Bulk Loader Modifies Read-Only and Hidden Fields - Identity Manager
search cancel

Bulk Loader Modifies Read-Only and Hidden Fields - Identity Manager

book

Article ID: 110706

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Suite

Issue/Introduction

This article explains the behavior of the Bulk Loader tool when processing user creation or modification tasks. Specifically, it addresses why attributes that appear as read-only or are excluded from the profile screen are still updated during bulk load operations.

Environment

Identity Manager 14.5 & 15

Cause

Bulk Loader operations bypass UI-level validation. Permissions, such as "read-only" status assigned to attributes on the profile screen, are enforced strictly by the user interface. Consequently, these validations do not apply when the Bulk Loader executes tasks directly against the user store.

Resolution

To manage attribute modifications during bulk load operations, use a Business Logic Task Handler (BLTH) or a Policy Xpress (PX) policy to enforce business rules.

  1. Identify the specific attributes requiring restricted access.
  2. Implement a BLTH or PX policy to monitor changes to these attributes during bulk load tasks.
  3. Configure the policy to trigger a validation check or block the operation if unauthorized changes are detected.
  4. Test the policy in a non-production environment to ensure it aligns with your business requirements.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.