Preserve Existing AD Description

I am working on a transform to set the AD Description but our CISO does not want the AD Description to change for users in a specific OU because they have put in there things like do not re-enable unless talking to CISO. I did LCS for like Litigation Hold, Security Hold and HR Hold as a means of knowing not to re-enable the account but he still wants what he puts in the description in AD to stay. I have the below transform to set the AD description and I have attribute sync turned on, but attribute sync is overwriting what he put in the description.

image

“name”: “SB_ADDescription”,

"type": "concat",

"attributes": {

    "values": \[

        {

            "type": "identityAttribute",

            "attributes": {

                "name": "jobTitle"

            }

        },

        " - ",

        {

            "type": "identityAttribute",

            "attributes": {

                "name": "employeeType"

            }

        }

    \]

},

"internal": false

}

With which identity attribute you have enabled the sync of description?

Here when the ad description is updated you need to make sure that you update the attribute same as what you have in AD description attribute then even if you have attribute sync it will update with the same value. Please brief me about your settings, then it will be easy to fix this problem.

What I have is a transform that concatenates the users jobtitle and employee type for the AD Description. We have three AD OUs HR Hold, Litigation Hold and Security Hold and then Lifecycle states that match them. Before if we manually placed a user in one of those OUs someone would go in and put like a comment in the AD description like Please do not enable unless talking to the CISO. With attribute sync on for AD Description it is overwriting that and our CISO doesn’t want that to happen. I want to exclude the description from getting overwritten if they are in one of those OUs.

Hi @dpowers1, the transform you are using does not have any conditional logic to control when the description gets set. You’ll need to update it to accept the user’s distinguished name (DN) as an input and add a condition that skips overwriting the description if the user is in a specific OU.

{
“name”: “Set AD Description”,
“type”: “conditional”,
“attributes”: {
“expression”: “$dn co ‘OU=First Protected OU’”,
“positiveCondition”: {
“type”: “accountAttribute”,
“attributes”: {
“sourceName”: “Active Directory”,
“attributeName”: “description”
}
},
“negativeCondition”: {
“type”: “conditional”,
“attributes”: {
“expression”: “$dn co ‘OU=Second Protected OU’”,
“positiveCondition”: {
“type”: “accountAttribute”,
“attributes”: {
“sourceName”: “Active Directory”,
“attributeName”: “description”
}
},
“negativeCondition”: {
“type”: “conditional”,
“attributes”: {
“expression”: “$dn co ‘OU=Third Protected OU’”,
“positiveCondition”: {
“type”: “accountAttribute”,
“attributes”: {
“sourceName”: “Active Directory”,
“attributeName”: “description”
}
},
“negativeCondition”: {
“type”: “concat”,
“attributes”: {
“values”: [
{
“type”: “identityAttribute”,
“attributes”: {
“name”: “jobTitle”
}
},
" - ",
{
“type”: “identityAttribute”,
“attributes”: {
“name”: “employeeType”
}
}
]
}
}
}
}
}
}
},
“input”: {
“dn”: {
“type”: “accountAttribute”,
“attributes”: {
“sourceName”: “Active Directory”,
“attributeName”: “distinguishedName”
}
}
},
“internal”: false
}

That worked but I had to modify it to use Velocity Logic because my tenant doesn’t do the co in the expression

“name”: “ADDescript_SB_Static”,

"type": "static",

"attributes": {

    "dn": {

        "type": "accountAttribute",

        "attributes": {

            "sourceName": "AD",

            "attributeName": "distinguishedName"

        }

    },

    "currentDescription": {

        "type": "accountAttribute",

        "attributes": {

            "sourceName": "AD",

            "attributeName": "description"

        }

    },

    "newDescription": {

        "type": "concat",

        "attributes": {

            "values": \[

                {

                    "type": "identityAttribute",

                    "attributes": {

                        "name": "jobTitle"

                    }

                },

                " - ",

                {

                    "type": "identityAttribute",

                    "attributes": {

                        "name": "employeeType"

                    }

                }

            \]

        }

    },

    "value": "#if($dn && ($dn.contains('OU=Security Hold') || $dn.contains('OU=Litigation Hold') || $dn.contains('OU=HR Hold')))$currentDescription#{else}$newDescription#end"

},

"internal": false

}