Source mapping Rule should not remove the value is account is missing

Hi Team

We are trying to set an identity attribute based on AD account attribute with below configurations.

Identity attribute: litholduser
ADaccount attribute: msExchUSerHoldPolicies
Identity mapping: Source mapping -> ApplicationRule->if AD attribute contains the text "unlimit", then set the identity attribute to true.

We have a scenario where the accounts contains “unlimit” would be removed from the identity. In that case, as per source mapping, the value “true” in identity attribute is getting removed. Is there a way to maintain the value in the identity attribute even if the AD account got removed from the identity cube?

Thanks

Divya M

Hello Divya. If this happens during a Refresh Identity Cube task with only Refresh identity attributes enabled, it matches a defect SailPoint fixed in IdentityIQ 8.5 under IIQTC-626. The defect caused an identity attribute value to be removed when the identity no longer had an account for the associated application source-mapping rule.

Could you confirm your IIQ version, patch level, and the options enabled on the refresh task?

If you are on 8.5 or later and the same scenario still reproduces, I would open a SailPoint Support case and reference IIQTC-626. If you are below 8.5, upgrading would be the cleanest fix, or you could check with Support whether the fix is available for your current version.

For an older version, a possible workaround is to add a second source mapping below the existing AD Application Rule. Configure it as a Global Rule that returns the current identity attribute value:

return identity.getAttribute(attributeDefinition.getName());

IIQ evaluates source mappings in their configured order and continues to the next source when the primary source cannot provide the required value. When the AD link is removed, the fallback rule returns the existing identity value instead of allowing it to be cleared. This same approach was confirmed working in a similar IIQ 8.3 case.

Also make sure the AD Application Rule returns an explicit "false" when the account exists but msExchUserHoldPolicies does not contain "unlimit". Returning null in that situation could cause the fallback rule to retain an older "true" value even though the hold policy no longer applies.

Thank you Harish. Our version of IIQ is 8.4P2. I will check with support team if any fix is available.

I will try this too. Thank you.