This article explains why Account Properties in Identity Manager may display stale information instead of real-time data from an endpoint, and provides a procedure to resolve this by clearing cached values from the Provisioning Repository.
Identity Manager 14.5 & 15
By default, the Provisioning Repository stores minimal information for account reference objects. When a user requests account properties, Identity Manager typically retrieves data in real-time from the endpoint.
However, if account attributes are configured in Custom Correlation Rules or Endpoint Attribute Mappings, these values are cached in the Provisioning Repository. When these mappings exist, the application displays the stored value rather than fetching data from the endpoint. Stale information persists until the next "Explore" operation updates the attribute, or until the cache is manually cleared.
Remove Mappings: Identify and remove the Custom Correlation Rules or Endpoint Attribute Mappings responsible for the cached data.
Locate Affected Accounts: Use ldapsearch to identify all account reference objects that contain a value for the specific attribute. Replace the placeholders (IMPS_HOST, PASSWORD, MyEndpoint, MyConnectorType, eTDYN-str-multi-01) with your specific environment details:
Prepare Deletion LDIF: The generated accountlist.ldif file contains the DNs of the affected accounts. Create a new input.ldif file to delete the attribute values for these accounts:
Apply Changes: Use the ldapmodify command to process the input.ldif file and clear the stale attributes:
To speak with a customer representative or a Support Engineer see . Scroll to the bottom of the page and click on your respective region.