We have a requirement to enable sync for attribute - distinguishedName which is from AD source, and in create account section of AD this is configured in a static way is it possible to enable sync for this attribute in any other way.
Hi Chandra,
To enable attribute synchronization, it is mandatory that the attribute is configured as an Identity Attribute. This is because the concept of attribute synchronization is to maintain the data from the Identity Cube as the source of truth to be propagated across connected sources.
Attribute synchronization ensures that account data on a source remains consistent with identity data in Identity Security Cloud. It uses identity information to keep data aligned across multiple systems in your enterprise.
Refers to Attribute Sync for more info.
Thanks Maria.
Is there any other way to implement this one
You need to be aware that distinguishedName is the Account ID for Accounts in the AD Source. That means if you were to directly change the DN, ISC will think the account has been deleted and a new one created.
See Best Practices: Active Directory Account Moves - Compass for details on what you want to achieve.
This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.