Create Profile Provisioning Policy Attributes
Prerequisites:
-
An OpenLDAP source has been added to your Identity Security Cloud site and accounts have been loaded.
-
The Provisioning feature must have been turned on and set up for your org.
When SailPoint provisions new accounts to an OpenLDAP direct connect source, it uses the attributes on the Create Profile page as instructions or a template for what to include in the account. This page is also referred to as the provisioning policy.
Some of the values needed to create a OpenLDAP account require a generator which compiles the appropriate attribute value based on a variety of information.
Important
This page describes the configuration of the default Create Profile. However, SailPoint recommends that you work with Services to define a Create Profile specific to your company's requirememts.
The following generators create required information for a new OpenLDAP account. The contents can be edited.
Account Attribute |
Generator |
Description |
---|---|---|
dn |
Create Unique Account ID |
This generator uses the value in the Pattern Used field to generate a unique DN for the new account. Caution
|
password |
Create Password |
This generator creates an initial password for the new account that matches the password policy assigned with the associated OpenLDAP source. |
CN |
Display Name |
Full name of the user to be created. For example, Martin K Smith. |
givenName |
First Name |
First name of the user to be created. |
SN |
Last Name |
Last name of the user to be created. |
|
Create Unique LDAP Attribute |
The email ID of the user to be created. |
uid |
Create Unique LDAP Attribute |
The unique ID of the user to be created. |
Note
- You can edit some aspects of this page from the user interface. For more information, refer to Updating the Account Creation Configuration. You can also schedule regular aggregations for this source.
- The OpenLDAP connector will provision the accounts with parentheses in the Common Name (CN) within a Distinguished Name (DN).