# Usernamegeneration

**URL:** <https://developer.sailpoint.com/discuss/t/usernamegeneration/70518>\
**Category:** SHF Discussion and Questions\
**Tags:** transforms, provisioning, identity-security-cloud\
**Created:** [July 1, 2024, 8:50pm UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518 "2024-07-01T20:50:51Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![anandan07](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anandan07](https://developer.sailpoint.com/discuss/u/anandan07)\
**Post date:** [July 1, 2024, 8:50pm UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/1 "2024-07-01T20:50:52Z")

</div>

I am getting below error when generating user id using usernamegenerator in AD.  
Calling getObject for objectType ‘account’ using id ‘XXXX’ and options ‘{cloudConfigOverrides={aggregateTimeout=30, disablePooling=true, timeout=30}}’ on source ‘Test\_AD [source]’. Exception: sailpoint.connector.ConnectorException: [InvalidConfigurationException] [Error details] Required string attribute ‘User’ is not defined.It must have a valid value.  
I already have “objectType - User” added in the provisioning policy. I have tried account id as DN, and SamAccountName but the error is same. Any help why its searching for string using “account” instead of “user”

---

<div class="post-metadata">

**Author:** ![naveenkarthikkrk](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/naveenkarthikkrk/32/11531_2.png) [@naveenkarthikkrk](https://developer.sailpoint.com/discuss/u/naveenkarthikkrk)\
**Post date:** [July 2, 2024, 2:00am UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/2 "2024-07-02T02:00:58Z")

</div>

Hi @anandan07 ,  
Are you using userNameGenerator for DN or SamAccountName .UsernameGenerator rule has to be used only for the nativeIdentity (accountId in any source) Here it can only be used in DN.Check that in configuration.Try to check the configuration in the source and try to increase the timeout .  
Thanks,

---

<div class="post-metadata">

**Author:** ![vguleria](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vguleria/32/7884_2.png) [@vguleria](https://developer.sailpoint.com/discuss/u/vguleria)\
**Post date:** [July 2, 2024, 8:14am UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/3 "2024-07-02T08:14:39Z")

</div>

Hi @anandan07,

I see the error is for attribute user which seems like a custom attribute. Can you please confirm for which attribute do you need the unique value. If it is a user, then i think you can use it but in order to make the uniqueness check here, you will need to make this attribute searcheable.

I request to provide some more information, so that we can assist you better.

Thank You.  
Regards  
Vikas.

---

<div class="post-metadata">

**Author:** ![anandan07](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anandan07](https://developer.sailpoint.com/discuss/u/anandan07)\
**Post date:** [July 2, 2024, 10:27am UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/4 "2024-07-02T10:27:07Z")

</div>

First i used to generate unique DN using username generator having DN as the account ID. Got the same error. Then tried changing account id to Samaccountname and tried generating samaccountname the error is same.  
If I hard code the value in the provisining profile as static and trigger provisioning it works fine.

---

<div class="post-metadata">

**Author:** ![anandan07](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anandan07](https://developer.sailpoint.com/discuss/u/anandan07)\
**Post date:** [July 2, 2024, 10:29am UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/5 "2024-07-02T10:29:50Z")

</div>

There is no custom attribute “User”. Only ObjectType attribute has User as the value. and even if i make sourcecheck to false i am getting the same error. I tried with accountid as DN and used the transform dint work and make account id as samaccountname and tested the transform for samaccountname same error “Calling getObject for objectType ‘account’ using id ‘XXXX’ and options ‘{cloudConfigOverrides={aggregateTimeout=30, disablePooling=true, timeout=30}}’ on source ‘Test\_AD [source]’. Exception: sailpoint.connector.ConnectorException: [InvalidConfigurationException] [Error details] Required string attribute ‘User’ is not defined.It must have a valid value.” – not sure from where its getting the objectType account. in provisining profile i have objecttype as user

---

<div class="post-metadata">

**Author:** ![bcariaga](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/bcariaga/32/1890_2.png) [@bcariaga](https://developer.sailpoint.com/discuss/u/bcariaga)\
**Post date:** [July 2, 2024, 12:34pm UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/6 "2024-07-02T12:34:18Z")

</div>

I did find another post with the same issue:

> [@Active Directory Create Account failing because of undefined required string attribute 'User'](https://developer.sailpoint.com/discuss/t/active-directory-create-account-failing-because-of-undefined-required-string-attribute-user/22436/14):
>
> Hi Aishwarya, I was not able to, unfortunately. I will be trying to use a new AD connector soon but for now I haven’t been able to find any fix.

It seems recreating the source solved this before.

@anandan07 Have you tried using the Create Unique LDAP Attribute instead?

---

<div class="post-metadata">

**Author:** ![anandan07](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anandan07](https://developer.sailpoint.com/discuss/u/anandan07)\
**Post date:** [July 9, 2024, 5:48pm UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/7 "2024-07-09T17:48:40Z")

</div>

> [@naveenkarthikkrk](#):
>
> userNameGenerator

I am using it for both SamAccountName and DN… error is same

---

<div class="post-metadata">

**Author:** ![anandan07](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anandan07](https://developer.sailpoint.com/discuss/u/anandan07)\
**Post date:** [July 9, 2024, 5:52pm UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/8 "2024-07-09T17:52:23Z")

</div>

> [@vguleria](#):
>
> nk you can use it but in order to make the uniq

I did not create any custom attribute as user… i want to generate unique id for samaccountname as i got this error i tried the same with DN with minor modification still the error is same

---

<div class="post-metadata">

**Author:** ![anandan07](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anandan07](https://developer.sailpoint.com/discuss/u/anandan07)\
**Post date:** [July 9, 2024, 5:53pm UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/9 "2024-07-09T17:53:21Z")

</div>

Yes i tried user create unique LDAP attribute it worked fine. I tried creating new source still same error

---

<div class="post-metadata">

**Author:** ![bcariaga](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/bcariaga/32/1890_2.png) [@bcariaga](https://developer.sailpoint.com/discuss/u/bcariaga)\
**Post date:** [July 9, 2024, 6:02pm UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/10 "2024-07-09T18:02:48Z")

</div>

Can you please share your create plan or specifically the transforms for these?

One way to troubleshoot would be to start with a very basic create plan and start adding attributes back in to identify where the error is coming from.

Have you made any changes to the account schema out of the box? According to the connector documentation, it is advised against changing account name and account id from the OOB configuration.

I’ve used the username generator to create DN and then unique ldap attributes for sAMAccountName. Is there a reason Unique LDAP Attribute won’t work for your use case?

---

<div class="post-metadata">

**Author:** ![vguleria](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vguleria/32/7884_2.png) [@vguleria](https://developer.sailpoint.com/discuss/u/vguleria)\
**Post date:** [July 10, 2024, 7:28am UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/11 "2024-07-10T07:28:59Z")

</div>

Hi @anandan07

Can you please share the screenshot of the create provisioing policy so that we can verify what is the error.

Thank You.  
Regards  
Vikas

---

<div class="post-metadata">

**Author:** ![anandan07](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anandan07](https://developer.sailpoint.com/discuss/u/anandan07)\
**Post date:** [July 11, 2024, 2:06pm UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/12 "2024-07-11T14:06:08Z")

</div>

Yes, I tried creating user with some hardcoded value (static) for samaccountname and DN it works fine. When using transform then getting the error  
transform for samaccountname –  
{  
“name”: “sAMAccountName”,  
“transform”: {  
“type”: “usernameGenerator”,  
“attributes”: {  
“sourceCheck”: true,  
“patterns”: [“$fn$ln”,  
“$fn$ln${uniqueCounter}”],  
“fn”: {  
“type”: “identityAttribute”,  
“attributes”: {  
“name”: “firstname”  
}  
},  
“ln”: {  
“type”: “identityAttribute”,  
“attributes”: {  
“name”: “lastname”  
}  
}  
}  
},  
“attributes”: {  
“cloudMaxSize”: “12”,  
“cloudMaxUniqueChecks”: “2”,  
“cloudRequired”: “true”  
},  
“isRequired”: false,  
“type”: “string”,  
“isMultiValued”: false  
}

---

<div class="post-metadata">

**Author:** ![anandan07](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anandan07](https://developer.sailpoint.com/discuss/u/anandan07)\
**Post date:** [July 11, 2024, 2:09pm UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/13 "2024-07-11T14:09:39Z")

</div>

create provisioning policy

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/a/ad324b86d21b8306dc26447795093dfdf70a6707.png)

---

<div class="post-metadata">

**Author:** ![Sivakrishna1993](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/sivakrishna1993/32/25424_2.png) [@Sivakrishna1993](https://developer.sailpoint.com/discuss/u/Sivakrishna1993)\
**Post date:** [July 14, 2024, 4:31pm UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/14 "2024-07-14T16:31:26Z")

</div>

Hi

Have you checked your dn value, correct or not?

Thanks  
Siva.K

---

<div class="post-metadata">

**Author:** ![anandan07](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anandan07](https://developer.sailpoint.com/discuss/u/anandan07)\
**Post date:** [July 15, 2024, 4:05pm UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/15 "2024-07-15T16:05:53Z")

</div>

DN value is correct…and if i hard code the samaccountname for ex - making it static and giving a value and tried provisioning it works with the same DN.but if I use uniqueaccount generation transform for samaccount name it failes.

---

<div class="post-metadata">

**Author:** ![Sivakrishna1993](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/sivakrishna1993/32/25424_2.png) [@Sivakrishna1993](https://developer.sailpoint.com/discuss/u/Sivakrishna1993)\
**Post date:** [July 15, 2024, 4:45pm UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/16 "2024-07-15T16:45:41Z")

</div>

Hi

Have you checked your transform output? write this transform in identity profile and check the value.

thanks,  
Siva.K

---

<div class="post-metadata">

**Author:** ![PhilRawlings1](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/philrawlings1/32/37266_2.png) [@PhilRawlings1](https://developer.sailpoint.com/discuss/u/PhilRawlings1)\
**Post date:** [July 16, 2024, 8:44am UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/17 "2024-07-16T08:44:10Z")

</div>

How long are the values for the first and last name?  
You have set “cloudMaxSixe” to 12, so if those values are longer than 11 characters (you need one for the counter) the transform will likely fail

Phil

---

<div class="post-metadata">

**Author:** ![anandan07](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anandan07](https://developer.sailpoint.com/discuss/u/anandan07)\
**Post date:** [July 16, 2024, 1:59pm UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/18 "2024-07-16T13:59:46Z")

</div>

yes transform is working fine. i have used the transform in identity profile and also in other application to generate some ids.

---

<div class="post-metadata">

**Author:** ![anandan07](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anandan07](https://developer.sailpoint.com/discuss/u/anandan07)\
**Post date:** [July 16, 2024, 2:00pm UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/19 "2024-07-16T14:00:47Z")

</div>

Actually its not the transform issue. As the transform works fine with other applications. ex OKTA. the issue is only with AD source connector

---

<div class="post-metadata">

**Author:** ![Sivakrishna1993](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/sivakrishna1993/32/25424_2.png) [@Sivakrishna1993](https://developer.sailpoint.com/discuss/u/Sivakrishna1993)\
**Post date:** [July 16, 2024, 4:08pm UTC](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518/20 "2024-07-16T16:08:17Z")

</div>

> [@anandan07](#):
>
> [Error details] Required string attribute ‘User’ is not defined. It must have a valid value.

Better reconfigure with new AD source. it will work.

[Next page](https://developer.sailpoint.com/discuss/t/usernamegeneration/70518.md?page=2)
