Policy Xpress conditions fail on non-production environments due to Unique Name mismatch - Identity Manager
search cancel

Policy Xpress conditions fail on non-production environments due to Unique Name mismatch - Identity Manager

book

Article ID: 108131

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Suite

Issue/Introduction

Policy Xpress (PX) policies may fail to execute in non-production environments (e.g., Staging, Development) even when they function correctly in production.

This article explains the behavior of "Task/Event Info Unique Name" across different Identity Manager instances and provides the recommended configuration to ensure portability between environments.

Environment

Identity Manager 14.x

Cause

In Identity Manager, the "Unique Name" is an internal ID generated by the environment's object store upon task creation. Because these IDs are created sequentially, the ID assigned to a specific task (e.g., "Modify User") will differ between instances (e.g., ID 391 in production vs. ID 473 in staging). Consequently, hardcoding these IDs in PX entry rules creates a dependency that is not environment-agnostic.

Resolution

To ensure Policy Xpress policies operate consistently across all environments, avoid using "Unique Name" for entry rules. Instead, use environment-independent attributes:

  1. Open the Policy Xpress policy in the Management Console.
  2. Modify the Action Entry Rule.
  3. Replace the usage of Task/Event Info > Unique Name with one of the following:
    • Friendly Name
    • Task Tag
  4. Save the policy. 

Note: Using Friendly Name or Task Tag ensures the policy logic remains valid regardless of the internal object ID assigned to the task in different Identity Manager instances.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.