# Get manager DN from an Identity in an Update Policy

**URL:** <https://developer.sailpoint.com/discuss/t/get-manager-dn-from-an-identity-in-an-update-policy/76984>\
**Category:** SHF Discussion and Questions\
**Tags:** transforms, identity-security-cloud\
**Created:** [August 16, 2024, 1:22pm UTC](https://developer.sailpoint.com/discuss/t/get-manager-dn-from-an-identity-in-an-update-policy/76984 "2024-08-16T13:22:02Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![rcgalvez](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@rcgalvez](https://developer.sailpoint.com/discuss/u/rcgalvez)\
**Post date:** [August 16, 2024, 1:22pm UTC](https://developer.sailpoint.com/discuss/t/get-manager-dn-from-an-identity-in-an-update-policy/76984/1 "2024-08-16T13:22:02Z")

</div>

Hi! We’re trying to get the distinguishedName of the manager of an identity. We’ve tried two ways: The first one is a simple tranfrom that gets it directly:

```auto
{ "name": "testManager",
    "type": "static",
    "attributes": {
        "managerName": "$identity.getManager().getStringAttribute(\"displayName\")",
        "value": "$managerName"
    },
    "internal": false
}

```

The problem of this transform is that it only works for identity attributes, not for account attributes. And the manager is an account attribute form the Active Directory account.

We’ve also tried to get it like this:

```auto
  
{
"name": "Test",
            "transform": {
                "attributes": {
                    "sourceName": "Active Directory source",
                    "attributeName": "givenName",
                    "accountReturnFirstLink": true,
                    "accountFilter": "(nativeIdentity.equals(\"nameofidentitty\"))"
                },
                "type": "accountAttribute"
}

```

We want to have in our Update Policy. Do you have any ideas? Thank you in advance.

---

<div class="post-metadata">

**Author:** ![sup3rmark](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/sup3rmark/32/36229_2.png) [@sup3rmark](https://developer.sailpoint.com/discuss/u/sup3rmark)\
**Post date:** [August 16, 2024, 2:25pm UTC](https://developer.sailpoint.com/discuss/t/get-manager-dn-from-an-identity-in-an-update-policy/76984/2 "2024-08-16T14:25:04Z")

</div>

Hey @rcgalvez! This is actually a perfect case for the `Get Reference Identity Attribute` primitive: [Get Reference Identity Attribute | SailPoint Developer Community](https://developer.sailpoint.com/docs/extensibility/transforms/operations/get-reference-identity-attribute)

Assuming there’s an Identity Attribute called `distinguishedName`, this should work for you:

```json
{
  "attributes": {
    "name": "Cloud Services Deployment Utility",
    "operation": "getReferenceIdentityAttribute",
    "uid": "manager",
    "attributeName": "distinguishedName"
  },
  "type": "rule",
  "name": "Get Manager DN"
}

```

_(note that `manager` is a special keyword in the `uid` field that dynamically references the manager of the current identity)_

---

<div class="post-metadata">

**Author:** ![IAMpdu](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/iampdu/32/2671_2.png) [@IAMpdu](https://developer.sailpoint.com/discuss/u/IAMpdu)\
**Post date:** [August 16, 2024, 2:57pm UTC](https://developer.sailpoint.com/discuss/t/get-manager-dn-from-an-identity-in-an-update-policy/76984/3 "2024-08-16T14:57:10Z")

</div>

Hello @rcgalvez,

You can create an identity “userdn” and add users DN then create another attribute managerDN and here is the transform to get reference from userDN attribute -

```auto
{
  
  "name": "Rule - ManagerDN",
  "type": "rule",
  "attributes": {
    "uid": "manager",
    "name": "Cloud Services Deployment Utility",
    "attributeName": "userdn",
    "operation": "getReferenceIdentityAttribute"
  },
  "internal": false
}

```

Thanks,  
IAM-PDU

---

<div class="post-metadata">

**Author:** ![rcgalvez](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@rcgalvez](https://developer.sailpoint.com/discuss/u/rcgalvez)\
**Post date:** [August 19, 2024, 12:17pm UTC](https://developer.sailpoint.com/discuss/t/get-manager-dn-from-an-identity-in-an-update-policy/76984/4 "2024-08-19T12:17:59Z")

</div>

> [@rcgalvez](#):
>
> , not for account attributes

The problem with your solution is that it only works with identity attributes. The attribute that we must get from the AD account is an accountAttribute only and that transform doesn’t work for this scenario. Please try to read carefully my post. We’re trying right now the second solution but we can’t get it to filter anything. Thank in advance.

---

<div class="post-metadata">

**Author:** ![rcgalvez](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@rcgalvez](https://developer.sailpoint.com/discuss/u/rcgalvez)\
**Post date:** [August 19, 2024, 12:18pm UTC](https://developer.sailpoint.com/discuss/t/get-manager-dn-from-an-identity-in-an-update-policy/76984/5 "2024-08-19T12:18:47Z")

</div>

The problem with your solution is that it only works with identity attributes. The attribute that we must get from the AD account is an accountAttribute only and that transform doesn’t work for this scenario. Please try to read carefully my post. We’re trying right now the second solution but we can’t get it to filter anything. Thank in advance.

---

<div class="post-metadata">

**Author:** ![sup3rmark](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/sup3rmark/32/36229_2.png) [@sup3rmark](https://developer.sailpoint.com/discuss/u/sup3rmark)\
**Post date:** [August 19, 2024, 12:31pm UTC](https://developer.sailpoint.com/discuss/t/get-manager-dn-from-an-identity-in-an-update-policy/76984/6 "2024-08-19T12:31:20Z")

</div>

You’d just create an additional Identity Attribute that pulls in the user’s distinguishedName from AD, and reference that attribute in the transform.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [October 18, 2024, 12:31pm UTC](https://developer.sailpoint.com/discuss/t/get-manager-dn-from-an-identity-in-an-update-policy/76984/7 "2024-10-18T12:31:29Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
