Active Directory Account Expiry Date Synchronization Limitations in Identity Manager
search cancel

Active Directory Account Expiry Date Synchronization Limitations in Identity Manager

book

Article ID: 128040

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Suite

Issue/Introduction

When synchronizing Active Directory accounts using account templates in Identity Manager, the ExpiryDate attribute may be reset to '0'. This occurs because the expiry date at the endpoint is defined as a capability attribute with specific mapping restrictions.

Environment

Identity Manager 14.5 & 15

Cause

The Active Directory ExpiryDate attribute is classified as a "capability attribute" within the Identity Manager endpoint definitions. As a result:

  • Users cannot map custom attributes (containing specific date values) directly to this field via the account template.
  • During synchronization, the system attempts to resolve the attribute; if no direct mapping is supported, the value defaults to empty or '0'.

Resolution

To correctly synchronize or update the Active Directory expiry date, use one of the following methods:

  1. Policy Xpress (PX) Policy: Create a PX policy to programmatically set the expiry date on the Active Directory account after the initial synchronization.
  2. Verify Attribute Mapping: Ensure that custom attributes are not being incorrectly mapped to capability attributes in the template configuration.
  3. Manual Update: If PX policies are not utilized, the expiry date must be managed directly at the endpoint or through separate task logic.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.