ISC RACF connector - Create Account as protected user without password / NOPASSWORD

Hi all,

we are configuring the RACF connector in SailPoint Identity Security Cloud and we have a question about the Create Account provisioning policy.

Our RACF requirement is that accounts should normally be created as protected users, without assigning a password during the standard account creation process.

In RACF terms, the expected result should be equivalent to creating the user with NOPASSWORD / protected user behavior.

In the SailPoint RACF connector documentation, the Create Profile Provisioning Policy Attributes page lists the following relevant generators/attributes:

- USER_ID

- password

- UG_DEF

The documentation describes the password generator as “The password for RACF”.

This creates a doubt for us, because our RACF process requires accounts to be created without a password, as protected users. Only in rare cases, if a user needs specific interactive access, the password is handled manually by the mainframe team outside the standard SailPoint create account flow.

Our questions are:

1. Does the ISC RACF connector support creating a RACF account as a protected user without providing a password?

2. If yes, what is the recommended configuration in the Create Account provisioning policy?

  • Should the password generator be disabled?

  • Should it be left empty/null?

  • Is there a specific attribute or connector configuration to send NOPASSWORD?

3. If the password field is mandatory in the Create Account policy, what is the recommended approach for customers whose RACF account creation process requires protected users by default?

4. If we provide a password just to satisfy the required field, would the resulting RACF user no longer be considered protected? We want to avoid creating accounts that are not aligned with the RACF security model.

Any guidance or confirmed implementation pattern for this scenario would be appreciated.

Thanks.

Hi, I don’t have a live RACF instance connected to ISC on which to test this, but you can probably use this knowledge from the Compass article: basically, the docs are stating you can keep the password blank, and the Attribute Requests will take care of themselves. You might be able to dump out the AccountRequests to verify what’s happening under the hood

https://community.sailpoint.com/t5/Connector-Directory/Mainframe-Integration-Modules/ta-p/78846#toc-hId-78846-h_2742562172561581507204348

Password for the user account specified in Username.

NOTE: Special type of user as authentication user is supported in application configuration for Mainframe Connector). For such type of users defined, password field must be kept blank. The special type of users are as follows:

  • Protected for RACF

  • Restricted for ACF2 and

  • With no Password (NOPW) for CA-Top Secret