Tips on running ISS Sync
Sync has seven phases.
When it fails, it will create a locked process and it can be resumed from the last completed phase.
All errors are written to lawdir/system/security_provisioning.log. Sync can be cancelled altogether with ssoconfig.
Sync will always identify some conflicts. Follow the instructions in the ISS Configuration guide to know which conflicts can safely be ignored.
For example, it might fail to sync an environment identity for a user. Try creating or deleting that environment identity in Landmark under the Gen profile manually using Rich Client, then rerun the sync identities phase.
Once federation is complete use the ISS website for all user maintenance tasks instead of LSA. Grant the actor role SecurityAdministrator_ST to anyone who needs the ability to maintain Lawson user accounts.
Update or rewrite user provisioning scripts to work with the newly federated environment. Use ISS list-based sync functionality.





