We are trying to set an identity attribute based on AD account attribute with below configurations.
Identity attribute: litholduser
ADaccount attribute: msExchUSerHoldPolicies
Identity mapping: Source mapping -> ApplicationRule->if AD attribute contains the text "unlimit", then set the identity attribute to true.
We have a scenario where the accounts contains “unlimit” would be removed from the identity. In that case, as per source mapping, the value “true” in identity attribute is getting removed. Is there a way to maintain the value in the identity attribute even if the AD account got removed from the identity cube?
Hello Divya. If this happens during a Refresh Identity Cube task with only Refresh identity attributes enabled, it matches a defect SailPoint fixed in IdentityIQ 8.5 under IIQTC-626. The defect caused an identity attribute value to be removed when the identity no longer had an account for the associated application source-mapping rule.
Could you confirm your IIQ version, patch level, and the options enabled on the refresh task?
If you are on 8.5 or later and the same scenario still reproduces, I would open a SailPoint Support case and reference IIQTC-626. If you are below 8.5, upgrading would be the cleanest fix, or you could check with Support whether the fix is available for your current version.
For an older version, a possible workaround is to add a second source mapping below the existing AD Application Rule. Configure it as a Global Rule that returns the current identity attribute value:
Also make sure the AD Application Rule returns an explicit "false" when the account exists but msExchUserHoldPolicies does not contain "unlimit". Returning null in that situation could cause the fallback rule to retain an older "true" value even though the hold policy no longer applies.