Source: projects/identity-management/knowledge-base/oneim-10-lts-technical-documents.md

> Source: projects/identity-management/knowledge-base/oneim-10-lts-technical-documents.md

One Identity Manager 10.0 LTS Technical Documents Index

Source: One Identity Manager 10.0 LTS technical documents

Captured: 2026-04-26

Purpose: durable workspace index of the official 10.0 LTS document set, with routing notes for OIM sandbox, IT Shop, role, synchronization, and developer work.

High-Value Reading Order

For the current sandbox and IT Shop entitlement work:

1. Identity management fundamentals: core objects, inheritance model, identity/resource concepts.

2. IT Shop structure and functionality: shelves, shops, products, requests, service items, request lifecycle.

3. System roles: ESet concepts, inheritance, assignment, exclusions, IT Shop publication.

4. Business roles: role hierarchy and assignment semantics distinct from system roles.

5. Connecting to Active Directory: ADSGroup, AD synchronization, containers, group scope/type, service-account needs.

6. Basics of target system synchronization: synchronization project behavior, object matching, provisioning, and troubleshooting.

7. One Identity Manager REST API and API Development: API-driven operations and custom APIs.

8. Configuring One Identity Manager and Operational guide: configuration parameters, transport, services, operations.

9. Process monitoring and troubleshooting: job queue, DBQueue, service/process health.

10. Web Portal / Working with the Web Portal: request UX and self-service verification.

Current Sandbox-Relevant Interpretation

Live OneIM DB checks on 2026-04-26 showed:

OneIM areaLive sandbox stateDocumentation route
IT Shop treeITShopOrg exists with Identity & Access Lifecycle root and AD group / role request nodes. Live semantics: ITShopInfo = SH for shop root, BO for direct shelves, PR for product nodes, CU for customer nodes.IT Shop structure and functionality
Products/service itemsAccProduct exists with predefined AD group and system-role request productsIT Shop structure and functionality
AD groupsADSGroup exists, but current groups are not IT Shop published (IsForITShop = 0)Connecting to Active Directory, IT Shop
System rolesESet and ESetHasEntitlement are empty, but schema and ESetType existSystem roles
AD syncGroups seeded under OU=OIM-Managed must later sync into ADSGroupConnecting to Active Directory, Basics of target system synchronization

For the AD shop-seeding project, create AD groups first. In a later OIM-side phase, sync them into ADSGroup, publish direct app groups as service items, and model SR_* bundle markers as OIM ESet system roles linked to included ADSGroup entitlements through ESetHasEntitlement. Do not model deep nested shelves in ITShopOrg; OneIM trigger logic rejects BO below BO, so application/domain grouping should use AccProductGroup, service item names, and metadata.

Documents by Type

Administration Guides

DocumentWorkspace relevance
One Identity Manager - AccountingCost/accounting contexts for service items and reporting.
One Identity Manager - Administration Guide for Connecting to Cloud HR SystemsHR source-system integration patterns; relevant for later demo identities.
One Identity Manager - Administration Guide for Database Systems IntegrationGeneric database target integration.
One Identity Manager - AttestationAttestation workflows for access review and policy confirmation.
One Identity Manager - Basics for managing target systems in One Identity ManagerCore target-system administration model; useful before any connector-specific work.
One Identity Manager - Behavior Driven GovernanceGovernance automation concepts and behavior-driven controls.
One Identity Manager - Business rolesBusiness role hierarchy, role assignment, inheritance, and role-based resource allocation.
One Identity Manager - Company policiesPolicy modeling and policy violation handling.
One Identity Manager - Compliance rulesCompliance-rule modeling for separation-of-duties and access controls.
One Identity Manager - Connecting a Privileged Account Management SystemsPAM integration patterns.
One Identity Manager - Connecting custom target systemsCustom connector/target system modeling.
One Identity Manager - Connecting to a Universal Cloud InterfaceUCI connector patterns.
One Identity Manager - Connecting to Active DirectoryPrimary reference for ADSAccount, ADSGroup, AD containers, synchronization, and provisioning.
One Identity Manager - Connecting to Active Directory with One Identity Active RolesActive Roles integration for AD management through ARS.
One Identity Manager - Connecting to Cloud applications using the SCIM connectorSCIM provisioning connector.
One Identity Manager - Connecting to Exchange OnlineExchange Online target-system integration.
One Identity Manager - Connecting to Google WorkspaceGoogle Workspace integration.
One Identity Manager - Connecting to HCL DominoHCL Domino integration.
One Identity Manager - Connecting to LDAPLDAP target-system integration, distinct from AD.
One Identity Manager - Connecting to Microsoft Entra IDMicrosoft Entra ID integration.
One Identity Manager - Connecting to Microsoft ExchangeOn-prem Exchange integration.
One Identity Manager - Connecting to Microsoft TeamsTeams integration.
One Identity Manager - Connecting to Oracle E-Business SuiteOracle EBS integration.
One Identity Manager - Connecting to SAP R/3SAP R/3 integration.
One Identity Manager - Connecting to SAP R/3 HRSAP HR integration.
One Identity Manager - Connecting to SAP R/3 with BI analysis authorizationsSAP BI authorization analysis.
One Identity Manager - Connecting to SharePointSharePoint integration.
One Identity Manager - Connecting to SharePoint OnlineSharePoint Online integration.
One Identity Manager - Connecting to UnixUnix target-system integration.
One Identity Manager - Data archivingArchiving operational and history data.
One Identity Manager - Identity management fundamentalsFoundational model for identities, resources, roles, inheritance, and processes.
One Identity Manager - Integration with OneLogin Cloud DirectoryOneLogin Cloud Directory integration.
One Identity Manager - IT Shop structure and functionalityIT Shop, shelves, products, service items, request lifecycle, and publication mechanics.
One Identity Manager - Operational guideOperations, service health, maintenance, and runtime administration.
One Identity Manager - Report subscriptionsReport subscription management.
One Identity Manager - Risk assessmentRisk index and risk analysis concepts; currently out of scope for AD seeding v1.
One Identity Manager - SAP functionsSAP-specific function handling.
One Identity Manager - Software managementSoftware/resource management.
One Identity Manager - Starling Connect Connector Administration GuideStarling Connect integration.
One Identity Manager - System rolesESet system role concepts, inheritance, exclusions, direct assignment, role nesting, and IT Shop publication.
One Identity Manager and Epic Integration - Administration Guide for Connecting to Epic Target SystemEpic integration.
One Identity Manager and Service Now Integration - Administration GuideServiceNow integration.
One Identity Manager - Administration Guide for Azure Cloud Access GovernanceCloud Access Governance integration.

Configuration Guides

DocumentWorkspace relevance
One Identity Manager - Authorizing and authenticating in One Identity ManagerAuthentication modules, authorization, and access to tools/APIs.
One Identity Manager - Configuration of Password Synchronization with the Password Capture AgentPassword sync using Password Capture Agent.
One Identity Manager - Configuration of Secure Password ExtensionSecure Password Extension setup.
One Identity Manager - Configuring One Identity ManagerCore configuration parameters and system configuration.
One Identity Manager - Web application configurationWeb Portal and web application configuration.

Deployment Guide

DocumentWorkspace relevance
One Identity Manager - Intelligent Query Chatbot DeploymentDeployment of the Intelligent Query Chatbot.

General

DocumentWorkspace relevance
One Identity Manager - GlossaryCanonical terminology lookup.

Getting Started Guide

DocumentWorkspace relevance
One Identity Manager - One Identity Manager tools user interfaceUI orientation for Manager, Designer, Launchpad, and related tools.

Installation Guide

DocumentWorkspace relevance
One Identity Manager - Installing the One Identity ManagerInstallation, database setup, and initial components.

Reference Guides

DocumentWorkspace relevance
One Identity Manager - API DevelopmentCustom API development and API Server extensibility.
One Identity Manager - Basics of target system synchronizationSynchronization project architecture, mappings, object matching, provisioning, and sync troubleshooting.
One Identity Manager - GlossaryDuplicate listing; use as terminology reference.
One Identity Manager - One Identity Manager REST APIREST API endpoints and API usage.
One Identity Manager - Setting Up the LDAP Connector for CA ACF2Mainframe LDAP connector setup.
One Identity Manager - Setting Up the LDAP Connector for CA Top SecretMainframe LDAP connector setup.
One Identity Manager - Setting Up the LDAP Connector for IBM iIBM i LDAP connector setup.
One Identity Manager - Setting Up the LDAP Connector for IBM RACFIBM RACF LDAP connector setup.
One Identity Manager - Web application developmentWeb application customization/development.

Release Notes

DocumentWorkspace relevance
One Identity Manager - DSI Release NotesDatabase Systems Integration release notes.
One Identity Manager - Release NotesCore 10.0 LTS release changes and known issues.
One Identity Manager - Starling Connect Connector Release NotesStarling Connect release notes.
One Identity Manager and Cloud HR Systems Integration - Release NotesCloud HR release notes.
One Identity Manager and Epic Integration - Release NotesEpic integration release notes.
One Identity Manager and Service Now Integration - ServiceNow Integration Release NotesServiceNow integration release notes.
One Identity Manager - Cloud Access Governance Release NotesCAG release notes.

Troubleshooting Guide

DocumentWorkspace relevance
One Identity Manager - Process monitoring and troubleshootingDBQueue, JobQueue, process monitoring, and troubleshooting. Critical for sandbox health work.

User Guides

DocumentWorkspace relevance
One Identity Manager - Connecting a database using the One Identity Manager connectorUser-facing database connector setup.
One Identity Manager - Connecting a target system using the CSV connectorCSV connector usage.
One Identity Manager - Connecting a target system using the PowerShell connectorPowerShell connector usage.
One Identity Manager - Connecting to a database using the generic ADO.NET providerADO.NET connector usage.
One Identity Manager - Connecting to a DB2 (LUW) databaseDB2 connector usage.
One Identity Manager - Connecting to a MySQL databaseMySQL connector usage.
One Identity Manager - Connecting to a PostgreSQL Server databasePostgreSQL connector usage.
One Identity Manager - Connecting to an Oracle DatabaseOracle connector usage.
One Identity Manager - Connecting to an SAP HANA databaseSAP HANA connector usage.
One Identity Manager - Connecting to an SQL Server databaseSQL Server connector usage.
One Identity Manager - Connecting to an SQLite databaseSQLite connector usage.
One Identity Manager - Help deskHelp desk user workflows.
One Identity Manager - Working with the Application Governance ModuleApplication Governance workflows.
One Identity Manager - Working with the Operations Support Web PortalOperations Support Web Portal workflows.
One Identity Manager - Working with the Web PortalWeb Portal end-user request and approval workflows.

Topic Routing

TopicRead first
IT Shop shelves, products, requestabilityIT Shop structure and functionality
AD groups and AD synchronizationConnecting to Active Directory; Basics of target system synchronization
System roles, resource bundles, ESetSystem roles
Business role hierarchy and assignmentsBusiness roles
Service item publicationIT Shop structure and functionality; Active Directory guide
API automationREST API; API Development
Process/queue healthProcess monitoring and troubleshooting; Operational guide
Web Portal verificationWorking with the Web Portal; Web application configuration

Local Follow-Ups