It might not be the case that groups are created and managed in FIM. There might be an external system with information about groups and their members.
At The Company, all groups related to the Organization are managed in the HR system. The membership—the member
attribute—is made available through the multi-value setting in the HR MA.
First of all, we need to import the group data from HR, using an Inbound synchronization rule.
We are getting the hang of this by now, so let's look at it quickly.
Select the Inbound button for Data Flow Direction.
In the HR system, at The Company the object type Resource Type is orgUnit, but in our FIM we want these set as group.
In this example, I use accountName to check if the group already exists, in order to make a join. Create Resource in FIM (projection) should likely be enabled in this scenario. At The Company, it is:
The Company has decided that all groups based on orgUnit and coming from HR should be Universal (scope), Security...