Symantec IGA

 View Only
  • 1.  IdG - Custom Account Attributes on Certification

    Posted Jun 22, 2021 05:17 PM
    Hello,

    I'd like to know if it's possible to open an Account Certification with custom attributes on the Identity Portal user view.

    For example, I have a custom JCS endpoint configured on my Universe with the following account mapping:

    This is a custom JCS database connector, importing accounts for IdG (The Users are imported from IdM)

    I'd like that this attributes show up for the user who is certifying the account on IdP:
    As you can see, no custom attribute is display.

    I've checked the Account Certification Template, but no custom attribute is available to configure on the Display tab:

    It's possible to make this custom attribute to show up for the final user?


    Regards


  • 2.  RE: IdG - Custom Account Attributes on Certification

    Posted Jun 23, 2021 01:18 PM
    If you don't need the automated remediation (I am not sure that works with Account certifications anyway), then import the accounts config into a new universe,  In the new universe, you can map all attributes.


  • 3.  RE: IdG - Custom Account Attributes on Certification

    Posted Jun 23, 2021 04:07 PM
    Hi all,

    Just my input here.

    Account certification is not doing anything on export/remediation.

    ------------------------------
    Senior Consultant/Architect- CA Identity Suite SME
    Topspin Technologies (Partner)
    ------------------------------



  • 4.  RE: IdG - Custom Account Attributes on Certification

    Posted Jun 24, 2021 08:45 AM
    Charly,

    Thanks for the tip, that's not the idea on this case.

    Regards,


  • 5.  RE: IdG - Custom Account Attributes on Certification

    Posted Jun 24, 2021 08:44 AM
    Ricky,

    Are you saying to import the accounts in another universe as Users?

    Regards,


  • 6.  RE: IdG - Custom Account Attributes on Certification

    Posted Jun 25, 2021 10:00 AM

    Assuming the accounts are from an IDM import, in the IDM import you have a configuration named something like, "IDM_master_accounts".  Here you have global users as users and the accounts linked to the global user as resources.  This is likely exactly what you are trying to certify.  

    In your new universe, your import connector is type 'database configuration' specifying "IDM_master_accounts" as the configuration to import. 

    In this imported dataset, the Users are the IM global users and their Accounts are represented as Resources (the same as the dataset you pulled from).  Now if you do a regular "User Certification" in this new universe, you are not limited in the attributes you can show to the end user and have other options as well.