This article explains how the Provisioning Server stores associations between objects internally in the Provisioning Repository. Every object in the Provisioning Repository contains a UUID stored in the eTID attribute. These eTID values serve as references to link objects. As objects are deleted and recreated, new UUIDs are generated. Moving data between installations requires accounting for these eTID values, as they may become invalid.
Object associations are categorized into two methods:
SuperiorClass object to a SubordinateClass object using eTPID and eTCID attributes.Managing Object Associations
Non-Inclusion Associations
The following relationships are managed directly on the object attributes:
Inclusion Object Associations
Inclusion Objects are named using the format eTPID_Value@eTCID_Value. The following relationships utilize this method:
Troubleshooting and FAQ
Data Migration Direct export and import are not supported due to dependency on existing eTID values. Before importing objects into a new Provisioning Server, strip existing eTID values. The system will then generate new UUIDs and rebuild the required associations.
Decommissioning an Endpoint The correct procedure is to delete the acquired Endpoint object to trigger automatic cleanup. If an endpoint was decommissioned without following this procedure:
3. Troubleshooting Inaccessible Accounts If accounts cannot be accessed when listing accounts for a Provisioning Global User, ensure they still exist on the native endpoint system. Run an Explore/Correlate to synchronize the data and resolve discrepancies.