while creating a source how the source will decide for which identity profile it is mapping? let say we have multiple identity profiles with its respective multiple authoritative sources, but while creating non-authoritative sources how it maps? kindly help on this what is the sequence/process or is there a way to select identity profile while creating non authoritative source. even each identity profile has LCS how exactly maps is so confusing
This is duplicate of Where to select identity profile while creating a source? - Identity Security Cloud (ISC) / ISC Discussion and Questions - SailPoint Developer Community can be closed.
Hi @shaffusailpoint ,
You can select create an identity profile for a source in Identity Management > Identity Profiles > Create New
Note that you will be able to create only one identity profile for each source but you will be able to map the attributes present in it from different sources
Since non-authoritative sources do not create or manage the core identity records, they do not influence the lifecycle states of identities.
The lifecycle states and identity profiles remain the responsibility of the authoritative sources.
Thanks !
Thank you kumar. But what I confused is what is relationship between authoritative source and non-authoritative sources?
A authoritative source consists of Authoritative sources are the primary systems that create, manage, and maintain identity records for users.
But where as ,
Non-authoritative sources are systems of interest from an access management perspective, where your users do their work. IdentityNow needs to know which identities have access to these systems (accounts) and what they can do with that access (entitlements) to help you manage them effectively.
what if the account does not exist in auth source, does ISC still create an account and manages accesses in non auth sources?
Yes, IdentityNow can create an account and manage accesses in non-authoritative sources even if the account does not exist in the authoritative source.
It will be treated as an uncorrelated source.
If the user comes into ISC via auth source, an identity cube will made for the user (only if the auth. source is associated with identity profile). The same user has multiple accounts like salesforce or AD (non-auth. source), if you try to onboard this, via correlation future it search for identity cube of the user and correlates with that.
If there is a user in non-auth. source like AD and salesforce, but he is not in auth source, the identity cube will not be generated for him. Hence, it will be treated as an uncorrelated account.
Please have a look at the below link
This looks great! thanks Gokul. other than uncorrelated it still manages accesses right for down stream accounts?
yeah. It will manage access for down stream accounts.
This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.