Native OU movement in Active Directory

Is there any Active Directory Connector Update that includes a fix to how a Identity Security Cloud Tenant handles native ou-movement of users?

In the best practice regarding moving users between OUs it is said that “…moving users in AD appears to the system like deleting and adding separate accounts. In addition, IdentityNow cannot simply update the distinguishedName since it is an AD identifier.”

I still gave it a try and it worked for me and the DN is getting updated, the object SID and guid are still the same and my Tenant is able to handle these changes.

I did not see any information about an update regarding this and wanted to ask if someone is able to provide me with more information.

Can you check what was the account id before and after OU move?

The Account ID stays the same, I moved the user again, aggregated and then checked the id again

when you say Account ID? can you explain what remained same. I am referring to ISC account ID> please check again. if you click on the account below will be the URL. I am checking on the account_id here …. does it remain same?

https://tenant-sb.identitynow.com/ui/a/admin/identities/<<identity_id>>/details/accounts/<<account_id>>

I mean the id that is displayed when I search for the identity in {tenant}/ui/a/admin/connections/sources/{source-id}/view/accounts. The id can either be viewed in the table or when accessing the account to view the account attributes. So what I mean by id is the account id that SailPoint gives to the (AD) account.

if you are using AC_NewParent for your OU move then you are good. if not i am pretty sure the account id will change unless something changed on ISC recently. in any case, since account id is not changing after OU move, i dont think there is any issue in your case .

Currently I am not using any rules, so it cannot be due to me using AC_NewParent. I will look again in the new releases something might have changed.

Regarding AC_NewParent:

I know how it is used through a before provisioning rule, but how is it used during provisioning? can it be set in a Before- or After connector rule?

The doc you referred, has the rule sample. Take a look at it. Yes. It can be set in the BPR.

1 Like