# ManagedBy Attribute in AD

**URL:** <https://developer.sailpoint.com/discuss/t/managedby-attribute-in-ad/116991>\
**Category:** IIQ Discussion and Questions\
**Tags:** identityiq, entitlements\
**Created:** [April 29, 2025, 3:49pm UTC](https://developer.sailpoint.com/discuss/t/managedby-attribute-in-ad/116991 "2025-04-29T15:49:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alyson\_Trad](https://avatars.discourse-cdn.com/v4/letter/a/f08c70/32.png) [@Alyson\_Trad](https://developer.sailpoint.com/discuss/u/Alyson_Trad)\
**Post date:** [April 29, 2025, 3:49pm UTC](https://developer.sailpoint.com/discuss/t/managedby-attribute-in-ad/116991/1 "2025-04-29T15:49:55Z")

</div>

## Which IIQ version are you inquiring about?

8.4p1

I am looking into the plausibility of utilizing the ManagedBy tab within Active Directory and correlating this back to the owner of an entitlement within SailPoint.  
I dont see a group correlation piece in the AD application connector at all.  
Would this need a custom rule to correlate these fields?

---

<div class="post-metadata">

**Author:** ![ajmerasunny1](https://avatars.discourse-cdn.com/v4/letter/a/3be4f8/32.png) [@ajmerasunny1](https://developer.sailpoint.com/discuss/u/ajmerasunny1)\
**Post date:** [April 29, 2025, 4:37pm UTC](https://developer.sailpoint.com/discuss/t/managedby-attribute-in-ad/116991/2 "2025-04-29T16:37:30Z")

</div>

Yes, you will have to use a custom rule to add the owner information. You can use the group refresh rule to get the managedBy field value and then use that to find the owner identitty and then set that as owner using .setOwner(identity).

Let me know if you need a sample rule or code snippet.

---

<div class="post-metadata">

**Author:** ![Alyson\_Trad](https://avatars.discourse-cdn.com/v4/letter/a/f08c70/32.png) [@Alyson\_Trad](https://developer.sailpoint.com/discuss/u/Alyson_Trad)\
**Post date:** [April 30, 2025, 3:42pm UTC](https://developer.sailpoint.com/discuss/t/managedby-attribute-in-ad/116991/3 "2025-04-30T15:42:44Z")

</div>

If you have any sample code, that would be very helpful!  
I had the initial ask flipped. We would want the ManagedBy field to drive the ownership within SailPoint. Would that be possible with a similar custom rule?

---

<div class="post-metadata">

**Author:** ![ajmerasunny1](https://avatars.discourse-cdn.com/v4/letter/a/3be4f8/32.png) [@ajmerasunny1](https://developer.sailpoint.com/discuss/u/ajmerasunny1)\
**Post date:** [April 30, 2025, 4:22pm UTC](https://developer.sailpoint.com/discuss/t/managedby-attribute-in-ad/116991/4 "2025-04-30T16:22:46Z")

</div>

Here you go

> import org.apache.commons.logging.Log;  
> import org.apache.commons.logging.LogFactory;  
> import com.client.iiq.constant.EntitlementObjectModel;  
> import com.client.iiq.constant.clientGlobalConstants;  
> import sailpoint.object.Filter;  
> import sailpoint.object.Identity;  
> import sailpoint.object.Link;  
> import sailpoint.object.ManagedAttribute;  
> import sailpoint.tools.GeneralException;  
> import sailpoint.tools.Util;  
> Log logADGroup = LogFactory.getLog(“client.rule.GroupAggregationRefresh-AD”);  
> ManagedAttribute group = (ManagedAttribute) accountGroup;  
> if (group != null) {  
> String riskLevel = (String) group.getAttribute(EntitlementObjectModel.ATT\_RISK\_LEVEL);  
> if (Util.isNullOrEmpty(riskLevel)) {  
> if (logADGroup.isTraceEnabled()) {  
> logADGroup.trace("Setting default risk level for group: " + group.getDisplayableName());  
> }  
> group.setAttribute(EntitlementObjectModel.ATT\_RISK\_LEVEL,  
> clientGlobalConstants.RISK\_LEVEL\_HIGH);  
> }  
> String managedBy = (String) group.getAttribute(“managedBy”);  
> if (managedBy != null) {  
> if (logADGroup.isTraceEnabled()) {  
> logADGroup.trace("Found managedBy: " + managedBy);  
> }  
> try {  
> Link link = context.getUniqueObject(Link.class, Filter.eq(“nativeIdentity”, managedBy));  
> if (link != null) {  
> Identity owner = link.getIdentity();  
> if (owner != null) {  
> if (logADGroup.isTraceEnabled()) {  
> logADGroup.trace("Owner: " + owner);  
> }  
> group.setOwner(owner);  
> } else {  
> logADGroup.error(“Owner returned by search is null”);  
> }  
> } else {  
> logADGroup  
> .error("Could not find identity with AD account associated with DN: " + managedBy);  
> }  
> } catch (GeneralException e) {  
> logADGroup.error(“Error retrieving owner object:”, e);  
> }  
> } else {  
> logADGroup.info(“managedBy for " + group.getDisplayableName() + " is null”);  
> }  
> } else {  
> logADGroup.error(“Group retrieved from accountGroup is null”);  
> }  
> return group;

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [June 29, 2025, 4:23pm UTC](https://developer.sailpoint.com/discuss/t/managedby-attribute-in-ad/116991/5 "2025-06-29T16:23:01Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
