Users have multiple Service Accounts tied to their account. Their email and employeeid are saved on the Service Accounts. When I send a reset password to the user it always changes the Service Account password instead of the primary account. The email went to the primary account. How do I specify the change should go to the primary account. Not quite sure where to configure this.
Please consider addressing the following when creating your topic:
What have you tried?
What errors did you face (share screenshots)?
Share the details of your efforts (code / search query, workflow json etc.)?
What is the result you are getting and what were you expecting?
Based on your post, I assume that you’re using SailPoint to reset the password for a user and that Active Directory is set up as a Pass-Thru Authentication method, which means that SailPoint password reset process can be used to change the AD account password.
I also am assuming that you have service account AD accounts linked to a real identity.
If all of the above is true, then If a multi-application source has multipleAccountPasswordSync set, all accounts on that source will accept the password change.
We just want to change the user’s primary account. We have AD set as the password store. I am thinking I can use an attribute to distinguish between the primary and service accounts. For example Service Account should not have employe type = full time. Unfortunately the service account has the user’s email and employee number.
I’d recommend splitting your service accounts and your employee accounts into two sources in this case - this should help resolve the password issues and also will prevent any attribute synchronization you may enable later from overwriting other service account attributes (in ISC attribute sync will apply to all accounts the identity has on a source) and role assignment. You can use filters for OUs or an LDAP filter to make sure one AD source only has the employees and the other has only the service accounts.
Note there is also a Machine Identity module offered by SailPoint - something to look at for the future, but the above should be able to address your issue immediately and prevent other common issues that appear when a user has multiple accounts on a source