...
...
...
- Full Control for the container that stores the system data (default name is “Indeed Identity”) and all of its descendant objects. To do so:
1. Open the Security property of the Indeed Identity container.
2. Click Add and specify the service account (servicecm).
3. Click Advanced, select the service account and click Edit.
4. Select the scope of This object and all descendant objects.
5. Set the Full control permission in the Permissions list.
6. Click ОК and then Apply.
- Permission to Read all Properties:
...
...
...
...
...
...
...
- Write: userAccountControl
- Write: thumbnailPhoto or Write: jpegPhoto
- Write: pwdLastSet
...
...
...
...
...
...
When configuring the permissions to read user properties different from default ones, it is also necessary to permit the service account (servicecm) to read the values of object attributes (i.e. Domain, container or organizational unit) that contains Indeed CM users. These attributes are: cn, objectGUID, name and showInAdvancedViewOnly.
...
...
...
...
...
...