Symantec IGA

 View Only
  • 1.  Pull Manager attribute from AD

    Broadcom Employee
    Posted Sep 20, 2017 01:40 AM

    What is the best way to pull Manager attribute from AD to IdM ?



  • 2.  Re: Pull Manager attribute from AD

    Broadcom Employee
    Posted Sep 20, 2017 02:44 AM

    I believe PX, if coding needs to be avoided.

     

    Regards,

    Sumeet

     



  • 3.  Re: Pull Manager attribute from AD
    Best Answer

    Broadcom Employee
    Posted Sep 20, 2017 11:05 AM

    Hi

    policy xpress is a good suggestion. The only issue is that it is only triggered based on specific events / tasks. So what's the best way to get the AD manager attribute depends on what you need to do with it.

     

    If you want to get this manager attribute during AD explore, you can also get the AD manager attribute during the Active Directory endpoint explore and update global user fields process if you define the Endpoint Mappings between the AD manager and Global User attribute (ex. eTCustomField99). Then map that Global user attribute (eTCustomField99) with an IM attribute (for example, %STRING_00%) on your IM environment Provisioning Advanced Settings. During AD endpoint explore, the value of AD manager attribute will be taken in DN format (ex. cn=manager,ou=users,dc=forwardinc,dc=ca) and this will be propagated to Global User attribute (in this case eTCustomField99) and from there it will be propagated to IM attribute (in this case %STRING_00%). Then you will have to trigger a policy xpress when the IM attribute (%STRING_00%) is updated so that you extract only the manager userid from the DN and set %MANAGER% attribute of the user.

     

    KR
    Russi



  • 4.  Re: Pull Manager attribute from AD

    Broadcom Employee
    Posted Sep 20, 2017 01:44 PM

    That helps, thank You Sumeet and Russi.