Ответсообщение недоступно
To populate a value on existing Active Directory accounts that currently have a blank attribute in SailPoint Identity Security Cloud (ISC), use Attribute Sync.
Attribute Sync is the standard, supported way to push identity attribute values to existing correlated accounts on a source (including AD). It only applies to existing correlated accounts and requires the account attribute to be mapped *directly from an Identity Attribute* in the source’s Create Account definition.
### Steps to Configure and Apply
1. Ensure the desired value exists on an Identity Attribute
- Create a new Identity Attribute (or reuse an existing one) if needed.
- Map it in the relevant Identity Profile so it holds the value you want to push (via authoritative source mapping, transform, static value, firstValid, etc.).
2. Map it in the AD source Create Account profile
- Go to Admin > Connections > Sources → select your Active Directory source.
- Under Account Management, select Create Account.
- Map the target AD account attribute to the Identity Attribute (mapping type = Identity Attribute).
- Save.
(Static values or generators alone generally do not participate in Attribute Sync for ongoing/existing-account updates.)
3. Enable Attribute Sync for the attribute
- In the same source, go to Account Management > Attribute Sync.
- In the “Sync with Identity” column, select the checkbox for the relevant attribute.
- Save.
4. Trigger the update for existing accounts
- On the Attribute Sync page, click Sync to run a bulk attribute sync for all accounts on the source.
- This is intended for initial application of a new sync configuration.
- Limited to 3 full syncs per source in a 24-hour period.
- For individual identities: Admin > Identity Management > Identities → select the identity → Actions > Synchronize Attributes.
Once configured, Attribute Sync will detect mismatches (blank on the account vs. a value on the identity) and provision the update to AD. Future changes to the identity attribute will also sync automatically.
### Important Notes and Caveats
- Attribute Sync only works for attributes that are mapped directly from an Identity Attribute in the Create Account definition. Values coming solely from transforms/static logic inside the provisioning policy often will not trigger properly for updates (especially nulls or previously blank fields).
- The AD service account used by the connector must have permission to modify the target attribute.
- After the initial bulk Sync, normal real-time attribute sync handles subsequent changes.
- Null/blank values *can* be propagated when the Identity Attribute is null (via Attribute Sync), but behavior can depend on exact mapping and connector handling.
- Multi-valued attributes or complex cases may require custom rules.
### Alternatives (if Attribute Sync is not ideal)
- Manually set the value directly in Active Directory (via ADUC, PowerShell, etc.) using the same service account, then run an account aggregation so ISC picks up the change.
- Use a workflow or the Identity API to call attribute synchronization for specific identities.
- For more complex one-time or conditional logic, a Before Provisioning rule or custom provisioning plan can force an Update operation.
This approach is the recommended and most commonly used pattern in the SailPoint community for exactly this scenario (populating previously blank attributes on existing AD accounts). If you share the specific attribute name, how the value is currently determined, and whether this needs to be one-time or ongoing, I can refine the guidance further.