Account ID Synchronization Failure using %UE% - Identity Manager
search cancel

Account ID Synchronization Failure using %UE% - Identity Manager

book

Article ID: 132847

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Suite

Issue/Introduction

In Identity Manager, account templates utilize rule strings to define attribute formats dynamically. However, a limitation exists when attempting to synchronize the Account ID attribute using the %UE% (User Email Address) rule string, even when Strong Synchronization is enabled.

Environment

Identity Manager 14.5 & 15

Cause

This behavior is by design. The Account ID attribute cannot be modified or synchronized via standard template rules once the account object is established, as the Provisioning Repository caches correlation attributes. Direct updates to these attributes on the endpoint are not automatically reflected in the Identity Manager cache without an exploration task

Resolution

To synchronize attributes that are not updating via template rules, implement a Policy Xpress (PX) policy to set values after the synchronization event.

  1. Create a Logical Attribute to store the desired value (e.g., the User Email).
  2. Configure a PX Policy of type Submitted Task.
  3. Set the trigger to Task Completion for the Create User or Modify User tasks.
  4. Add an action to the PX Policy that explicitly sets the ADS Account ID on the target endpoint using the value stored in the logical attribute.
  5. IMPORTANT: Schedule a periodic Explore and Correlate task on the Active Directory endpoint to ensure the Provisioning Repository cache is updated with any changes made during this process

Additional Information

For more information on Attributes and Rule strings, please refer to the Attributes and Rule Strings in Account Templates - 14.5 or Attributes and Rule Strings in Account Templates - v15

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.