12.2 Configuring Common Connector Settings
Key Takeaways
The Settings tab holds connection parameters, Test Connection, and the partitioning, merging, and delta aggregation options that the connector supports.
Every application needs an account schema with an Identity Attribute (the unique account ID) and a Display Attribute.
A group schema is linked to accounts by setting the account entitlement attribute's Type to the group schema's Native Object Type.
Entitlement marks an attribute as access to track; Managed puts values in the Entitlement Catalog so they can have owners, descriptions, and be requestable.
Applications support one each of the Create, Update, Delete, Enable, Disable, Unlock, Change Password, CreateGroup, and UpdateGroup provisioning policies.
Configuring Common Connector Settings
Objective 5.2 is configure common connector settings. Connectors differ, but most applications share the same three sub-tabs on Configuration: Settings, Schema, and Provisioning Policies.
Settings: Connecting and Reading
The Settings tab holds the connection parameters for the connector type. Use Test Connection to verify them. Settings also hold the connector's options for partitioning, data merging, and delta aggregation, where supported.
Example: Delimited File
| Setting | Notes |
|---|---|
| File Path, File Encoding | The file to parse. With no encoding set, the server default is used. |
| File Transport | Local, FTP, FTPS, SCP, or SFTP, with host, port, and credentials. The account running the application server needs read access for Local. |
| Parsing Type | Delimited (with a delimiter such as \\u0009 for tab) or Regular Expression (groups define tokens) |
| File has column header on first line / Columns | Columns are required for regex parsing, or when there is no header, or to rename columns used by the BuildMap rule |
| Fail on column length mismatch | Fail when a line lacks columns |
| Filtering | Lines to skip, filter empty objects, a comment character, and a Filter String (for example, department == "Manufacturing") that drops matching objects |
| Merging | For objects spanning multiple lines: Index Column, whether data is sorted by it (otherwise an in-memory merge is built), ignore case, and which columns to merge |
| Iteration Partitioning | Auto (calculated) or Manual (objects per partition) |
Example: JDBC
Connection settings include the database URL, JDBC driver, and credentials. You also define the account SQL statement or stored procedure. If one account spans several rows, enable merging with index columns, and the SQL must include ORDER BY on those index columns. The JDBC connector supports aggregation, delta aggregation, partitioning, account and group management, and provisioning rules, either one rule for every operation or a separate rule per operation (Create, Modify, Delete, Enable, Disable, Unlock).
Schema: What Gets Read
Every application needs an account schema. Many also have group (account group) schemas, and some connectors support multiple object types, each with its own schema. Use Discover Schema Attributes where supported, then Preview to test.
| Schema field | Meaning |
|---|---|
| Native Object Type | The object on the target, such as User and Group, or DBA_USER and DBA_ROLES |
| Identity Attribute (required) | The unique identifier of the object on the source. It becomes the account's native identity. Do not change it on connectors with predefined schemas. |
| Display Attribute (required) | The name shown in the UI |
| Instance Attribute | Identifies a specific instance of a multi-instance application |
| Include Permissions | Adds directPermissions for connectors whose feature string includes DIRECT_PERMISSIONS |
| Group: Description Attribute | Fills the ManagedAttribute description during group aggregation |
Linking accounts to groups: set the Type of the account schema's entitlement attribute (for example, memberOf) to the Native Object Type of the group schema (often group). Account values then map to the group schema's identity attribute.
Attribute Properties
| Property | Effect |
|---|---|
| Entitlement | Tracked as access. Used in certifications (additional entitlements), role profiles, account group certifications, and LCM. |
| Managed | Values become ManagedAttributes in the Entitlement Catalog, where they can be requestable and have owners, display names, and descriptions. Group aggregation adds all groups to the catalog automatically. |
| Multi-Valued | Stored as a list, even with one value |
| Correlation Key | Used only for activity and unstructured-data correlation, not account correlation |
| Minable | Returned to role mining and profile creation |
| Remediation Modifiable | Certifiers can change the value during a review: Select, Free text, or Readonly |
Schema rules to remember: attribute names cannot begin with IIQ_ (reserved), and they must not duplicate extended attribute names (section 2.3).
Delta Aggregation, Partitioning, and Features
- Delta aggregation is enabled in the aggregation task, but it works only if the connector supports it. Some connectors need extra settings on the application, such as a delta table or change-tracking column for JDBC. Delta aggregation can be partitioned only if the connector implements partitioning. Otherwise it runs single-threaded.
- Partitioning must be configured on the application (Settings) and enabled in the task. If the connector cannot partition, IdentityIQ falls back to generic (task-level) partitioning at the database level (section 2.1).
- Features. Each connector advertises what it can do, such as provisioning, enable/disable, unlock, password changes, direct permissions, and delta. UI options appear only when the feature is present. That is why a provisioning policy type or an Include Permissions checkbox may be missing for some applications.
Provisioning Policies: What Gets Written
For read-write applications, provisioning policies list the attributes each operation needs. The types are Create, Update, Delete, Enable Account, Disable Account, Unlock Account, Change Password, CreateGroup, and UpdateGroup. Only one of each type is allowed, and not every object supports every type. Fields calculate values from literals, scripts, or rules, such as return identity.firstname, or ask a person (section 4.2). Review Required makes the approver review a calculated field. Some connectors ship predefined Create policies that you can modify.
Application Dependencies say a user needs an account on another application first. If it is missing, IdentityIQ adds an account request for it, and dependent field values can be read from that application. Dependencies are enforced on Create operations only.
A JDBC application returns one row per account-and-role pair, so each account appears on several rows. What must be configured?
Enable merging with the index column and make the SQL statement ORDER BY that index column.
Mark the role column as Correlation Key.
Enable Native Change Detection.
Create a second account schema for the extra rows.
Accounts on an LDAP application show memberOf values, but group details from the group schema never appear on the accounts. What link is missing?
The group schema needs a Correlation Key.
The accounts must be marked Remediation Modifiable.
The application must be authoritative.
The account schema's entitlement attribute Type must match the group schema's Native Object Type.
An engineer marks an application attribute as Correlation Key, expecting it to help correlate accounts to identities. Why doesn't this work?
Correlation Key only works with delimited files.
Correlation Key is used only for activity and unstructured-data correlation; account correlation is set on the Correlation tab or with a rule.
Correlation Key must also be marked Minable.
Correlation Key applies only to group schemas.
Which schema attribute property places the attribute's values in the Entitlement Catalog so they can have owners, descriptions, and be requestable?
Multi-Valued
Minable
Entitlement only
Managed
Sections you finish are checked off in the contents.