Installation guide
Technical Guidelines 29
To synchronize all users without having them replicated on one single server, you need to
determine which set of servers holds all the users, and then create an instance of the Identity
Manager driver on each of those servers. To prevent two instances of the driver from trying to
synchronize the same users, you need to use scope filtering to define which users each instance
of the driver should synchronize.
NOTE: You should use scope filtering even if your server’s replicas don’t currently overlap. In
the future, replicas could be added to your servers and an overlap could be created
unintentionally. If you have scope filtering in place, your Identity Manager drivers do not try to
synchronize the same users, even if replicas are added to your servers in the future.
Here’s an example of how scope filtering is used:
The following illustration shows an Identity Vault with three containers that hold users: Marketing,
Finance, and Development. It also shows an Identity Management container that holds the driver
sets. Each of these containers is a separate partition.
Figure 3-4 Example Tree for Scope Filtering
In this example, the Identity Manager administrator has two Identity Vault servers, Server A and
Server B, shown in Figure 3-5 on page 30. Neither server contains a copy of all the users. Each server
contains two of the three partitions, so the scope of what the servers hold is overlapping.
The administrator wants all the users in the tree to be synchronized by the GroupWise driver, but
does not want to aggregate replicas of the users onto a single server. He chooses instead to use two
instances of the GroupWise driver, one on each server. He installs Identity Manager and sets up the
GroupWise driver on each Identity Manager server.
Server A holds replicas of the Marketing and Finance containers. Also on the server is a replica of the
Identity Management container, which holds the driver set for Server A and the GroupWise Driver
object for Server A.
ACME
DevelopmentMarketing Finance
ACME Identity Vault
JBassad
Identity Management
Driver Set
Server A Server B
GroupWise
Driver A
GroupWise
Driver B