Thanks Efren ! for the detailed solution. I was worried about using PX because then I need to directly modify AD account attributes. But as you are saying there is no harm doing it so I can use that . Mean while we have decided not to update any attribute in AD and only doing correlation just to avoid any issue but in future if needed we can do it.
Thanks
Renuka
From: CA Security Global User CommunityMessage Boards [mailto:
CommunityAdmin@communities-mail.ca.com]
Sent: Monday, April 14, 2014 12:49 PM
To:
mb_message.2252815.113130110@myca-email.ca.com
Subject: [CA IdentityMinder (formerly CA Identity Manager) General Discussion] RE: AD Attribute Synchronization
Hello
If you need to update these fields and do it without templates, try it using PolicyXpress. One idea for doing this is to create a special task such as "ModifyUsersSpecial" ... created as copy of the ModifyUser task, but not synchronize accounts and policies.
The PolicyXpress run when the "tag" of the task is "ModifyUsersSpecial" and update the fields you want from the identity to the AD. Of course, you will select all the fields that interest you only. If there are massive changes can be used "bulk load" calling the new task "ModifyUsersSpecial" ...your PolicyXpress will made the changes for you. That's other way to sync and propogate IDM attributes to AD.
This works really well, do not hesitate to try it.
I hope be useful for you
Efren
Posted by:EfrenYanez
--
CA Communities Message Boards
113132650
mb_message.2252815.113130110@myca-email.ca.com<mailto:
mb_message.2252815.113130110@myca-email.ca.com>
https://communities.ca.com