiple Connector Servers on the Same Machine

To install additional Connector Servers on the same machine, download the Connector Server zip file from the downloads section. Create a directory to install to, and unzip the file there. Edit the configuration file as described above ensuring that you have a unique port. You may also want to make sure that the trace file is different as well. You can then run the additional Connector Server interactively or as a service.


# 360 Degree Recon

The 360 Degree Recon is one of a type feature of Cymmetri that enables administrators to have a holistic view of user data.

The 360-degree reconciliation process in Cymmetri is designed to ensure that identity data across different systems is consistent and up-to-date. The reconciliation process involves comparing records from Cymmetri with the records in target systems (like Active Directory) and identifying discrepancies that need to be addressed.

The 360-degree reconciliation process in Cymmetri is crucial for maintaining data integrity across all connected systems. By regularly running reconciliation, organizations can ensure that their identity data is accurate.

### Configuring 360 Degree Recon

The 360 degree recon can be configured for all the provisioning applications supported by Cymmetri. Here we will be seeing an example of 360 Degree Recon with Active Directory.

As the first step for configuring 360 Recon the administrator needs to configure a pull recon as explained [here](/lifecycle-management/application-management/provisioning-how-to/active-directory-legacy-provisioning#pull-reconciliation).&#x20;

<figure><img src="/files/IQ6PK3urrLqN2xJmTEQu" alt=""><figcaption></figcaption></figure>

Once the pull recon is configured the user next needs to go on the 360 Degree Recon page as shown below:

<figure><img src="/files/kcSUP5XqJYAz73u5QVR7" alt=""><figcaption></figcaption></figure>

The 360-Degree Reconciliation page displays all the pull reconciliations configured for either users or groups. The administrator can select a configured reconciliation and run a 360-degree reconciliation for that specific pull.

<figure><img src="/files/bDixzcs8Not2o9bMCovQ" alt=""><figcaption></figcaption></figure>

Once the 360-degree reconciliation is started the administrator can then go to the History tab and view the results of the reconciliation on the reconciliation dashboard

<figure><img src="/files/sbMrvzphjRcntkoChI7p" alt=""><figcaption></figcaption></figure>

**Reconciliation Dashboard**

The reconciliation dashboard provides an overview of the latest reconciliation run, including key metrics and visualizations to help administrators quickly identify and address issues.

**Key Metrics:**

* **Last Start Date**: Indicates the start time of the most recent reconciliation run.
* **Last End Date**: Indicates the end time of the most recent reconciliation run.
* **Total Processed Records**: The total number of records processed during the reconciliation.
* **Records Pulled from Target App**: The number of records pulled from the target application (e.g., Active Directory).
* **Present in Cymmetri only**: Number of records that exist in Cymmetri but not in the target system.
* **Present in Target only**: Number of records that exist in the target system but not in Cymmetri.
* **Accounts Overdue in the target**: Number of accounts that are overdue in the target system but not reflected in Cymmetri.

**Break Type Analysis**

The break type analysis section uses a pie chart to categorize the types of breaks (discrepancies) identified during the reconciliation. In the example shown in the image, all breaks are categorized as "Present in Cymmetri only," indicating that certain records exist in Cymmetri but are missing from the target system.

**Filter Options**

Administrators can filter the results based on several criteria:

* **Login ID**: Search for discrepancies related to specific user logins.
* **Break Type**: Filter the results based on the type of break (e.g., "IDM exists, Target not exists").
* **Break Count Min/Max**: Filter based on the minimum and maximum break counts.

**Reconciliation Results Table**

The results table provides detailed information on the discrepancies found during the reconciliation process.

**Columns:**

* **User Login**: The login ID of the user in the Cymmetri IDM system.
* **Source Application Login**: The corresponding login ID in the source application (e.g., Active Directory).
* **Application Login**: The login ID in the application (if applicable).
* **Break Type**: Describes the nature of the discrepancy (e.g., "IDM exists, Target not exists").
* **Break Count**: Indicates how many times this particular break type was found for the user.
* **Actions**: Provides option for viewing the user details for further understanding of the user data

**Common Break Types**

* **IDM Exists, Target Not Exists**: This indicates that the user or identity exists in the Cymmetri IDM system but does not exist in the target system (e.g., Active Directory).
* **Target Exists, IDM Not Exists**: This indicates that the user or identity exists in the target system but does not exist in the Cymmetri IDM system.

**Actions to Resolve Discrepancies**

Once discrepancies are identified, administrators can take the following actions:

* **Manual Review**: Examine the discrepancy details and determine if the record should be updated, deleted, or if the discrepancy can be ignored.
* **Automated Actions**: Depending on the configuration, some discrepancies can be automatically resolved by provisioning or de-provisioning the necessary accounts.


# 360 Degree Comparison Report

Cymmetri’s 360-Degree Reconciliation feature provides a robust solution for ensuring data integrity and consistency across your organization’s identity landscape. This functionality involves pulling user and role information from various applications connected to the Cymmetri platform. This collected data is then compared against your organization's primary Source of Truth (e.g., HRMS) and the Cymmetri identity store.

Key Capabilities and Benefits

This feature provides a holistic, 360-degree view of user entitlements, allowing administrators to easily identify and rectify discrepancies. It facilitates several critical reporting and security scenarios, including:

* Identity Discrepancy Reporting: The system can generate reports highlighting users who exist in the source application but are not present in the Cymmetri identity store or a target application. This helps identify onboarding failures or synchronization issues.
* Entitlement Mismatch Analysis: It provides a comprehensive comparison of user entitlements (roles, permissions, etc.) across multiple applications. This allows for the easy identification of unauthorized access or provisioning errors, such as a user having a role in one application but not in another where it is required, or vice versa.
* Enhanced Audit and Compliance: By providing a single, consolidated view of all user entitlements, the feature significantly streamlines audit processes. It ensures that user access aligns with established policies and helps maintain a secure posture by highlighting potential security risks.

<figure><img src="/files/rGm9UDEqarHoMVWfr6yn" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/F6dKn9mEnNcSasco4HUa" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/BtA3BgSMqiLMG6wnN9Io" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/mWXkrcmw4hn7LYDFJK8a" alt=""><figcaption></figcaption></figure>


# Provisioning How to


# Cymmetri Connector List

Below is a list of Cymmetri connectors along with brief descriptions:

<table data-view="cards"><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>15Five</strong></td><td>Employee engagement and performance management platform.</td></tr><tr><td><strong>Active Directory</strong></td><td>Directory service for managing users and resources in a Windows network.</td></tr><tr><td><strong>Airbrake</strong></td><td>Error tracking and performance monitoring tool.</td></tr><tr><td><strong>Airtable</strong></td><td>Collaborative database and spreadsheet tool.</td></tr><tr><td><strong>Aiven</strong></td><td>Managed cloud database services provider.</td></tr><tr><td><strong>Akamai</strong></td><td>Content delivery network (CDN) and cloud service provider.</td></tr><tr><td><strong>AlertMediaCom</strong></td><td>Communication and alerting platform for emergency situations.</td></tr><tr><td><strong>AlertOps</strong></td><td>Incident management and alerting system.</td></tr><tr><td><strong>AlexisHR</strong></td><td>Human resources management system.</td></tr><tr><td><strong>Ally</strong></td><td>Goal-setting and performance management tool.</td></tr><tr><td><strong>AlphaSense</strong></td><td>Market intelligence and research platform.</td></tr><tr><td><strong>Alterdesk</strong></td><td>IT service management and helpdesk software.</td></tr><tr><td><strong>AlternativeInvestmentExchange</strong></td><td>Platform for alternative investments.</td></tr><tr><td><strong>Amadeus</strong></td><td>Travel technology solutions provider.</td></tr><tr><td><strong>Amazon AppStream</strong></td><td>Desktop application streaming service.</td></tr><tr><td><strong>Amazon AWS</strong></td><td>Cloud computing services platform by Amazon.</td></tr><tr><td><strong>Amazon AWS Redshift</strong></td><td>Data warehousing service on Amazon AWS.</td></tr><tr><td><strong>Amazon AWS SSO</strong></td><td>Single Sign-On service by Amazon AWS.</td></tr><tr><td><strong>Amazon Business</strong></td><td>E-commerce platform for businesses.</td></tr><tr><td><strong>AmazonManagedGrafanaSAML</strong></td><td>Managed Grafana service with SAML support.</td></tr><tr><td><strong>AmbientAI</strong></td><td>AI-powered workplace safety and compliance solutions.</td></tr><tr><td><strong>AMGTime</strong></td><td>Time and attendance management software.</td></tr><tr><td><strong>Anaplan</strong></td><td>Cloud-based planning and performance management platform.</td></tr><tr><td><strong>Anaqua</strong></td><td>Intellectual property management software.</td></tr><tr><td><strong>AndFrankly</strong></td><td>Employee engagement and feedback platform.</td></tr><tr><td><strong>Andromeda</strong></td><td>Security and risk management solutions.</td></tr><tr><td><strong>Anecdotes</strong></td><td>Employee recognition and rewards platform.</td></tr><tr><td><strong>AngelPoints</strong></td><td>Employee rewards and recognition platform.</td></tr><tr><td><strong>Animaker</strong></td><td>DIY video-making platform.</td></tr><tr><td><strong>Anodot</strong></td><td>Real-time analytics and anomaly detection platform.</td></tr><tr><td><strong>Anomalo</strong></td><td>Data quality and anomaly detection tool.</td></tr><tr><td><strong>AnswerHub</strong></td><td>Enterprise Q&#x26;A platform.</td></tr><tr><td><strong>Aon Hewitt</strong></td><td>Human resources and benefits consulting services.</td></tr><tr><td><strong>AperianGlobal</strong></td><td>Talent management and recruitment solutions.</td></tr><tr><td><strong>AppAegis</strong></td><td>IT security and compliance solutions.</td></tr><tr><td><strong>AppDynamicsEncrypted</strong></td><td>Application performance management with encryption support.</td></tr><tr><td><strong>AppDynamicsSSO</strong></td><td>Single Sign-On support for AppDynamics.</td></tr><tr><td><strong>Apperio</strong></td><td>Legal spend management and analytics platform.</td></tr><tr><td><strong>Appian</strong></td><td>Business process management and automation platform.</td></tr><tr><td><strong>AppianOnPrem</strong></td><td>On-premises deployment of Appian's platform.</td></tr><tr><td><strong>AppreciateHub</strong></td><td>Employee recognition and rewards platform.</td></tr><tr><td><strong>Apptio</strong></td><td>IT financial management and optimization software.</td></tr><tr><td><strong>Aprimo</strong></td><td>Marketing operations and digital asset management platform.</td></tr><tr><td><strong>AquaCloudSecurityPlatform</strong></td><td>Cloud security management platform.</td></tr><tr><td><strong>Arbitrip</strong></td><td>Travel and expense management solution.</td></tr><tr><td><strong>Arc GIS Online</strong></td><td>Online geographic information system (GIS) service.</td></tr><tr><td><strong>ArculessAML</strong></td><td>Anti-Money Laundering compliance platform.</td></tr><tr><td><strong>Area1Horizon</strong></td><td>Security solution for email and phishing protection.</td></tr><tr><td><strong>Area1Security</strong></td><td>Advanced threat protection and security platform.</td></tr><tr><td><strong>Ariba Network</strong></td><td>Procurement and supply chain management platform.</td></tr><tr><td><strong>AribaContractManagement</strong></td><td>Contract management solutions by Ariba.</td></tr><tr><td><strong>Articulate360</strong></td><td>eLearning authoring and content creation suite.</td></tr><tr><td><strong>Arxspan</strong></td><td>Laboratory information management system (LIMS).</td></tr><tr><td><strong>Asana</strong></td><td>Work management and collaboration tool.</td></tr><tr><td><strong>AskSpoke</strong></td><td>IT support and service management platform.</td></tr><tr><td><strong>AspenMesh</strong></td><td>Service mesh solution for microservices.</td></tr><tr><td><strong>Aspera</strong></td><td>High-speed file transfer solutions.</td></tr><tr><td><strong>AsperaV4</strong></td><td>Updated version of Aspera's file transfer solutions.</td></tr><tr><td><strong>AssemblaSAML</strong></td><td>Single Sign-On (SSO) integration for Assembla.</td></tr><tr><td><strong>Assembly</strong></td><td>Employee engagement and performance management platform.</td></tr><tr><td><strong>AssetBank</strong></td><td>Digital asset management system.</td></tr><tr><td><strong>AssetSonar</strong></td><td>IT asset management and inventory system.</td></tr><tr><td><strong>Atatus</strong></td><td>Application performance monitoring and error tracking.</td></tr><tr><td><strong>Atiim</strong></td><td>Performance management and employee feedback platform.</td></tr><tr><td><strong>Atipica</strong></td><td>Talent acquisition and recruitment solutions.</td></tr><tr><td><strong>Atlassian</strong></td><td>Collaboration and productivity tools, including Jira and Confluence.</td></tr><tr><td><strong>AtlassianCloud</strong></td><td>Cloud-based solutions by Atlassian.</td></tr><tr><td><strong>Attendease</strong></td><td>Event management and planning software.</td></tr><tr><td><strong>Aurion</strong></td><td>HR and payroll management system.</td></tr><tr><td><strong>Autodesk360</strong></td><td>Cloud-based design and engineering tools.</td></tr><tr><td><strong>Automox</strong></td><td>Endpoint management and patching solution.</td></tr><tr><td><strong>Auvik</strong></td><td>Network management and monitoring solution.</td></tr><tr><td><strong>AvidSecureInc</strong></td><td>Security and compliance management services.</td></tr><tr><td><strong>AvisoSAML</strong></td><td>SAML integration for Aviso.</td></tr><tr><td><strong>Avochato</strong></td><td>Communication and messaging platform for sales teams.</td></tr><tr><td><strong>Awardco</strong></td><td>Employee recognition and rewards platform.</td></tr><tr><td><strong>Axiom</strong></td><td>Data management and analytics platform.</td></tr><tr><td><strong>Axomo</strong></td><td>IT management and automation solutions.</td></tr><tr><td><strong>Axonius</strong></td><td>Security asset management and visibility platform.</td></tr><tr><td><strong>AxwayAmplify</strong></td><td>Integration and API management platform by Axway.</td></tr><tr><td><a href="/pages/VBkLHAYGTFtDn8ueLr1O"><strong>Azure</strong></a></td><td>Cloud computing services platform by Microsoft.</td></tr><tr><td><strong>BakerHillNextGen</strong></td><td>Loan origination and account management platform.</td></tr><tr><td><strong>BambooHR</strong></td><td>Human resources management and tracking software.</td></tr><tr><td><strong>BambuSproutSocial</strong></td><td>Social media management and marketing tools.</td></tr><tr><td><strong>BanyanCommandCenter</strong></td><td>Security and access management solution.</td></tr><tr><td><strong>BasicOps</strong></td><td>IT operations and incident management platform.</td></tr><tr><td><strong>Beam</strong></td><td>Employee engagement and performance management tool.</td></tr><tr><td><strong>BeautifulAI</strong></td><td>Presentation and slide design software.</td></tr><tr><td><strong>BenchlingEnterprise</strong></td><td>Life sciences research and data management platform.</td></tr><tr><td><strong>BenefexRewardHub</strong></td><td>Employee rewards and benefits management platform.</td></tr><tr><td><strong>BenefitFocus</strong></td><td>Benefits administration and management platform.</td></tr><tr><td><strong>BenefitsolverSAML</strong></td><td>SAML integration for Benefitsolver.</td></tr><tr><td><strong>Beneplace</strong></td><td>Employee benefits and discount programs.</td></tr><tr><td><strong>Benetrac</strong></td><td>Benefits administration and management software.</td></tr><tr><td><strong>Benevity</strong></td><td>Corporate social responsibility and employee giving platform.</td></tr><tr><td><strong>BenSelect</strong></td><td>Employee benefits selection and management tool.</td></tr><tr><td><strong>Betterworks</strong></td><td>Performance management and goal-setting platform.</td></tr><tr><td><strong>BeyondTrust</strong></td><td>Privileged access management and security solutions.</td></tr><tr><td><strong>BigCenter</strong></td><td>IT management and support platform.</td></tr><tr><td><strong>BigID</strong></td><td>Data privacy and protection platform.</td></tr><tr><td><strong>BigPanda</strong></td><td>IT operations and incident management platform.</td></tr><tr><td><strong>BigTinCan</strong></td><td>Sales enablement and content management solutions.</td></tr><tr><td><strong>Birdeye</strong></td><td>Customer experience and reputation management platform.</td></tr><tr><td><strong>Birst</strong></td><td>Business intelligence and analytics platform.</td></tr><tr><td><strong>BitGlass</strong></td><td>Cloud security and data protection platform.</td></tr><tr><td><strong>BitlySAML</strong></td><td>SAML integration for Bitly.</td></tr><tr><td><strong>BitSightTech</strong></td><td>Security ratings and risk management platform.</td></tr><tr><td><strong>Biztera</strong></td><td>IT management and service delivery platform.</td></tr><tr><td><strong>Blackboard</strong></td><td>Education technology and learning management system.</td></tr><tr><td><strong>Blink</strong></td><td>Employee communication and engagement platform.</td></tr><tr><td><strong>BlissBook</strong></td><td>Employee recognition and engagement tool.</td></tr><tr><td><strong>Blissfully</strong></td><td>SaaS management and vendor management platform.</td></tr><tr><td><strong>BlocksEdit</strong></td><td>Content management and editing tool.</td></tr><tr><td><strong>BlogIn</strong></td><td>Blog management and publishing platform.</td></tr><tr><td><strong>BlueBoard</strong></td><td>Employee recognition and rewards platform.</td></tr><tr><td><strong>BlueJeans</strong></td><td>Video conferencing and collaboration tool.</td></tr><tr><td><strong>BlueOceanBrain</strong></td><td>Employee learning and development platform.</td></tr><tr><td><strong>BMCAtriumSSO</strong></td><td>Single Sign-On integration for BMCAtrium.</td></tr><tr><td><strong>BoardBookit</strong></td><td>Board meeting and governance management tool.</td></tr><tr><td><strong>BoardEffect</strong></td><td>Board management and governance platform.</td></tr><tr><td><strong>Bob</strong></td><td>People management and HR platform.</td></tr><tr><td><strong>Bonsai</strong></td><td>Freelance management and invoicing software.</td></tr><tr><td><strong>BoomiSAML</strong></td><td>SAML integration for Boomi.</td></tr><tr><td><strong>Boostr</strong></td><td>Employee recognition and performance management tool.</td></tr><tr><td><strong>BoxNet</strong></td><td>Cloud storage and file sharing service.</td></tr><tr><td><strong>Brainshark</strong></td><td>Sales enablement and training platform.</td></tr><tr><td><strong>BrainstormQuickHelp</strong></td><td>Quick help and support tool for brainstorming.</td></tr><tr><td><strong>BranchSAML</strong></td><td>SAML integration for Branch.</td></tr><tr><td><strong>BrandfolderSAML</strong></td><td>SAML integration for Brandfolder.</td></tr><tr><td><strong>BrandWorkzCom</strong></td><td>Brand management and marketing platform.</td></tr><tr><td><strong>Braze</strong></td><td>Customer engagement and marketing automation platform.</td></tr><tr><td><strong>Breezy</strong></td><td>Recruitment and applicant tracking system.</td></tr><tr><td><strong>BreezyHR</strong></td><td>HR and recruitment software.</td></tr><tr><td><strong>BridgeCrew</strong></td><td>Cloud security and compliance platform.</td></tr><tr><td><strong>BrightEdge</strong></td><td>SEO and content performance platform.</td></tr><tr><td><strong>CentrifyPrivilegeAccessService</strong></td><td>Privileged access management and security solution.</td></tr><tr><td><strong>CenturyLink</strong></td><td>Telecommunications and cloud services provider.</td></tr><tr><td><strong>CequenceSecurity</strong></td><td>Security solutions for data and infrastructure.</td></tr><tr><td><strong>Cerby</strong></td><td>Security and compliance management platform.</td></tr><tr><td><strong>Ceresa</strong></td><td>Data protection and privacy management solution.</td></tr><tr><td><strong>Ceridian</strong></td><td>Human resources and payroll management software.</td></tr><tr><td><strong>Cerner</strong></td><td>Health information technology solutions provider.</td></tr><tr><td><strong>Certify</strong></td><td>Expense management and reporting tool.</td></tr><tr><td><strong>Cezanne</strong></td><td>HR software for small and medium-sized businesses.</td></tr><tr><td><strong>CGRFoundation</strong></td><td>Foundation for research and data management.</td></tr><tr><td><strong>ChangePoint</strong></td><td>Project and portfolio management software.</td></tr><tr><td><strong>Chargebee</strong></td><td>Subscription management and billing platform.</td></tr><tr><td><strong>ChartHop</strong></td><td>Org chart and employee directory tool.</td></tr><tr><td><strong>ChartioSAML</strong></td><td>SAML integration for Chartio.</td></tr><tr><td><strong>ChatterSAML</strong></td><td>SAML integration for Chatter.</td></tr><tr><td><strong>ChatWork</strong></td><td>Team communication and collaboration platform.</td></tr><tr><td><strong>CheckpointInfinityPortal</strong></td><td>Security management and threat detection solution.</td></tr><tr><td><strong>Cherwell</strong></td><td>IT service management and workflow automation platform.</td></tr><tr><td><strong>ChorusAI</strong></td><td>Conversation analytics and sales performance platform.</td></tr><tr><td><strong>ChromeRiver</strong></td><td>Travel and expense management software.</td></tr><tr><td><strong>CSV Directory</strong></td><td>Custom integration for CSV-based directories.</td></tr><tr><td><strong>Custom</strong></td><td>Custom integration solution for unique use cases.</td></tr><tr><td><strong>DarwinBox</strong></td><td>HR and talent management software.</td></tr><tr><td><strong>FreshDesk</strong></td><td>Customer support and ticketing system.</td></tr><tr><td><strong>Freshservice</strong></td><td>IT service management and helpdesk software.</td></tr><tr><td><strong>Freshworks</strong></td><td>Customer engagement and support platform.</td></tr><tr><td><strong>Google</strong></td><td>Google services integration, including Google Workspace.</td></tr><tr><td><strong>Google Workplace</strong></td><td>Productivity and collaboration suite by Google.</td></tr><tr><td><strong>hCaptcha</strong></td><td>CAPTCHA service for protecting websites from bots.</td></tr><tr><td><strong>Hive</strong></td><td>Collaboration and project management tool.</td></tr><tr><td><strong>Ingenium</strong></td><td>Enterprise content management system.</td></tr><tr><td><strong>Jedox</strong></td><td>Performance management and business analytics platform.</td></tr><tr><td><strong>Jenkins</strong></td><td>Continuous integration and delivery tool.</td></tr><tr><td><strong>Joomla</strong></td><td>Content management system for websites.</td></tr><tr><td><strong>LDAP</strong></td><td>Lightweight Directory Access Protocol for directory services.</td></tr><tr><td><strong>Liferay</strong></td><td>Enterprise portal and content management system.</td></tr><tr><td><strong>Lotus Notes</strong></td><td>Email and collaboration software.</td></tr><tr><td><strong>Lucid</strong></td><td>Visual collaboration and diagramming tool.</td></tr><tr><td><strong>Lucidchart</strong></td><td>Diagramming and flowchart creation software.</td></tr><tr><td><strong>ManageEngine AD Manager Plus</strong></td><td>Active Directory management and reporting tool.</td></tr><tr><td><strong>ManageEngine ServiceDesk Plus</strong></td><td>IT service management and helpdesk solution.</td></tr><tr><td><strong>NetSuite</strong></td><td>Cloud-based ERP and business management software.</td></tr><tr><td><strong>NextThink</strong></td><td>IT operations analytics and end-user experience management.</td></tr><tr><td><strong>oDesk</strong></td><td>Freelance job platform (now Upwork).</td></tr><tr><td><strong>Office365</strong></td><td>Productivity suite by Microsoft.</td></tr><tr><td><strong>OracleFusion</strong></td><td>Oracle's suite of cloud-based enterprise applications.</td></tr><tr><td><strong>OracleHCM</strong></td><td>Human Capital Management solutions by Oracle.</td></tr><tr><td><strong>PagerDuty</strong></td><td>Incident management and response platform.</td></tr><tr><td><strong>Paladin</strong></td><td>Legal and compliance management software.</td></tr><tr><td><strong>PaloAltoNetworksSAML</strong></td><td>SAML integration for Palo Alto Networks.</td></tr><tr><td><strong>PAM</strong></td><td>Privileged Access Management solutions.</td></tr><tr><td><strong>Pivotal</strong></td><td>Application development and deployment platform.</td></tr><tr><td><strong>Piwik</strong></td><td>Open-source web analytics platform (now Matomo).</td></tr><tr><td><strong>PowerShell</strong></td><td>Task automation and configuration management framework.</td></tr><tr><td><strong>Prezi</strong></td><td>Presentation software with interactive and dynamic features.</td></tr><tr><td><strong>ReadCube</strong></td><td>Research management and document discovery tool.</td></tr><tr><td><strong>SailPointIIQ</strong></td><td>Identity governance and administration platform.</td></tr><tr><td><strong>Salesforce</strong></td><td>Customer relationship management (CRM) platform.</td></tr><tr><td><strong>Samanage</strong></td><td>IT service management and asset management software.</td></tr><tr><td><strong>SAPNetWeaverSAML</strong></td><td>SAML integration for SAP NetWeaver.</td></tr><tr><td><strong>ScienceLogic</strong></td><td>IT operations and management platform.</td></tr><tr><td><strong>SCIM v1.1</strong></td><td>System for Cross-domain Identity Management version 1.1.</td></tr><tr><td><strong>SCIM v2.0 (Basic)</strong></td><td>Basic implementation of SCIM v2.0 for user management.</td></tr><tr><td><strong>SCIM v2.0 (Bearer)</strong></td><td>SCIM v2.0 with Bearer token authentication.</td></tr><tr><td><strong>SCIM v2.0 (Fixed Bearer)</strong></td><td>SCIM v2.0 with Fixed Bearer token authentication.</td></tr><tr><td><strong>SCIM v2.0 (Github)</strong></td><td>SCIM v2.0 implementation for GitHub.</td></tr><tr><td><strong>SCIM v2.0 (Salesforce)</strong></td><td>SCIM v2.0 implementation for Salesforce.</td></tr><tr><td><strong>Script Connector</strong></td><td>Custom integration using scripting for unique requirements.</td></tr><tr><td><strong>ServiceNow</strong></td><td>IT service management and enterprise workflow solutions.</td></tr><tr><td><strong>Shutterstock</strong></td><td>Stock photo and image licensing platform.</td></tr><tr><td><strong>Sisense</strong></td><td>Business intelligence and analytics platform.</td></tr><tr><td><strong>Slack</strong></td><td>Team communication and collaboration tool.</td></tr><tr><td><strong>Smartsheet</strong></td><td>Work management and automation platform.</td></tr><tr><td><strong>SNOW Commander</strong></td><td>Snowflake data management and automation tool.</td></tr><tr><td><strong>Snowflake</strong></td><td>Cloud-based data warehousing platform.</td></tr><tr><td><strong>Splunk</strong></td><td>Data analysis and monitoring platform.</td></tr><tr><td><strong>SplunkCloud</strong></td><td>Cloud-based data analysis and monitoring by Splunk.</td></tr><tr><td><strong>SuccessFactors</strong></td><td>Human resources management and talent management solutions.</td></tr><tr><td><strong>SugarCRM</strong></td><td>Customer relationship management (CRM) software.</td></tr><tr><td><strong>Tableau</strong></td><td>Data visualization and business intelligence platform.</td></tr><tr><td><strong>TeamViewer</strong></td><td>Remote access and support software.</td></tr><tr><td><strong>Vimeo</strong></td><td>Video hosting and sharing platform.</td></tr><tr><td><strong>Zendesk</strong></td><td>Customer service and support ticketing system.</td></tr><tr><td><strong>Zenduty</strong></td><td>Incident management and response platform.</td></tr><tr><td><strong>ZingHR</strong></td><td>Human resources management and payroll solutions.</td></tr></tbody></table>


# Supported Provisioning Operations

Cymmetri provides a robust suite of provisioning operations that enable seamless identity and access management across various applications. Below is a detailed overview of the provisioning operations supported by Cymmetri.

**1. Test Operation**

* **Purpose**: The Test Operation is used to validate the connectivity and configuration settings between Cymmetri and the target application or directory service. This operation ensures that all necessary parameters, such as API endpoints, credentials, and schema mappings, are correctly configured.
* **Usage Scenario**: Before initiating any provisioning tasks, administrators can use the Test Operation to verify that the integration between Cymmetri and the target system is functioning as expected.

**2. Sync Operation**

* **Purpose**: The Sync Operation synchronizes user and group data between Cymmetri and the connected applications. This operation ensures that the identity information in Cymmetri is in sync with the data in external systems.
* **Usage Scenario**: The Sync Operation is typically scheduled to run at regular intervals or triggered manually to ensure that changes in the external system (e.g., new users, updated roles) are reflected in Cymmetri.

**3. Search Operation**

* **Purpose**: The Search Operation allows administrators to query the target application or directory for specific users or groups. This operation is essential for identifying and managing specific identities in the external system.
* **Usage Scenario**: Administrators can use the Search Operation to find users based on attributes such as username, email, or group membership, facilitating targeted management tasks like updates or deletions.

**4. Create Operation**

* **Purpose**: The Create Operation is used to provision new user accounts or groups in the target application or directory based on the identity data maintained in Cymmetri.
* **Usage Scenario**: When a new employee joins an organization, the Create Operation can be triggered to automatically provision their account in various applications, ensuring immediate access to necessary resources.

**5. Update Operation**

* **Purpose**: The Update Operation allows administrators to modify existing user or group attributes in the target system. This operation is crucial for maintaining accurate and up-to-date identity information across systems.
* **Usage Scenario**: If an employee's role changes, the Update Operation can be used to modify their access privileges or update their profile information in connected applications.

**6. Delete Operation**

* **Purpose**: The Delete Operation is used to de-provision user accounts or groups from the target application or directory. This operation is essential for removing access when users leave the organization or no longer require certain resources.
* **Usage Scenario**: Upon the termination of an employee, the Delete Operation can be triggered to remove their accounts from all connected applications, ensuring security and compliance.

**7. Role Assign Operation**

* **Purpose**: The Role Assign Operation assigns specific roles to users in the target system, granting them access to particular resources or permissions.
* **Usage Scenario**: When an employee is promoted to a managerial position, the Role Assign Operation can be used to grant them additional access rights aligned with their new responsibilities.

**8. Role Unassign Operation**

* **Purpose**: The Role Unassign Operation removes previously assigned roles from users, revoking their access to certain resources or permissions.
* **Usage Scenario**: If an employee is reassigned to a different department, the Role Unassign Operation can be utilized to revoke roles that are no longer relevant to their new position.


# Azure Provisioning

Azure provisioning in Cymmetri involves setting up configurations to automate the creation and management of user accounts in Microsoft Entra ID. This allows for seamless user onboarding and offboarding processes.

To implement Azure provisioning in Cymmetri, follow these general steps:

The administrator needs to login to Azure Portal: <https://portal.azure.com&#x20>;

<figure><img src="/files/PfQs4deT72wX9L7y2nNf" alt=""><figcaption></figcaption></figure>

Once logged in click on **More services->** button

<figure><img src="/files/zKAlW1YBsYXKYOwmoUBS" alt=""><figcaption></figcaption></figure>

In the next screen click on **Identity** -> **App registrations** inside the **Identity management** section

<figure><img src="/files/H2fmZ1BvKcQMgMjqAunm" alt=""><figcaption></figcaption></figure>

Next click on **New registration** to register a new App. Registering your application establishes a trust relationship between your app and the Microsoft identity platform. The trust is unidirectional: your app trusts the Microsoft identity platform, and not the other way around. Once created, the application object cannot be moved between different tenants.

<figure><img src="/files/O7pqTXVGBwl13gbyZHB5" alt=""><figcaption></figcaption></figure>

Next enter the **Application Name** and select the Supported account types to organizational directory only : **Accounts in this organizational directory only (Cymmetri Organization only - Single tenant)** and then click on **Register**

<figure><img src="/files/FYji0TsEEWwSnqFsLQOY" alt=""><figcaption></figcaption></figure>

Once registered next click on **Authentication** menu and **+Add a platform**.

<figure><img src="/files/F3Vt47iEA4oZHOUlWRcv" alt=""><figcaption></figcaption></figure>

On the next screen select **Mobile and desktop applications**

<figure><img src="/files/JGEV2eCOWSIHRgrCOz01" alt=""><figcaption></figcaption></figure>

&#x20;Enter a **Custom redirect URIs:**  *<http://localhost>* and click on Configure

<figure><img src="/files/FeeLHJpllcjxrm1J9jMM" alt=""><figcaption></figcaption></figure>

Further enable the **Public Client flows** and click on **Save** button

<figure><img src="/files/5OkF36FcqLVxCiQrVZLN" alt=""><figcaption></figcaption></figure>

Next go to **Certificates and secrets** menu and create a new client secret:

<figure><img src="/files/W8N7IYsqrLzaSOmOr3VW" alt=""><figcaption></figcaption></figure>

Next enter a **Description** for the and select the duration after which the secret would **Expire** -Recommended is 180 days (6 months) but can be changed as per the need. Once both the details are entered click on **Add** button

<figure><img src="/files/rq8M359bFMwZOO4RdmTL" alt=""><figcaption></figcaption></figure>

Next copy and save the Client Secret ID and Client Secret Value in a safe and accessible place. Client secret values cannot be viewed, except for immediately after creation. Be sure to save the secret when created before leaving the page.

<figure><img src="/files/milhv1bZ4DEpbbzB0H5k" alt=""><figcaption></figcaption></figure>

Once the client secret details are stored next click on **API permissions** menu and then + **Add a permission**

<figure><img src="/files/etFAClFex7e5XQ0nO4JI" alt=""><figcaption></figcaption></figure>

On this page select **Microsoft Graph**

<figure><img src="/files/YgfcAq5ld2meSS1UiWBt" alt=""><figcaption></figcaption></figure>

On the next page we require permissions for both **Delegated and Application permissions.** Select each type of permission and in that Search and select the following permissions/scopes:

1. APIConnectors.Read.All
2. Directory.ReadWrite.All
3. OpenID (Not available for Application Permissions)
4. PrivilegedAccess.Read.AzureAD
5. User.ReadWrite.All
6. Directory.Read.All

<figure><img src="/files/8KvRYJ1Cgs36neB4ZhIx" alt=""><figcaption></figcaption></figure>

Once all the permissions are added a warning is shown: <mark style="color:red;">"You are editing permission(s) to your application, users will have to consent even if they’ve already done so previously."</mark> The administrator needs to click on the "Grant admin consent for Cymmetri Organization" link

<figure><img src="/files/MhrWiIZIqUUuuA2tH85L" alt=""><figcaption></figcaption></figure>

On the click of the link a popup appears to grant admin consent, click on **Yes**

<figure><img src="/files/RQ0gmV1MpGwMah9R1qAV" alt=""><figcaption></figcaption></figure>

Next click on **Expose an API** and then click on **Add** to add an **Application ID URI**: The Application ID URI, also called identifier URI, is a globally unique URI used to identify the web API. This URI is the prefix for scopes in the Oauth protocol. You can either use the default value in the form of api://, or specify a more readable URI.

<figure><img src="/files/repZsKIyD2TcXa8UdrOf" alt=""><figcaption></figcaption></figure>

On the next page keep the default values intact and click on **Save** button

<figure><img src="/files/08wcVAOcg82bqZ5CTr6u" alt=""><figcaption></figcaption></figure>

Finally you can see the **Overview** page that contains all the information you need to configure Azure in Cymmetri.

<figure><img src="/files/AS9x9CjaqexkPVcQc9ub" alt=""><figcaption></figcaption></figure>

Also the User config Application Authority can be obtained from the endpoint section in the Overview page:

<figure><img src="/files/FZt3wOSMJWHoSvHuq5YH" alt=""><figcaption></figcaption></figure>

This completes the Azure side of the configuration, next the administrator needs to need to move to Cymmetri and configure the Azure application. Mentioned below are the steps required to configure Azure in Cymmetri:

Add a new Azure application **Identity Hub->Applications** and then click on the **+Add New** button

<figure><img src="/files/e9nPcrz5ldsFFsIFkYgq" alt=""><figcaption></figcaption></figure>

Once added the administrator needs to go to Policy Attribute section and ensure all the below mentioned attributes are present (Add if not already present):

* mailNickname
* displayName
* \_\_PASSWORD\_\_
* \_\_NAME\_\_
* userPrincipalName
* givenName
* surname
* mail
* usageLocation

<figure><img src="/files/47YxjnLx1ZaSld8Srwhp" alt=""><figcaption></figcaption></figure>

Next the administrator needs to go to the Policy Map section and ensure a mapping shown as below is created:

<table><thead><tr><th width="202">Application Field</th><th width="143">Field</th><th width="134">User Principal</th><th width="124">Create Only</th><th>Update Only</th></tr></thead><tbody><tr><td>displayName</td><td>displayName</td><td>-</td><td>True</td><td>True</td></tr><tr><td>__NAME__</td><td>login</td><td>-</td><td>True</td><td>True</td></tr><tr><td>__PASSWORD__</td><td>password</td><td>-</td><td>True</td><td>True</td></tr><tr><td>mailNickname</td><td>mailNickName</td><td>-</td><td>True</td><td>True</td></tr><tr><td>userPrincipalName</td><td>login</td><td>True</td><td>True</td><td>True</td></tr><tr><td>givenName</td><td>firstName</td><td>-</td><td>True</td><td>True</td></tr><tr><td>surname</td><td>lastName</td><td>-</td><td>True</td><td>True</td></tr><tr><td>mail</td><td>email</td><td>-</td><td>True</td><td>True</td></tr><tr><td>usageLocation</td><td>country</td><td></td><td>True</td><td>True</td></tr><tr><td>azureLicense</td><td>azureLicense</td><td>&#x3C;actual license key></td><td>True</td><td>True</td></tr></tbody></table>

Once the policy map is created next the administrator needs to go to  Provisioning section and then to **Server Configuration** and need to configure the connector server as shown below:

<figure><img src="/files/RGCSjYbN6gaXzalGX1NJ" alt=""><figcaption></figcaption></figure>

Once the Server Configuration is done next the administrator needs to implement User Configuration with the below mentioned fields:

* User config Application Authority: This is the authority under which the application operates. For example, if you're using Azure AD, the application authority might be `https://login.microsoftonline.com/<tenant_id>/oauth2/authorize`
* User config application client id: This is the unique identifier for your application. It is provided by Azure when you register your application. For example, `e9a5a8b6-8af7-4719-9821-0deef255f68e`.
* Client Secret: This is a secret key used by the application to prove its identity when requesting access tokens. It should be kept confidential. For example, `7f7df45a-251e-49d3-a396-748bf8e05a3c`.
* User config domain: This is the domain associated with your Azure AD. For example, `contoso.onmicrosoft.com`.
* User config base password: This is the base password used for your application. For example, `MyBasePassword123`.
* Redirect URI: This is the URI to which Azure AD will redirect the user after authentication. For example, api://05b765c3-d64f-7704-b0d8-5c4c6bc674df
* User config resource URI: This is the URI of the resource (API, web app, etc.) that the application wants to access. For example, `https://graph.microsoft.com`.
* Azure Tenant ID: This is the identifier for your Azure AD tenant. For example, `72f988bf-86f1-41af-91ab-2d7cd011db47`.
* User config base username: This is the base username used for your application. For example, `MyUsername@contoso.onmicrosoft.com`.

<figure><img src="/files/cj0LHhtEWMWCgC6N3oiA" alt=""><figcaption></figcaption></figure>

Once the configuration is done and saved, Next click on **TEST CONFIGURATION** to test if Cymmetri is able to connect to Azure Server.

### Assign various Product Licenses to user

For assigning any sort of licenses to a user of various products two main policy map entries need to done as shown below:

* azureLicense: Need to provide license key for the product you wish to assign to the user
* usageLocation: This field needs a two-letter country code (ISO standard 3166). Required for users that are assigned licenses due to legal requirements to check for availability of services in countries. Examples include: `US`, `JP`, and `IN`.

<figure><img src="/files/OoC4SzRU94xQSSV6Ebdy" alt=""><figcaption></figcaption></figure>

The value for azureLicense can be obtained as explained below:

Go to <https://admin.microsoft.com/> and login using the admin credentials. Once logged in go to **Billing->Licenses->Microsoft Teams Exploratory**

<figure><img src="/files/ayVhFqK0jXYYQLHZhecp" alt=""><figcaption></figcaption></figure>

Once you click that it opens the page from which we can copy the product id from URL as shown below:

<figure><img src="/files/ZyO7QEnVdoP1f2qOfSKB" alt=""><figcaption></figcaption></figure>

Once all the above configuration is done, on the same page in Cymmetri go to **Assignments section** and assign users to the application and ensure that these users are created in Azure's Microsoft Entra ID along with the Microsoft Teams license.


# Active Directory (AD) Provisioning

This document provides a formal, step-by-step guide to configuring an AD integration with the Cymmetri platform. This integration allows Cymmetri to act as a central identity store, managing users and their attributes within the AD environment.

Before beginning the configuration, ensure you have the following:

* Domain Administrator Credentials: A username and password for a AD account with full administrative privileges.
* Domain & Controller Details: The Domain Name and the IP address or hostname of the AD domain controller.
* SSL/TLS Certificates: For secure communication via port 636, the Certificate Authority (CA) certificate must be exported from the AD server and imported into the Cymmetri connector server. This ensures the communication channel is trusted and encrypted. Refer the link below for more details: [ https://www.manageengine.com/products/active-directory-audit/kb/how-to/how-to-install-ssl-certificates-in-active-directory.html](< https://www.manageengine.com/products/active-directory-audit/kb/how-to/how-to-install-ssl-certificates-in-active-directory.html>)
* Network Access: Ensure that necessary ports (especially 636 for secure LDAPS communication) are open and accessible between the Cymmetri connector server and the AD domain controller.

#### Configuration Steps

**Step 1:** Configure your Active Directory Certificate and export it to Connector Server

Exporting your Active Directory certificate to the Connector Server is a necessary and crucial step. This ensures that the Active Directory and Cymmetri Identity Server can communicate over LDAPS (LDAP over SSL). For this to happen, LDAPS requires a properly formatted certificate installed in your Active Directory Domain Controllers. Please refer to this link and follow the same steps: <https://www.manageengine.com/products/active-directory-audit/kb/how-to/how-to-install-ssl-certificates-in-active-directory.html>

Once the certificate has been imported per the above instructions, you must restart the application to apply the changes made.

**Step 2: Create the AD Application in Cymmetri**

1. Navigate to the Identity Hub and select Application.

<figure><img src="/files/tUlQ16VYxKU6snq0jUi2" alt=""><figcaption></figcaption></figure>

2. Click Create Application.
3. Search for "Active Directory" and select the appropriate application type.
4. Name the application "Simple AD" to easily identify it within Cymmetri.

<figure><img src="/files/my0VPqzMEZqZm6uIsnOV" alt=""><figcaption></figcaption></figure>

**Step 3: Create a Policy Map**

The policy map defines the attribute mapping between Cymmetri and AD. This is crucial for synchronizing user data correctly.

1. Go to the Policy Attribute section.
2. Review the pre-filled, standard attribute mappings (e.g., sAMAccountName to login, givenName to firstName, mail to email).

<figure><img src="/files/mkkvCAGxrcfs9RHYKIXX" alt=""><figcaption></figcaption></figure>

3. Add any new or custom attributes by clicking Add new, entering the attribute name and description, and saving.

<figure><img src="/files/ehHqE0hbmNlWRjXgcpqY" alt=""><figcaption></figcaption></figure>

**Step 4: Configure User & Server Settings**

This two-part step establishes the connection parameters and user search criteria.

User Configuration:

* Principal & Principal Password: Enter the credentials of the domain administrator account. This account is used by Cymmetri to connect to AD.

<figure><img src="/files/89lDWcJEXbtsmGlTXckl" alt=""><figcaption><p>principal</p></figcaption></figure>

<figure><img src="/files/PSkJOJw3I4WeN9nismmj" alt=""><figcaption><p>(principal password)</p></figcaption></figure>

* Server Hostname: The IP address or hostname of the AD domain controller.

<figure><img src="/files/0IGj3cSr9i42LBS58Uh9" alt=""><figcaption></figcaption></figure>

* User Entry Searches & Base Contexts: Define the LDAP search queries and organizational units (OUs) that Cymmetri will use to find users and groups within AD.

<figure><img src="/files/boLvSOCSLDmpTgkKrdP7" alt=""><figcaption><p>user search entries</p></figcaption></figure>

<figure><img src="/files/ANWAP1laZsDZd4BjnGJZ" alt=""><figcaption><p>Base Contexts</p></figcaption></figure>

Click Save Configuration and then Test Configuration to verify a successful connection.

<figure><img src="/files/ijT0ghNrnqpjyvRLyTib" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/IGfvtHRCfj2Ij4YJbGtE" alt=""><figcaption></figcaption></figure>

Server Configuration:

* Server Hostname: The hostname of the Cymmetri connector server.

<figure><img src="/files/lBB7yObhP656AX8y633C" alt=""><figcaption></figcaption></figure>

* Server Password: The password for the connector server.

<figure><img src="/files/HhVxWmxbRx94c9EeFZGQ" alt=""><figcaption></figcaption></figure>

* Server Port: The port number for communication (e.g., 636 for secure LDAPS).

<figure><img src="/files/Vl9YwIQZ6mTwU8RL6BWr" alt=""><figcaption></figcaption></figure>

* Connector Bundle Name & Version: The name and version of the Cymmetri connector bundle, which facilitates communication with AD.

<figure><img src="/files/7RMLFow9K2Agg2QPoe16" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/dyON6nZ1isOEX854Sc8T" alt=""><figcaption></figcaption></figure>

* Click Save Configuration, then Test Configuration.

<figure><img src="/files/I3i56REEqU8tFpfI2B1r" alt=""><figcaption></figcaption></figure>

**Step 5: Perform a Reconciliation (Push)**

A Push Reconciliation is the process of synchronizing user data from Cymmetri to the AD target system.

1. Navigate to Reconciliation.
2. Select the Push option.
3. Click Add New to create a new push reconciliation job.

<figure><img src="/files/jyrecIIPdcYmvu83BGal" alt=""><figcaption></figcaption></figure>

4. Configure the job settings and execute it.

<figure><img src="/files/rgKcLge3y7nyhaTZI3nT" alt=""><figcaption></figcaption></figure>

5. Monitor the job status by navigating to Recon History.

<figure><img src="/files/9EaNaFlypEmJ0PWKISuR" alt=""><figcaption></figcaption></figure>

**Step 6: Verify Reconciliation in AD**

To confirm that the push reconciliation was successful, verify the user data directly within the AD target system.

1. Use Remote Desktop Protocol (RDP) to connect to the AD server.

<figure><img src="/files/Rg8amdJVQmwQWDKE3OJg" alt=""><figcaption></figcaption></figure>

2. Enter the computer credentials (IP address and password) to connect.

<figure><img src="/files/do77N5QunjdBSJdKzN7A" alt=""><figcaption></figcaption></figure>

3. Once logged in, open the Active Directory management console.

<figure><img src="/files/X0DRuTStLL2Y2ZwQo3JH" alt=""><figcaption></figcaption></figure>

4. Right-click on the domain and use the Find function to search for the user who was pushed from Cymmetri. If the user appears with the correct attributes, the reconciliation was successful.

<figure><img src="/files/oLiSky2my8SijWikEXZP" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/Rkgz7FjYi0JyYNpogFj6" alt=""><figcaption></figcaption></figure>


# LDAP Provisioning

LDAP, or Lightweight Directory Access Protocol, is a protocol for accessing and managing directory services over a network. It provides a centralized, hierarchical way to store and authenticate identity-related information like user accounts, groups, and organizational data. This document outlines the formal steps to configure a Simple LDAP application in Cymmetri used for LDAP Provisioning.

#### Prerequisites

Before beginning the configuration, ensure you have the following:

* **LDAP server login credentials**: Specifically, the Bind DN and password.
* **LDAP server access**: To configure and test connections.
* **SSL/TLS certificates**: Required for secure connections using LDAPS (LDAP over SSL). The LDAPS port (typically 636) must be enabled, and the CA certificate must be exported from the LDAP server and imported into the connector server.

### LDAP Essentials

Key information needed for the configuration includes:

* **Server Hostname and Port**: The address of the LDAP server and the port for communication (e.g., 636 for LDAPS).
* **Base DN (Distinguished Name)**: The starting point for all searches within the directory hierarchy (e.g., dc=example,dc=com).
* **OU (Organizational Unit) name**: The name of the specific organizational unit you are targeting.

### Step-by-Step Configuration

#### Step 1: Create a Simple LDAP Application

1. Navigate to Identity Hub → Application.

<figure><img src="/files/p5sCJYfod11LChWBd43U" alt=""><figcaption></figcaption></figure>

2. Click Create Application and search for "Simple LDAP."

<figure><img src="/files/tcpdiikbm2ticNdi8ADy" alt=""><figcaption></figcaption></figure>

#### Step 2: Create Policy Map

The policy map defines which attributes are fetched from your LDAP directory.

1. Go to the Policy Attribute section. The table is pre-filled with common LDAP attributes, but you can add  new ones.
   * cn (Common Name): The full name of the user.
   * uid (User ID): A unique user identifier.
   * sn (Surname): The user’s last name.

<figure><img src="/files/V0QrLnlirKEvvUiXvge3" alt=""><figcaption></figcaption></figure>

2. **Standard Attribute Mapping**:

The following mappings are typically used for provisioning:

* telephoneNumber → mobile
* cn → login
* givenName → firstName
* mail → email
* sn → lastName
* cn → firstName

3. Adding New Attributes:

* Click '**Add new**'.
* Enter the attribute name and description, then click Save.

<figure><img src="/files/7y53a3H997bQbJHHEZgJ" alt=""><figcaption></figcaption></figure>

* Toggle the Active switch to enable the new attribute.

<figure><img src="/files/WKSzXOVUJGECESAXzgq5" alt=""><figcaption></figcaption></figure>

#### Step 3: Map Your LDAP to Cymmetri

1. In the same window, go to the Policy Map option.
2. Map each LDAP attribute to its corresponding Cymmetri user attribute. By default, the mapping is set to false and needs to be manually configured.

<figure><img src="/files/pJ7r7Z0UIdKrGkgv1WUJ" alt=""><figcaption></figcaption></figure>

#### Step 4: Configure User Configuration

This section defines how Cymmetri searches for and interacts with user entries in LDAP.

1. Navigate to User Configuration.
2. Enter the Root Suffixes.

<figure><img src="/files/LFBBQu2u02FT1n77QjYO" alt=""><figcaption></figcaption></figure>

3. Provide the Principal Password.

<figure><img src="/files/pYUW82AbqjrfqQjNRfoy" alt=""><figcaption></figcaption></figure>

4. Enter the Base Contexts for group entry searches.

<figure><img src="/files/0NahM34w9CDGEhC4aPPz" alt=""><figcaption></figcaption></figure>

5. Enter the Server HostName.

<figure><img src="/files/KFBYlStQPBD0WFy4WxM5" alt=""><figcaption></figcaption></figure>

6. Enter the Principal (the Bind DN)

<figure><img src="/files/1ZwSBMALLNRHX0IeFhMC" alt=""><figcaption></figcaption></figure>

7. Enter the User Entry Searches.

<figure><img src="/files/38tgNp7vUv9H7rz94ooP" alt=""><figcaption></figcaption></figure>

8. Click Save Configuration and then Test Configuration to verify a successful connection.

<figure><img src="/files/8EEC3f59JKCaa2hPWrqR" alt=""><figcaption></figcaption></figure>

#### Step 5: Configure Server Configuration

This section defines the connection parameters for the connector server.

1. Enter the Server Hostname.

<figure><img src="/files/rT9haBhGe3fICv1qywLR" alt=""><figcaption></figcaption></figure>

2. Enter the Server Password.

<figure><img src="/files/cnL2jtBW360eMAriORni" alt=""><figcaption></figcaption></figure>

3. Enter the Server Port.

<figure><img src="/files/UWdNL6XGeQ3aRCclZa8S" alt=""><figcaption></figcaption></figure>

4. Enter the Server Connector Bundle Name.

<figure><img src="/files/BfZ4Wq5YIaNS6SLa3gjc" alt=""><figcaption></figcaption></figure>

5. Enter the Server Connector Bundle Version.

<figure><img src="/files/VnPaN8F2S7s7FQR84jYv" alt=""><figcaption></figcaption></figure>

6. Enter the Server Connector name.

<figure><img src="/files/RAuJXHwPbLXSFgpBgzF6" alt=""><figcaption></figcaption></figure>

7. Click Save Configuration and then Test Configuration.

<figure><img src="/files/qL3Adxp54QZ4n80CDaoy" alt=""><figcaption></figcaption></figure>

**Step 6: Execute Push Reconciliation on LDAP**

1. Click on Reconciliation, select push, and click on add new

<figure><img src="/files/6Lw17qMHwvIumQd3WSlT" alt=""><figcaption></figcaption></figure>

2. Configure Push Recon Configuration

<figure><img src="/files/uN5J9wH2yKN2f9qE4BJK" alt=""><figcaption></figcaption></figure>

3. Click On Run Recon and View in History

<figure><img src="/files/QMqU32zYMt6Q2LfPKvx1" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/eUC09KTFjyIEVWDjKuzk" alt=""><figcaption></figcaption></figure>

4. Click on the View Icon to see the Progress and the result of reconciliation

<figure><img src="/files/emr5TAt7BtbDjJUMbcqJ" alt=""><figcaption></figcaption></figure>

5. View in Reconciliation History

<figure><img src="/files/enqNv0k2P0vkveSDF9dx" alt=""><figcaption></figcaption></figure>

**Step 7: View Reconciliation Push User in the LDAP Target System**

1. Go to <http://10.0.6.17/phpldapadmin> and enter the required credentials.

<figure><img src="/files/Ytkli3y7g5UgGg0acAzE" alt=""><figcaption></figcaption></figure>

2. &#x20;Select the required server

<figure><img src="/files/NZthdpc8KyXOZGCSaP8z" alt=""><figcaption></figcaption></figure>

3. Click on search and verify in the search filter by entering its value

<figure><img src="/files/XjnoOtJxq7uVcqBWzttp" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/FnM6QWaAcNiUXMJEo4jA" alt=""><figcaption></figcaption></figure>


# Google Workspace Provisioning

Google Workspace is a software-as-a-service platform (SAAS) that provides email, calendar, documents and other services. This connector uses the Google Workspace provisioning APIs to create, add, delete and modify user accounts and email aliases.

**Note:** \
*1. Only the Premium (paid) or Educational versions of Google* Workspace *provide access to the provisioning APIs.*\
*2. Connector will not work on the free Google* Workspace *Domain*

### Configuration

For Configuring Google Workspace for provisioning we need to first obtain the client\_secret.json file from the Google Workspace instance.

### Create New Project

Go To <https://console.developers.google.com/> and create a new Project if not already created.  A new project needs to be created because it allows you to manage the credentials required to access Google APIs and services securely. A new project can be created by clicking on the New Project on top right or by clicking on the the Resource Dropdown&#x20;

<figure><img src="/files/cNnrJG8uVOQlNvysC5WK" alt=""><figcaption></figcaption></figure>

And the on the **NEW PROJECT** link on top right

<figure><img src="/files/EfPW6ZE4QaJ4L2pWId9l" alt=""><figcaption></figcaption></figure>

Next enter the **Project name** and select **Organisation** and **Location** as shown below and click on **CREATE** button

<figure><img src="/files/9aQ6zoc7mbyhEKwhwM0P" alt=""><figcaption></figcaption></figure>

### ADMIN SDK API:

The Admin SDK API is needed to programmatically manage and interact with various aspects of a Google Workspace domain, such as users, groups, organizational units, and settings. Here are some key reasons why the Admin SDK API is essential:

1. **User Management**: The Admin SDK API allows you to create, retrieve, update, and delete user accounts in your Google Workspace domain. You can manage user details such as name, email address, password, and organizational unit.
2. **Group Management**: You can create, retrieve, update, and delete groups within your Google Workspace domain using the Admin SDK API. This includes managing group members and settings.
3. **Organizational Unit Management**: The API enables you to manage organizational units (OUs) within your Google Workspace domain. You can create, retrieve, update, and delete OUs, as well as move users and groups between OUs.
4. **User Reports**: The Admin SDK API provides access to various reports about user activity, such as login activity, email sending/receiving activity, and more. These reports can help you monitor and analyze user behavior within your domain.
5. **Settings Management**: You can manage various domain-wide settings, such as email routing, calendar sharing settings, and device management settings, using the Admin SDK API.
6. **Security and Compliance**: The API provides features for managing security and compliance settings within your Google Workspace domain, such as 2-step verification, password policies, and audit logs.

To enable ADMIN SDK API click on **Enabled API & Services** and Search for Admin SDK API:

<figure><img src="/files/gnmi3VUw87YPUpc3FXpG" alt=""><figcaption></figcaption></figure>

Click on Admin SDK API and then click on the Enable button&#x20;

Once enabled, Click on CREDENTIALS tab

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003459370/original/wbli7LiQzXCyB02l8FOeM3s092yDTdQAnQ.png?1649373796" alt=""><figcaption></figcaption></figure>

Now click on **Credentials** section and click on **CREATE CREDENTIALS** button and in that select OAuth client ID option

<figure><img src="/files/5rr6GQfVoY83q4E7Ef2U" alt=""><figcaption></figcaption></figure>

Select **Desktop app** as Application type, provide a name for the OAuth 2.0 client and then click on the **CREATE** button

<figure><img src="/files/Vxa6zaGl2Ol2dAeh2Vk4" alt=""><figcaption></figcaption></figure>

A response screen is visible that shows that the "OAuth client created" It also displays Your Client ID and Your Client Secret. You may download the JSON here using the DOWNLOAD JSON option.

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003459380/original/amdvor65yucMv85Eer8snqHz4uNb457Mkg.png?1649373853" alt=""><figcaption></figcaption></figure>

Click on OAuth consent screen and then Click on **EDIT APP.** Enter the required details and Click on **SAVE AND CONTINUE** button

<figure><img src="/files/TjE7YEdJCI1RWlTPtncb" alt=""><figcaption></figcaption></figure>

Select Internal as User Type if you want to restrict access only to the users of your organization.

<figure><img src="/files/lZbZSQqVhim3SIaui83x" alt=""><figcaption></figcaption></figure>

Search for Admin SDK API  on the Scopes screen and select scope for user: `.../auth/admin.directory.user`

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003459413/original/RCoanvgVxMkq5zw30Qx0u1TfBeBkoYAXag.png?1649373929" alt=""><figcaption></figcaption></figure>

Select the scope for group: `.../auth/admin.directory.group`

<figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003459414/original/QQK-airbxl3LXIrw1J-gkGTuW_v3KzvZIQ.png?1649373940" alt=""><figcaption></figcaption></figure>

Next Click on Credentials section  and downlaod OAuth client json file on your local machine by clicking on the **Download OAuth client** button.

<figure><img src="/files/LQDI5CnD1D3T8ghUS8x5" alt=""><figcaption></figcaption></figure>

Next download the[**`net.tirasa.connid.bundles.googleapps-1.4.2.jar`**](https://github.com/Tirasa/ConnIdGoogleAppsBundle/releases/download/net.tirasa.connid.bundles.googleapps-1.4.2/net.tirasa.connid.bundles.googleapps-1.4.2.jar)bundle for Google Workspace from the Connector Server website. Once downloaded open a new command prompt and change to the directory where you have downloaded the bundle and run the following command on the `client_secrets.json` file that you obtained earlier step:

{% code fullWidth="true" %}

```
$ jar xvf net.tirasa.connid.bundles.googleapps-1.4.2.jar
$ java -jar net.tirasa.connid.bundles.googleapps-1.4.2.jar /path/to/client_secrets.json
Please open the following address in your browser: ?
access_type=offline ...
```

{% endcode %}

This command opens the default browser, and loads a screen on which you authorize consent to access the Google Apps account. When you have authorized consent, the browser returns a code. Copy and paste the code into the terminal from which you ran the original command

```
Attempting to open that address in the default browser now... 
Please enter code: XXXXXXXX
```

A response similar to the following is returned.

<figure><img src="/files/csfBYlNR8IYw7oUdpQw6" alt=""><figcaption></figcaption></figure>

Once the above information is obtained we need to configure the Google Workspace in Cymmetri with Server Configuration and User Configuration as shown below:

<figure><img src="/files/rcQvwochfgktButLWOOa" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/PnV97Ti9ss8UBS0GgAKt" alt=""><figcaption></figcaption></figure>

Once the configuration is done click on **TEST CONFIGURATION** button to check if the configuration is working.

Once the test is successful next go to the **Assigments** section and assign the application to a user as shown below:

<figure><img src="/files/UtegZhRzQ6V5TuP09jfW" alt=""><figcaption></figcaption></figure>

Once assigned ensure that the user is created in Google Workspace.


# Powershell Provisioning

## Integration with Powershell

1. For the powershell connector we need a windows server machine with a connId server on it.
2. Configure powershell connector with following properties\
   \ <br>

   <figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003459699/original/0bqm-TxEPXupd7-5b1VqyNwMtTKrdFD1EA.png?1649374540" alt=""><figcaption></figcaption></figure>
3. Must configure powershell script with valid data using the reference below

Reference: <https://drive.google.com/drive/folders/1XHt6aNmPzs7V7OKesk31FwqLxGf3u2ST?usp=sharing>&#x20;


# REST Connector Provisioning

Integration REST Application

1. The REST connector is designed to manage provisioning by relying on RESTful service.
2. For REST applications we need target applications which support REST API’s.
3. Following configuration is tested for felicity application.
4. We need REST API’s to integrate with cymmetri.
5. Following are the cymmetri configuration which need to configure in user configuration in cymmetri.
6. It is Basic REST configuration which need to configure in application.

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003459764/original/Nf5IkJXLHPE7R89McTxYcClKHRbMWNPV9Q.png?1649374607)

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003459774/original/hC6w0yXpo8UlEVteZOr2ADnJvMm2pN-ATg.png?1649374616)

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003459777/original/xoGRkkiJ9_Q2dtOLuCKXCKJ7ni3PBL-FAg.png?1649374628)

1. We need to provide Groovy code to run create user, update user, delete user and also recon pull and push (for recon pull we need to add sync script and for recon push we need to add search script)
2. For sample script please validate following link

<https://drive.google.com/drive/folders/1Vs8y1ZHXV3AjqsPkQSnwUoVppL-yc8Vl?usp=sharing>&#x20;

Note: Please Configure script step by step

1. Configure test script at initial step and then test configuration for provided script (If configure successfully then only go for step b).
2. Configure create script and test configuration (If successfully configured then only go for step c).
3. Configure update script and test configuration (If successfully configured then only go for step d).
4. Configure delete script and test configuration (If successfully configured then only go for step e).
5. Configure sync(pull) script and test configuration (If successfully configured then only go for step f).
6. Configure search(push) script and test configuration (If successfully configured then only go to the next step).


# SCIM v2.0 Provisioning with Basic Authentication

Integration SCIM v2.0 with Basic

1. Any application which supports SCIM v2.0 with basic authentication is workable for application.
2. Following are configuration which is used for SCIM with basic authenticator.

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003459787/original/2sLZp0M4CKHYgwlZ1DH5dl_p8ycJVnIUdQ.png?1649374696)

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003459789/original/_lDWAX3rGvmTWvSB7AN4TfuKtMJh8uxnsA.png?1649374708)

1. Base address - It is the endpoint of the target system which supports SCIM v2 API’s.
2. Username - Username to authenticate SCIM API endpoint.
3. Password - Password to authenticate SCIM API endpoint.
4. Authentication type - It is Fixed Bearer compulsory.
5. Update method - Patch or Put method.
6. Accept - Http header which accepts (application/json etc).
7. Content Type - Http header which accepts (application/json etc).


# SCIM 2.0 with Bearer Authentication

1. Any application which supports SCIM v2.0 with bearer token is workable for application.<br>

   <figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003459811/original/PSROuSBIchNyli__tGejfJE4XLTOK7bpxg.png?1649374849" alt=""><figcaption></figcaption></figure>

   <figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003459814/original/eWZHLXTTUNIfL7I_RDyfB5qTghrAU-7sXA.png?1649374869" alt=""><figcaption></figcaption></figure>

   <figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003459840/original/uHqKKvrJ6ZMP6tV-TDINn8ssl0F0fwASlQ.png?1649374883" alt=""><figcaption></figcaption></figure>

   <figure><img src="https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003459860/original/xXORmTT9bkY_ZlS76tn54MxZ1VI-6mGAPw.png?1649374894" alt=""><figcaption></figcaption></figure>
2. Following are configuration which is used for SCIM with bearer.
   1. Base address - It is the endpoint of the target system which supports SCIM v2 API’s.
   2. Username - Username to authenticate SCIM API endpoint.
   3. Password - Password to authenticate SCIM API endpoint.
   4. Security Token - It is a token which is used to authenticate.
   5. Grant Type - It is grant type which is used to grant access for API’s.
   6. Client Id - client id for authentication
   7. Client Secret - client secret for authentication
   8. Authentication type - It is Fixed Bearer compulsory.
   9. Update method - Patch or Put method.
   10. Accept - Http header which accepts (application/json etc).
   11. Content Type - Http header which accepts (application/json etc).
   12. Access Token Base Address - base address for access token
   13. Access Token Node Id - node id for access token
   14. Access Token Content Type - content type for access token.


# SCIM 2.0 with Fixed Bearer

1. Any application which supports SCIM v2.0 with fixed bearer is workable for application.
2. Following are configuration which is used for SCIM with fixed bearer

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003459926/original/tmM4vRLs3HPEgXBWD9damt3lnImj9MpGjg.png?1649375077)

1. Base address - It is the endpoint of the target system which supports SCIM v2 API’s.
2. Username - Username to authenticate SCIM API endpoint.
3. Password - Password to authenticate SCIM API endpoint.
4. Authentication type - It is Fixed Bearer compulsory.
5. Fixed Bearer Value - The value for fixed bearer.
6. Update method - Patch or Put method.
7. Accept - Http header which accepts (application/json etc).
8. Content Type - Http header which accepts (application/json etc).


# Github Provisioning

Github Enterprise provides provisioning using SCIM 2.0

\
Pre-requisites

1. Create an account in Github (Enterprise).
2. Enable SAML for the Github tenant to be used with Cymmetri.

Step 1. Configure SSO in Cymmetri

Note the application URL received from the Git SAML configuration

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003459962/original/-OT8GcFjzvhANoty7uAdkgUvAaZClc9USw.png?1649375220)

Continue the configuration by logging into Cymmetri using at least Application Administrator role

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003460010/original/OREyuWixbNL1IPy3XMxlbmK514GdGs3pvg.png?1649375263)

Note: Public certificate gets from SSO metadata(cymmetri) and format it using following

<https://www.samltool.com/format_x509cert.php>&#x20;

Note: Make sure when you test SAML then in cymmetri login with github admin users loginid which is added in cymmetri.

Configure Profile Mapping

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003460027/original/RKhO4SRvbHtVGrZQ75e0RwBRfC8o5p1Ftw.png?1649375364)

Create User in Cymmetri and make sure login id of Cymmetri is same as gitHub Admin user login id.&#x20;

![](https://s3-ap-south-1.amazonaws.com/ind-cdn.freshdesk.com/data/helpdesk/attachments/production/84003460028/original/OKsFrebzBHV2wA7zGF_0t2S6G0iRgYq2NA.png?1649375380)

Test SSO with the Cymmetri user.

1. Configure **SCIM v2.0 (Github)** application from master (cymmetri).
2. Basic provisioning policy attribute and policy map already aaded in default schema.
3. Github Application is run using Fixed Bearer token.
4. To get Fixed bearer token following steps used.

Step 1: Go to user settings in github

Step 2: Go to developer settings

Step 3: Go to personal access token and generate new token

Step4: Click on Configure SSO

Step 5: Click on Authorize

1. Use following cymmetri provision configuration and change according to github account.
2. Fixed Bearer Value copy from personal access token
3. Click on save
4. Click on Test Configuration with success message.
5. Check Policy map
6. Disable default for the respective attribute


# ServiceNow Provisioning

To configure ServiceNow Application with cymmetri we need to configure Active Directory application. Please follow the steps provided below.

1. Get ServiceNow application from Cymmetri Master apps.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXd6H1owyR6hzreJi9Rs56k9WjLGGUYQuEXmc178mxEmG100mDY4aYOIhdJW4842Xx-UckgyGlqURGYf1-zj3_yFNSdU3FFKXvfGqRlQE-zGdWqJ-Yx5U3MI2TbupVRr_rljRYUn2x2vNIEXLLvevc0cGE0?key=lUE454jiBC3DhVb2sxeZBA" alt=""><figcaption></figcaption></figure>

2. After Getting application from cymmetri master activate provisioning of selected application i.e Service Now.
3. After successfully activating provisioning, setup server configuration.

&#x20;           Note: Basic configuration is already provided in cymmetri master application. If the       connid server is configured externally then configure server config as per requirement.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXfYFVQXrqNgMzyIMVXMPwDg2qOrnxuKZlvJGgMXH5AmSo8pk_vfq48POEcLWGiUNYdTRPbVSGkOM9vxUH2N99Im9rGiV_OxLdntvFZ2waO1s6oGJ8Yi5w67MX4ggHv0wRYSsG_LJrTgEQ6_oqJO1Wzf7M9a?key=lUE454jiBC3DhVb2sxeZBA" alt=""><figcaption></figcaption></figure>

4. Successfully configuring server configuration, next step is to configure User Configuration. This is the most important step to connect and perform operations with Service Now.

For User configuration we need User config base address,User config username and User config base password  for all these credentials first we need to create account in Service Now which is a target application

Create account by clicking on below link

<https://developer.servicenow.com/> and sign in to the account.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXevpaTDPHik0D8lsK8dkugpfGQ62r2KAqsz43OpSyUCZ1ljMJJ_INdPaQ6nRQZHSfqBCbauwNha2WUVGyFFr4zrtb1MYV8xbrtQGBqhwbuFpnf9gIpJ9m_zIs3BYYORFM_MUZlmBX2VWGvuXTaXNq4P5JJq?key=lUE454jiBC3DhVb2sxeZBA" alt=""><figcaption></figcaption></figure>

After clicking continue we have to enter a verification code which we will get from the entered email address.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXdQ-z_kOgARuIQrPoDmYAJkotPdUTAQtch0xG096q3sEYJghhMdhBCXW1wuxoaABSQ9k4SPtslqe6vc9BSfzbcM9ZPSlwn2QGgqGMIg4xEMDe5JZG5H5QUb8DyJ8RuOEpUuQEzWrYi_EIOy9jkFI1__UT0?key=lUE454jiBC3DhVb2sxeZBA" alt=""><figcaption></figcaption></figure>

Now we can go to Service Now account and click on My Profile and setting&#x20;

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXdXOYehKNRrTe0ziB-67TsngRx7nJizL_1Og-5SV5F3miE3ZCyYeCYqeQmmxNpEWHOYp8wWNvWkZS0tiJHSCklFIBvMtmtSd6_Ziw-m9W9x5stJZYCmWqBZUogXoDDXVP9-j9Gl9wf3CBVnm4kYHn3Digs?key=lUE454jiBC3DhVb2sxeZBA" alt=""><figcaption></figcaption></figure>

it again asking for verification code.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXczDqdDTLev0osExrtRwiQ_PuIuvtvuTsNXT3yPuZGWUbooz1FEsS50xg7VlHLIK50eY-Y6yjrI23Lha5mn6-eaY8fDoYvb-fIS8KRjYpbebglqvCHwa0TIU05gzRmXtwka5AurRUsTbT20jwR5EDhdzdON?key=lUE454jiBC3DhVb2sxeZBA" alt=""><figcaption></figcaption></figure>

Enter the verification code and verify the account.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXdyS6Wgs-043lf0qGndcrZYHsFJqr9aueD6ebumhrtyNMArFoU4hPufHlNoGNgQDKfUU2opYXipqTfu6Q0RqdwF4CqSlkSVhlv5M_wmtpjHHa5qYDsx784dn6QIn0BIWPuRqDYODbmaSy4NTHBWk6MztLQ?key=lUE454jiBC3DhVb2sxeZBA" alt=""><figcaption></figcaption></figure>

Then click on Developer Program option

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXfuMVW2PaI8EwUdXGi12Nh97ZXF64Wm81QBGws8o4O3jAE8pd4VxfdhWJKGpThZST5zhm35oaObyus3ra1QUP9qHodpSSzkXMFvjriBlITW-KRiO20rEz_Cekg8aXCGZYqBL0bjG-pLQ27myc7rDjNgW9gX?key=lUE454jiBC3DhVb2sxeZBA" alt=""><figcaption></figcaption></figure>

Now check the job responsibilities for admin account  as shown in the screenshot

Now click on “Start building” tab for setting up an instance.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXf7tVTRTEdh70AA4ye19UZ6ZANf-HjUJnL8AYQSb4RPKaoZXSWEk57KARwQxfcAzAezOOkNfFAskomnGa4QkMM-rvlHhtIHn5yJ18beQowHttWEeaHqa1vjzbSBig-3rkN6QbnIss0drwiST_cJvUh3E6UF?key=lUE454jiBC3DhVb2sxeZBA" alt=""><figcaption></figcaption></figure>

After setting up an instance we will get credentials for configuring the service now.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcWxISe6zdHmLe6DFJxHDPmCgh8_CZsWChNWIyrsn9NPZUrukD0MGfoGspYVEwK-YVWwVAtMVqhUhVO2WqWyVQw7RQLNMEsxSwEBJ5YQrasKbmTnmcem-Na6-olfSEVruva2c0kj6UMkreWMo1-FMxV_xY?key=lUE454jiBC3DhVb2sxeZBA" alt=""><figcaption></figcaption></figure>

Add these credentials to the user configuration and save and test the configuration.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXepgJyjkTiX_96PpHRroK2ITnojkoJVhiRyfzzTkvOfI5JgIFdDj2Jr3YTZqsgoZX1atjpj-HJsXLVB2xHEVQ2XDo958yBzOU5jXirutOuW7kG0RTmSxTT7veaQwyYwsBgNorGfVdWjMhuuy6CySPXZYFY?key=lUE454jiBC3DhVb2sxeZBA" alt=""><figcaption></figcaption></figure>

Now we have to add the policyAttribute which is not available. Go to policyAttribute and click on Add New button.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXc4Q5a4k8dC3AKIgtwbLcvmT7tS8-pPtw3X38z_ag8DsXsT2fSRPy3L6175NCMcphTUgz1r3VxnvGMtQ5h4RZbTbIB7CSZqr_Mjzok1kTdcOnGdLr3vKY74Dtn1KWkhKaRBEg8OKHmJ54Ez-S49oz7eCyzD?key=lUE454jiBC3DhVb2sxeZBA" alt=""><figcaption></figcaption></figure>

After clicking on the new button we have to add policyAttribute.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcQFO3Wb1VIJ70My6iniPw8WiO80Z4xVkmEgS11MIN7ssl6hkrTX7WW0u9FI898j1JWUVWZJTxWx86fGkFgfpDiViq_W-Dy6zTvz2wMvNN-9RxxUZA6f0i4D2KF3hSB4kOgo7Wce-qUe_GO_5TGX1H97Iri?key=lUE454jiBC3DhVb2sxeZBA" alt=""><figcaption></figcaption></figure>

Now we also need to map the policyAttribute name and description and save it.

After completing policyAttribute we need to map these attributes with the cymmetri fields.

Go to policyMap and for user policyMap click on AddCymmetriField.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXctACQDtieW7R_XWgIDdm_N-On_rN3b9CyBN2ySGr2J6ioWkcn7dPHRnLEPQy6ZdE-PzrE8BmdDpuDZWRnH2g2ZPe9e3h_dZzT67x5IbecTxzmJpg3bFZMRFBnlUVwLrOqeIwu8h2rb9CkTcf-9ojpceYmm?key=lUE454jiBC3DhVb2sxeZBA" alt=""><figcaption></figcaption></figure>

After clicking Add Cymmetri Field, window will open&#x20;

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXdYELWKc_cBvw90-s_VXcfjK1xfKcFhAMI2dlaX-yxJ1F7DJWkVKWXv4gzVsK-NDl_0I6MoQTNm27pZ8WZa_Zqw-j0GEyE6h14RSZUbLH9kEUcwzPVQoYVk9w5-u3Ki9eehhDEf8O_2lgrqmDyFF9jFtkw?key=lUE454jiBC3DhVb2sxeZBA" alt=""><figcaption></figcaption></figure>

Click application field and select field which we want to map with cymmetri field (Select Cymmetri Field) and check create Only and Update Only tab and if we want to make any field as unique field then check Is User Principal checkbox and save it.

&#x20;           Map remaining field as above just remember which field is unique(is user Principal        marked checked).

After all configuration with these above steps now we are able to assign Service Now  Application to the user. To check whether a user created or not to the target application we need to go to Service Now account click on All and search for Users&#x20;

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXco0_91le8O0_whYTw7DYKT_HnuxR4BBB51ftL1GJ1yDjFgOOOXU0b6__2ONfBo3_vaS6WOyOH1V6ntCetjaiLWam2vycquYW6ylmvAnp1nmrHeAACXxz_p9cD4jCDodW33RfTLM5oOUk_hK3qaLke5e75a?key=lUE454jiBC3DhVb2sxeZBA" alt=""><figcaption></figcaption></figure>

Here we will get all the user list.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcLnIdcCiRKp3XeY2XE5gQk4bEn_VWF9DSo3k4lEaTmw4yreth-za-Kr18zxbGmcwQPlqXsR9pgwah6G9EGhQSWvJBMsysO6gn1TIR9y24gW4kQ-o4tkl_09LnBKoG5PA9codE_dCpWewmA0ginLOURSb1G?key=lUE454jiBC3DhVb2sxeZBA" alt=""><figcaption></figcaption></figure>


# AMAYA

AMAYA is Cymmetri's no-code/low-code provisioning tool designed to simplify and automate user identity and access management. It allows administrators to create, manage, and automate user provisioning workflows for various target systems (e.g., Slack, Azure, ServiceNow) without requiring extensive coding knowledge. The platform's core functionality is to manage the full lifecycle of user identities and their roles through a series of configurable operations, primarily by leveraging REST API endpoints.

The AMAYA application within Cymmetri is designed to facilitate the provisioning of users and groups to various target systems through a series of configurable operations. This application supports a variety of operations to manage the lifecycle of user identities, including testing a connection to the target system, syncing, searching, creating, updating, deleting, and managing roles.

#### Configuring the Amaya Application in Cymmetri&#x20;

1. Navigate to Applications → Add New → Create from Scratch.
2. Search for and select "Amaya."

<figure><img src="/files/i8GX9WHgvJ3XqKWMlSAk" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/OnbvyiBBdNnE2urbQTJu" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/ujcwBJEFFHgoBScJmOVH" alt=""><figcaption></figcaption></figure>

### **Application Provisioning**

The **Application Provisioning** interface for AMAYA is divided into several tabs:

#### **User Configuration**

Let's you configure the various user identity operations quickly and without coding

<figure><img src="/files/yedZouhXD1K2Vr6bD5Ef" alt=""><figcaption></figcaption></figure>

This interface allows administrators to configure and manage how users and groups are provisioned to or from target systems like Slack, Azure, ServiceNow, etc.

### Server Configuration

1. In the Server Configuration panel, input the IP address and other details for the Connector server.

<figure><img src="/files/BOKZoPRPp73XaWgu0bLW" alt=""><figcaption></figcaption></figure>

2. Save the configuration. A "Provisioning Configuration Successful" message will confirm that the connection profile has been established.

<figure><img src="/files/dbxOJ4cN7SPNmSUeK1Nl" alt=""><figcaption></figcaption></figure>

3. Test Operation (GET All Users) This step validates the connection and payload structure.

* Import the GET /api/now/table/sys\_user cURL command into the Test Operation slot.

<figure><img src="/files/ldQQRVvAZJLoedMUVF3k" alt=""><figcaption></figcaption></figure>

* Append ?sysparm\_limit=10 to limit the response to a manageable size (10 users).

<figure><img src="/files/VpwMgVAU4r31z5NS7Yq2" alt=""><figcaption></figcaption></figure>

* Run the request. Verify that the response is a 200 OK and contains an array of ten user objects.

<figure><img src="/files/oT66xpBumvmqyHnMQA99" alt=""><figcaption></figcaption></figure>

* Designate the response array as the result and the unique identifier field, sys\_id, as the Unique ID Key.

<figure><img src="/files/OEylo0jVp7E7FkXXgxg7" alt=""><figcaption></figcaption></figure>

**Synchronization Operation This operation seeds the policy mapping for attribute synchronization.**

* Paste the validated cURL command into the Sync Operation → cURL Import field.

<figure><img src="/files/vtj1q5NfAzDaWXq0loFS" alt=""><figcaption></figcaption></figure>

* Re-identify the result and sys\_id fields.

<figure><img src="/files/OEylo0jVp7E7FkXXgxg7" alt=""><figcaption></figcaption></figure>

* Save the configuration and click Generate Policy Mapping. This launches the automatic attribute mapping wizard.

**Automatic Policy Mapping The wizard scans the sample user data and presents a mapping interface.**

* Source Attribute (ServiceNow): The field name from the ServiceNow response.
* Destination Attribute (Cymmetri): The corresponding Cymmetri field.

For example:

* user\_name maps to login
* first\_name maps to firstName
* email maps to email
* sys\_id maps to the User Principal, which is the mandatory identifier.

You can uncheck irrelevant fields to create a lean and precise mapping.<br>

<figure><img src="/files/de4qWKZxS0a24B7GmIGu" alt=""><figcaption></figcaption></figure>

#### **CRUD Operations Configuration**

**Create User Operation:**

Endpoint: POST /api/now/table/sys\_user

<figure><img src="/files/ul0Li9t0GShmUMPyWBU2" alt=""><figcaption></figcaption></figure>

* Body Template: A JSON payload that maps Cymmetri user attributes to ServiceNow fields. Cymmetri’s built-in JSON validation and beautification tools ensure the payload is correctly formatted.

For example:

<figure><img src="/files/iYlZ9qnsyrOkm6lma4cM" alt=""><figcaption></figcaption></figure>

Validate –

Role Provisioning: An optional second node, Assign Role, can be added to the flow. This node consumes the sys\_id returned from the initial user creation to assign a role

<figure><img src="/files/k8u71k06FQojrovf753z" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/jUJNLPmzl8Atf7CJZJ3x" alt=""><figcaption></figcaption></figure>

Role assign another node.

<figure><img src="/files/L0FaeyPy5HMPiNH53RBy" alt=""><figcaption></figcaption></figure>

**Role Assignment and Unassignment**

**Role Assignment Flow Since ServiceNow handles roles as a separate table, the connector uses a two-node flow:**

* Node 1 (Create User): Creates the user and captures the sys\_id as ${UID}.

<figure><img src="/files/FI2fdSbyH7naRvbHJk6k" alt=""><figcaption></figcaption></figure>

* Node 2 (Assign Role): Makes a POST call to /api/now/table/sys\_user\_role with a body that links the user (${UID}) and the role (${\_role}).

<figure><img src="/files/70sDZWMgZdyFRVoKJoIu" alt=""><figcaption></figcaption></figure>

**Update User Operation**

To update an existing user, the system leverages the same attribute mapping used for user creation. However, the API endpoint is modified to include the user's unique identifier.

* API Endpoint: PUT /api/now/table/sys\_user/${UID}
* Method: PUT
* Purpose: This request updates an existing user record. The ${UID} variable, which is an alias for the user's sys\_id in ServiceNow, ensures that the specific user record is targeted. The request body contains the updated user attributes (e.g., first name, email, department), allowing for partial or full updates to the user's profile.

<figure><img src="/files/tdtwFqsuEhbCdsPgP2w5" alt=""><figcaption></figcaption></figure>

**Delete User Operation**

Deleting a user is a streamlined process that requires only the user's unique identifier.

* API Endpoint: DELETE /api/now/table/sys\_user/${UID}
* Method: DELETE
* Purpose: This request permanently removes a user record from ServiceNow. The DELETE operation automatically handles the removal of all associated data, including any roles linked to the user's account.

<figure><img src="/files/PeT9fknPF3BHlRUeb8x2" alt=""><figcaption></figcaption></figure>

#### Role-Based Workflows

Since ServiceNow manages user-to-role relationships in a separate table, the Cymmetri connector uses multi-node flows to handle these operations accurately.

**Role Assignment Flow**

This two-step process ensures a role is correctly assigned to a user immediately after the user account is created.

1. Node 1: Create User
2. Action: A POST request creates the new user account in ServiceNow.
3. Output: The sys\_id of the newly created user is captured and stored as the variable ${UID} for subsequent use.
4. Node 2: Assign Role
5. Action: A POST request is made to the sys\_user\_role table, which manages user-role relationships.
6. API Endpoint: POST /api/now/table/sys\_user\_role

Request Body: The request body formally links the user and the role:\
JSON\
{

&#x20; "user": "${UID}",

&#x20; "role": "${\_role}"

}

* Purpose: This step assigns a specific role to the user, identified by the ${\_role} variable, which is sourced from a pre-loaded CSV file containing over 200 role IDs within Cymmetri.

<figure><img src="/files/vgYpGfBoUlVKeqPiT4Pi" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/jYxPaRYNnMOT0lzQa9lU" alt=""><figcaption></figcaption></figure>

**Role Unassignment Flow**

This more complex three-node process is required because ServiceNow needs the specific sys\_id of the role assignment record to delete it, rather than just the user or role sys\_id.

1. Node 1: Fetch Assignment ID
2. Action: A GET request queries the sys\_user\_role table to find the specific assignment record.
3. API Endpoint: GET /api/now/table/sys\_user\_role?sysparm\_query=role=${\_role}^user=${UID}
4. Output: The system captures the sys\_id of the role assignment record and stores it as the variable ${roleAssignmentID}.

<figure><img src="/files/9o1TiwwJKPA1z1BDFFSR" alt=""><figcaption></figcaption></figure>

2. Node 2: Remove Role
   1. Action: A DELETE request is made to the sys\_user\_role table to remove the role assignment.
   2. API Endpoint: DELETE /api/now/table/sys\_user\_role/${roleAssignmentID}
   3. Purpose: This final step explicitly removes the role from the user by using the unique identifier of the assignment&#x20;

<figure><img src="/files/FOHxUidQUSIEoD9lJXnF" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/xiDicx83I4kv97artOuk" alt=""><figcaption></figcaption></figure>

#### Advanced Workflow and Data Transformation

This section formalizes the advanced features of the Cymmetri-Amaya integration.

**Multi-Role Support**&#x20;

This feature enables the synchronization of user roles from a connected application (e.g., ServiceNow) into Cymmetri.

* Synchronize Roles: The connector can pull and map user roles from the source system. In Cymmetri, these synchronized roles are typically categorized under a \_ROLE\_ object.
* Assign Roles: The system can bring users in along with their assigned roles, ensuring permissions are accurately reflected in Cymmetri's Identity Hub. This eliminates the need for manual role assignments after user provisioning.

<figure><img src="/files/cue5JuxWIEIWP0NkcHDl" alt=""><figcaption></figcaption></figure>

**Condition Node**&#x20;

A Condition Node introduces conditional logic, allowing the workflow to take different paths based on specific criteria.

* Example: A condition can check for a user's type, like usertype:emp (for "employee"). If the condition is met, the workflow follows one path; if not, it follows another. This is crucial for applying different provisioning policies to different types of users (e.g., employees vs. contractors).

<figure><img src="/files/U2QnzAxaB9RHW0hZNprS" alt=""><figcaption></figcaption></figure>

**Transformational Node**

A Transformational Node is a powerful tool for manipulating and standardizing data within the workflow. It's used to modify or create data fields based on existing response data from an API call.

* Purpose: The primary use is to convert raw data into a format required by another system. For example, it can be used to generate an email address from a user's employee code.
* Example: An API response might contain an emp\_code field. The Transformational Node can take this value and append a domain to it to create an email address.
* Placeholders: The node uses placeholders (e.g., ${emp\_code}) to refer to specific data attributes from the API response. These placeholders hold the data corresponding to the attribute, making it easy to reference and transform.

<figure><img src="/files/R307GbkUcPNV9elWe97k" alt=""><figcaption></figcaption></figure>

All identity management operations—including user synchronization, creation, updates, and role assignments—are built using a combination of the core nodes mentioned above.

Sync Operation (User Pull): The sync operation uses an API Node to perform a GET request, an Iterator Node to process the list of users returned, and Transformational or Condition Nodes to format the data and apply business logic.

<figure><img src="/files/REBSuvIrI2sQTPdUrps8" alt=""><figcaption></figcaption></figure>

* Create Operation: This operation uses an API Node with a POST request to create a user, followed by Transformational Nodes to format the payload and potentially Condition Nodes for approval workflows.

<figure><img src="/files/iJLAHys7rJkJF1ePhgCo" alt=""><figcaption></figcaption></figure>

* Update Operation: Similar to the create operation, it uses an API Node with a PUT or PATCH request, with the same supporting nodes.

<figure><img src="/files/eeYO9XDmr1eFo1cBW9za" alt=""><figcaption></figcaption></figure>

Delete Operation: This uses an API Node with a DELETE request, typically a streamlined workflow

<figure><img src="/files/H5wHbr3l9VLVWpvckHy5" alt=""><figcaption></figcaption></figure>

* Role Assign/Unassign: These are multi-node workflows that use a series of API Nodes for creating or deleting role assignments, often including Condition Nodes for validation.

<figure><img src="/files/sSwjPKKcI9bEGVKCDhVO" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/av5fQA0rJZoEZAQrXkrb" alt=""><figcaption></figcaption></figure>

### **AMAYA Key Operations**&#x20;

* **Test Operation**: This operation is used to test the configuration with the target system. It ensures that the setup is correct and that the AMAYA application can communicate with the target system.
* **Sync Operation**: This operation is used to synchronize users or groups from the target system. It ensures that the user/group data in Cymmetri is consistent with the data in the target system.
* **Search Operation**: This operation allows administrators to search for users or groups in the target system, making it easier to find specific entities.
* **Create Operation**: This operation is used to create users or groups in the target system based on the information in Cymmetri.
* **Update Operation**: This operation allows for updating the details of existing users or groups in the target system, ensuring that changes made in Cymmetri are reflected accurately.
* **Delete Operation**: This operation is used to delete users or groups from the target system, removing access or decommissioning identities as required.
* **Role Assign Operation**: This operation assigns roles to users or groups in the target system, helping to manage permissions and access levels.
* **Role Unassign Operation**: This operation unassigns roles from users or groups in the target system, removing permissions as necessary.

**Quick Setup with Predefined Templates**

The second image shows the **Quick Setup** screen, which provides predefined templates for popular applications. These templates simplify the process of setting up provisioning by offering pre-configured settings for the following applications:

* **Slack**
* **ServiceNow**
* **HubSpot**
* **Azure**
* **AWS Identity Center**
* **Zoho Expenses**
* **Zoho Books**
* **Zoho CRM**
* **Zoho Desk**

Administrators can quickly start with these templates, which have standard configurations, and customize them as needed to suit their specific requirements. The search function at the top allows users to find other applications if the needed one is not listed among the predefined templates.

**Hook Configurations**\
If the administrator needs to write some custom action before and/or after provisioning the application, that can be enabled by configuring web hooks, as shown in the Hook Configuration. The configuration supports a PRE and a POST HOOK for triggering custom code before and/or after provisioning of the application. Refer to webhooks [here](/lifecycle-management/configuring-webhooks)

<figure><img src="/files/5BKMPND4HPyFXs2xZwzB" alt=""><figcaption></figcaption></figure>


# HRMS




---

[Next Page](/llms-full.txt/1)

