Hi,
Can we restrict attribute sync happening for accounts which are correlated to a specific Identity Profile.
Hi,
Can we restrict attribute sync happening for accounts which are correlated to a specific Identity Profile.
Hi,
I’m not sure to well understand but to set which attributes you want to synchronize betwen ISC and the target application you have to check/uncheck them in Synchronize Attributes part in your Source.
Hi Chandra,
Can you explain a bit more why you would only want to synchronize attributes to some identity profiles?
The simplest way I can think of is splitting your application into multiple sources (1 for each profile).
Thanks,
Margo
@chandramohan27 Could you provide a more detailed explanation of the use case? Based on my understanding of your statement, if you have an Identity Profile called ‘ABC’ that creates identities in ISC, and these identities have access to multiple target sources such as ‘App1’, ‘App2’, and ‘App3’ (correlated accounts), then the attribute synchronization will only occur on the sources where it has been configured. This is OOTB behavior.
Hi Chandra,
I would need more information but imagine this could be possible if the identity attribute is not populated in the other identity profile.
Hi @chandramohan27 , I think that’s possible, by creating another identity attribute and populating the value only to that specific Identity profile using either directly from authoritative source or transform.
In Create provisioning profile either you can map that attribute directly or use a transform to populate the attribute.
Then in attribute sync config, check only the attribute that you have created and populated for that specific identity profile and leave the other blank.
Thanks
V
Let me add more information to this use case.
I have 2 Identity profiles in IDN [1 from Workday as Auth source, other one Delimited file as Auth]. Lets Say I have 20 accounts in SAP source, 10 accounts were correlated with Identities from Workday Profile and other 10 are correlated with identities from Delimited source profile. Now I want to stop attribute sync for accounts that are correlated with Delimited source profile.
Thanks.
Hi Chandra,
I don’t believe there is a way that you can configured this OOTB.
Here are a couple approaches to consider:
I’d lean towards the first unless anyone has another idea. Attribute sync is only supported when it is mapped to a create profile directly from an identity attribute - using transforms in this scenario will not work
@chandramohan27 @margocbain ,
Correct, this is bit difficult to control/restrict Attribute Sync on the basis of some condition. I am not sure but can we do this with account update policy? Just another thought.
This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.