Correlation Tab

Use the correlation tab to configure how application accounts are assigned to identities within IdentityIQ using account and identity information.

To configure Account Correlation you can select an existing correlation configuration from the list or create a new configuration using the correlation wizard. The correlation wizard walks you through both attribute and condition based correlation.

In the manager correlation section, configure how assigned managers should be resolved to identities using existing information.

Attribute Based Correlation

Use attributes of the application's account to find identities based on attribute values stored on Identity objects. This is how accounts are typically correlated to Identities. For example, you can correlate the application's account attribute "mail" with an identity's attribute "email."

Condition Based Correlation

Assigns application accounts to existing identities by defining attribute conditions. Service and Administrator accounts might be handled using condition based correlation. For example, the root account on Unix typically does not have any identifying attributes that can help when trying correlate it to an existing identity. In cases where the account owner is known because they are the application owner, a direct mapping can be used.

To configure Manager Correlation you must select two attributes, the Application Attribute and the Identity Attribute.

Application Attribute

The name of the application's account attribute that holds the reference to the manager.

Identity Attribute

The name of the identity attribute to use when searching for managers.

For example, if the application has an attribute managerEmail with the value set as the email address of the manager of every user with an account on the application, and you have an identity attribute email configured within IdentityIQ with the value set as the email address for every identity cube, you would correlate the application attribute managerEmail with the identity attribute email to perform manager correlation.