Initial Password Synchronization to Active Directory During User Onboarding
search cancel

Initial Password Synchronization to Active Directory During User Onboarding

book

Article ID: 124526

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Governance CA Identity Portal CA Identity Suite

Issue/Introduction

During the initial user onboarding process in Identity Manager—specifically when using the TEWS web service call to execute a "Create User" task—the password may fail to synchronize to the Active Directory (AD) endpoint. This article provides the configuration steps to ensure the initial password is correctly pushed to Active Directory.

Environment

Identity Manager

Resolution

To ensure the initial password synchronizes correctly to the Active Directory endpoint during user creation, follow these steps:

  1. Modify the Create User Task: Access the Identity Manager User Console and locate your initial user creation task.
  2. Add a Provisioning Role: Configure the "Create User" task to assign a provisioning role to the user during creation. This can be an existing role or a "dummy" provisioning role created specifically for this purpose.
  3. Validate Synchronization: Assigning a provisioning role during the "Create User" task forces the creation of the Global User object. When the global user is created with a provisioning role, the subsequent modification task to add the AD role will correctly trigger the password synchronization to the Active Directory endpoint.