Symantec IGA

  • 1.  AD Attribute Synchronization

    Posted Mar 25, 2014 12:15 PM

    Hi,

    I did following for Initial upload process for AD.

    - Created IDM User and Autocorrelated /Corelated IDM user with existing AD User.

    - Weak Sync on Template as Dont want to update Groupmembership.Even Strong Sync applies only on multiattribute like groupmembership.

    My Question is how can i modify all profile attribute pushed from IDM to AD like organization data and Contact details ?that means synch IDM user attibutes to AD attributes.

    Only Solution i could see is create an IDM user with bare minimum attributes and then After correlation Modify that user with all attributes and it will change all attribute in AD .

    Is there any other way to sync/Overwrite/propogate IDM attributes to AD ? 

    Thanks



  • 2.  RE: AD Attribute Synchronization

     
    Posted Mar 28, 2014 03:08 PM
    renus:

    Hi,

    I did following for Initial upload process for AD.

    - Created IDM User and Autocorrelated /Corelated IDM user with existing AD User.

    - Weak Sync on Template as Dont want to update Groupmembership.Even Strong Sync applies only on multiattribute like groupmembership.

    My Question is how can i modify all profile attribute pushed from IDM to AD like organization data and Contact details ?that means synch IDM user attibutes to AD attributes.

    Only Solution i could see is create an IDM user with bare minimum attributes and then After correlation Modify that user with all attributes and it will change all attribute in AD .

    Is there any other way to sync/Overwrite/propogate IDM attributes to AD ? 

    Thanks

     

     

     


    Hi All,

    Any suggestions here for this member?

    Thanks!

    Chris



  • 3.  RE: AD Attribute Synchronization

    Posted Apr 07, 2014 01:59 AM

    Hi,

    Any solution to this would be of great interest to me as well. We have many problems with this today. The only solution we have found is to make a 'fake' change in the AD templates (do no propagate this change to the accounts), then change the template attributes back again. You may then chose to propagate values for these attributes to all AD accounts using this template.

    This is by no means a very good solution, but it works.

     

    Regards,

    Mikael Granhaug



  • 4.  RE: AD Attribute Synchronization
    Best Answer

    Posted Apr 14, 2014 12:49 PM

    Hello

    If you need to update these fields and do it without templates, try it using PolicyXpress. One idea for doing this is to create a special task such as "ModifyUsersSpecial" ... created as copy of the ModifyUser task, but not synchronize accounts and policies.

    The PolicyXpress run when the "tag" of the task is "ModifyUsersSpecial" and update the fields you want from the identity to the AD. Of course, you will select all the fields that interest you only.    If there are massive changes  can be used "bulk load" calling the new task "ModifyUsersSpecial" ...your PolicyXpress will made the changes for you.  That's other way to sync and propogate IDM attributes to AD.

    This works really well, do not hesitate to try it.

    I hope be useful for you

    Efren



  • 5.  RE: [CA IdentityMinder (formerly CA Identity Manager) General Discussion] R

    Posted Apr 14, 2014 12:57 PM
    Thanks Efren ! for the detailed solution. I was worried about using PX because then I need to directly modify AD account attributes. But as you are saying there is no harm doing it so I can use that . Mean while we have decided not to update any attribute in AD and only doing correlation just to avoid any issue but in future if needed we can do it.

    Thanks

    Renuka

    From: CA Security Global User CommunityMessage Boards [mailto:CommunityAdmin@communities-mail.ca.com]
    Sent: Monday, April 14, 2014 12:49 PM
    To: mb_message.2252815.113130110@myca-email.ca.com
    Subject: [CA IdentityMinder (formerly CA Identity Manager) General Discussion] RE: AD Attribute Synchronization


    Hello

    If you need to update these fields and do it without templates, try it using PolicyXpress. One idea for doing this is to create a special task such as "ModifyUsersSpecial" ... created as copy of the ModifyUser task, but not synchronize accounts and policies.

    The PolicyXpress run when the "tag" of the task is "ModifyUsersSpecial" and update the fields you want from the identity to the AD. Of course, you will select all the fields that interest you only. If there are massive changes can be used "bulk load" calling the new task "ModifyUsersSpecial" ...your PolicyXpress will made the changes for you. That's other way to sync and propogate IDM attributes to AD.

    This works really well, do not hesitate to try it.

    I hope be useful for you

    Efren
    Posted by:EfrenYanez
    --
    CA Communities Message Boards
    113132650
    mb_message.2252815.113130110@myca-email.ca.com<mailto:mb_message.2252815.113130110@myca-email.ca.com>
    https://communities.ca.com