AD Attribute Sync is Not Working

:bangbang: Please be sure you’ve read the docs and API specs before asking for help. Also, please be sure you’ve searched the forum for your answer before you create a new topic.

  1. We need to update two AD attributes: DistinguishedName and workMail.

  2. These attribute values are coming from another AD source.

  3. The values from that source are showing correctly in the Identity system.

  4. We are trying to sync these Identity values to our AD.

  5. However, during the sync process, these two attributes are not getting updated in our AD.

Hi @gbalag

Is there any failure by any chance? can you search the user in “Search” tab with its name as “John Doe” and look for account activity, if you find any Update Account entry check for any failure or its values if everything looks good

Hi @rpriya ,
I am not seeing any failures in Account Activity level in search Tab for the user which created

Do you see any entry and is the plan built appropriately? Try “Synchronize Attributes” on Identity level and check account activity again

HI @gbalag So many questions…

Can you start with posting your create account profile for the CyberArk AD Source.

Bear in mind that if you are using distinguishedName as the Account ID in the target Source then Attribute Sync is not your friend here, you will need to make use of AC_NewParent and AC_NewName.

Is workMail a modified schema attribute in your AD?

You really have 2 AD sources with the same Domain Name?

You appear to be populating an email address into physicalDeliveryOfficeName.