12.2 Configuring Common Connector Settings

Key Takeaways

  • The Settings tab holds connection parameters, Test Connection, and the partitioning, merging, and delta aggregation options that the connector supports.

  • Every application needs an account schema with an Identity Attribute (the unique account ID) and a Display Attribute.

  • A group schema is linked to accounts by setting the account entitlement attribute's Type to the group schema's Native Object Type.

  • Entitlement marks an attribute as access to track; Managed puts values in the Entitlement Catalog so they can have owners, descriptions, and be requestable.

  • Applications support one each of the Create, Update, Delete, Enable, Disable, Unlock, Change Password, CreateGroup, and UpdateGroup provisioning policies.

Last updated: September 2026

Configuring Common Connector Settings

Objective 5.2 is configure common connector settings. Connectors differ, but most applications share the same three sub-tabs on Configuration: Settings, Schema, and Provisioning Policies.

Settings: Connecting and Reading

The Settings tab holds the connection parameters for the connector type. Use Test Connection to verify them. Settings also hold the connector's options for partitioning, data merging, and delta aggregation, where supported.

Example: Delimited File

SettingNotes
File Path, File EncodingThe file to parse. With no encoding set, the server default is used.
File TransportLocal, FTP, FTPS, SCP, or SFTP, with host, port, and credentials. The account running the application server needs read access for Local.
Parsing TypeDelimited (with a delimiter such as \\u0009 for tab) or Regular Expression (groups define tokens)
File has column header on first line / ColumnsColumns are required for regex parsing, or when there is no header, or to rename columns used by the BuildMap rule
Fail on column length mismatchFail when a line lacks columns
FilteringLines to skip, filter empty objects, a comment character, and a Filter String (for example, department == "Manufacturing") that drops matching objects
MergingFor objects spanning multiple lines: Index Column, whether data is sorted by it (otherwise an in-memory merge is built), ignore case, and which columns to merge
Iteration PartitioningAuto (calculated) or Manual (objects per partition)

Example: JDBC

Connection settings include the database URL, JDBC driver, and credentials. You also define the account SQL statement or stored procedure. If one account spans several rows, enable merging with index columns, and the SQL must include ORDER BY on those index columns. The JDBC connector supports aggregation, delta aggregation, partitioning, account and group management, and provisioning rules, either one rule for every operation or a separate rule per operation (Create, Modify, Delete, Enable, Disable, Unlock).

Schema: What Gets Read

Every application needs an account schema. Many also have group (account group) schemas, and some connectors support multiple object types, each with its own schema. Use Discover Schema Attributes where supported, then Preview to test.

Schema fieldMeaning
Native Object TypeThe object on the target, such as User and Group, or DBA_USER and DBA_ROLES
Identity Attribute (required)The unique identifier of the object on the source. It becomes the account's native identity. Do not change it on connectors with predefined schemas.
Display Attribute (required)The name shown in the UI
Instance AttributeIdentifies a specific instance of a multi-instance application
Include PermissionsAdds directPermissions for connectors whose feature string includes DIRECT_PERMISSIONS
Group: Description AttributeFills the ManagedAttribute description during group aggregation

Linking accounts to groups: set the Type of the account schema's entitlement attribute (for example, memberOf) to the Native Object Type of the group schema (often group). Account values then map to the group schema's identity attribute.

Attribute Properties

PropertyEffect
EntitlementTracked as access. Used in certifications (additional entitlements), role profiles, account group certifications, and LCM.
ManagedValues become ManagedAttributes in the Entitlement Catalog, where they can be requestable and have owners, display names, and descriptions. Group aggregation adds all groups to the catalog automatically.
Multi-ValuedStored as a list, even with one value
Correlation KeyUsed only for activity and unstructured-data correlation, not account correlation
MinableReturned to role mining and profile creation
Remediation ModifiableCertifiers can change the value during a review: Select, Free text, or Readonly

Schema rules to remember: attribute names cannot begin with IIQ_ (reserved), and they must not duplicate extended attribute names (section 2.3).

Delta Aggregation, Partitioning, and Features

  • Delta aggregation is enabled in the aggregation task, but it works only if the connector supports it. Some connectors need extra settings on the application, such as a delta table or change-tracking column for JDBC. Delta aggregation can be partitioned only if the connector implements partitioning. Otherwise it runs single-threaded.
  • Partitioning must be configured on the application (Settings) and enabled in the task. If the connector cannot partition, IdentityIQ falls back to generic (task-level) partitioning at the database level (section 2.1).
  • Features. Each connector advertises what it can do, such as provisioning, enable/disable, unlock, password changes, direct permissions, and delta. UI options appear only when the feature is present. That is why a provisioning policy type or an Include Permissions checkbox may be missing for some applications.

Provisioning Policies: What Gets Written

For read-write applications, provisioning policies list the attributes each operation needs. The types are Create, Update, Delete, Enable Account, Disable Account, Unlock Account, Change Password, CreateGroup, and UpdateGroup. Only one of each type is allowed, and not every object supports every type. Fields calculate values from literals, scripts, or rules, such as return identity.firstname, or ask a person (section 4.2). Review Required makes the approver review a calculated field. Some connectors ship predefined Create policies that you can modify.

Application Dependencies say a user needs an account on another application first. If it is missing, IdentityIQ adds an account request for it, and dependent field values can be read from that application. Dependencies are enforced on Create operations only.

Loading diagram...
Configuration tab building blocks
Test Your Knowledge

A JDBC application returns one row per account-and-role pair, so each account appears on several rows. What must be configured?

A

Enable merging with the index column and make the SQL statement ORDER BY that index column.

B

Mark the role column as Correlation Key.

C

Enable Native Change Detection.

D

Create a second account schema for the extra rows.

Test Your Knowledge

Accounts on an LDAP application show memberOf values, but group details from the group schema never appear on the accounts. What link is missing?

A

The group schema needs a Correlation Key.

B

The accounts must be marked Remediation Modifiable.

C

The application must be authoritative.

D

The account schema's entitlement attribute Type must match the group schema's Native Object Type.

Test Your Knowledge

An engineer marks an application attribute as Correlation Key, expecting it to help correlate accounts to identities. Why doesn't this work?

A

Correlation Key only works with delimited files.

B

Correlation Key is used only for activity and unstructured-data correlation; account correlation is set on the Correlation tab or with a rule.

C

Correlation Key must also be marked Minable.

D

Correlation Key applies only to group schemas.

Test Your Knowledge

Which schema attribute property places the attribute's values in the Entitlement Catalog so they can have owners, descriptions, and be requestable?

A

Multi-Valued

B

Minable

C

Entitlement only

D

Managed

Sections you finish are checked off in the contents.