it detects “SYNCHRONIZATION_ORPHAN” in the users in the AD and there are not in the IAM, but it does not create them in the IAM. What could it be due to?
How can I make the users detected as “SYNCHRONIZATION_ORPHAN” imported into IAM. That is, the AD users create them in iam despite detecting them as orphans.
The idea behind orphan detection is to find accounts in your target system like AD which dont below to a user. These users either need to be linked to a real user or they need to removed. You will be able to see these in the webconsole orphan management UI.
If you want to just add these users to OpenIAM then
– disable orphan management
– disable downstream provisioning