2.3 Creating Extended Attributes and the Objects That Support Them
Key Takeaways
Identity (Identity), account (Link), Application, role (Bundle), entitlement (ManagedAttribute), and CertificationItem are the common objects with extended attributes, each described by an ObjectConfig.
Extended attributes are defined on Global Settings pages: Identity Mappings, Account Mappings, Application Attributes, Role Configuration, and Entitlement Catalog Attributes.
A searchable extended attribute needs a database column: a numbered extendedN column or a named column declared in the object's Extended.hbm.xml file.
Extended attribute names must be unique and must not duplicate any application schema attribute name, or aggregation may not update values correctly.
Customized .hbm.xml files live under WEB-INF and are overwritten on upgrade, so keep copies and reapply them.
Creating Extended Attributes and the Objects That Support Them
Blueprint objective 1.3 asks you to demonstrate knowledge of creating extended attributes. Objective 7.4 asks which common IdentityIQ objects can have extended attributes. The two go together: you create an extended attribute on one of those objects, and where it is stored decides whether you can search on it.
What an Extended Attribute Is
Every IdentityIQ object class has standard attributes built into the product, such as an identity's firstname, lastname, email, and manager. An extended attribute is one you add for your organization, such as costCenter on identities, privileged on accounts, or riskTier on applications. The definitions are kept in an ObjectConfig object for the class. The console command oconfig lists every class that has an ObjectConfig and its extended attributes, numbered by their extended column slot.
Which Objects Support Extended Attributes
| Object (class) | What it represents | Where you define the extended attribute | Mapping file |
|---|---|---|---|
| Identity | The identity cube for a person or non-human identity | Global Settings > Identity Mappings | IdentityExtended.hbm.xml |
| Link | An account on an application | Global Settings > Account Mappings | LinkExtended.hbm.xml |
| Application | An application definition | Global Settings > Application Attributes | ApplicationExtended.hbm.xml |
| Bundle | A role | Global Settings > Role Configuration (extended attributes) | BundleExtended.hbm.xml |
| ManagedAttribute | An entitlement or account group in the Entitlement Catalog | Global Settings > Entitlement Catalog Attributes | ManagedAttributeExtended.hbm.xml |
| CertificationItem | A line item in an access review | Mirrors the account attributes | CertificationItemExtended.hbm.xml |
The installation guide also lists TargetExtended.hbm.xml (permission targets) and AlertExtended.hbm.xml (activity alerts). For the exam, focus on the six rows above. Extended attribute questions almost always involve identities, accounts, applications, roles, entitlements, or certification items.
Two Ways to Store a Value
- Non-searchable. The value is stored in the object's serialized XML attributes map. It displays and can be used in rules, but it cannot be filtered in searches.
- Searchable. The value is copied into a real database column so that searches, filters, populations, and reports can query it. The column must already exist in the Hibernate mapping.
Searchable columns come in two styles:
- Numbered columns – properties named
extended1,extended2, and so on. The Edit Identity Attributes page says the default number of searchable identity attributes is ten. The installation guide lets you add numbered properties up to a maximum of twenty. - Named columns – a property with a meaningful name, such as
costCenter. Hibernate turns camel case into a lower-case, underscore-separated database column (cost_center). When you map an attribute to a named column in the UI, you enter the .hbm.xml property name, not the database column name.
An example of adding numbered, indexed identity properties to IdentityExtended.hbm.xml:
<property name="extended1" type="string" length="450" index="spt_identity_extended1_ci"/>
<property name="extended2" type="string" length="450" index="spt_identity_extended2_ci"/>
<property name="extended11" type="string" length="450" index="spt_identity_extended11_ci"/>
Adding index="spt_identity_extendedN_ci" creates a case-insensitive index for that column. Identity attributes of type Identity, which point at another identity such as a region owner, are stored in separate extended identity fields. oconfig lists them in their own sub-list.
Creating an Extended Attribute: The Procedure
- Plan the columns. Decide which attributes must be searchable. If the default slots are not enough, edit the relevant
*Extended.hbm.xmlfile inWEB-INF/classes/sailpoint/object. - Regenerate and apply the DDL. Run
iiq schemato produce new database scripts. On a new install, create the database with them. On an existing install, apply the column changes to the database. - Define the attribute in the UI. Use the matching Global Settings page. Give it an Attribute Name (the name rules use) and a Display Name, choose a type, and select Searchable if it needs a column.
- Map its sources. Identity and account attributes take their values from source mappings: application attributes, application rules, or global rules (section 16.3). Application, role, and entitlement attributes are usually entered in the UI and can have allowed values, default values, and a Required flag for string types.
- Populate it. Identity attributes are promoted during aggregation and identity refresh. Account attributes are filled from their source mappings during aggregation.
Rules That Produce Exam Traps
- Names must be unique. The documentation warns that an extended attribute must not share a name with any attribute in any application schema. If an extended attribute matches a schema attribute, values may not update correctly during aggregation. A standard prefix avoids collisions.
- You cannot reuse a standard identity attribute name for an identity extended attribute.
- Renaming is risky. Changing an attribute name can make previously aggregated values unrecognizable.
- Accounts and certification items move together. If you change the account (Link) extended attributes, make the same change to the CertificationItem attributes. This lets searchable account values be stored on certification items for searching and status icons.
- Upgrades overwrite
WEB-INF. CustomizedIdentityExtended.hbm.xml,LinkExtended.hbm.xml, andCertificationItemExtended.hbm.xmlfiles must be saved and copied into the new installation before upgrading the database. - Keep the default mappings. AI-Driven Identity Security (formerly AI Services) needs every default field in the
.hbm.xmlfiles. Add columns, but do not remove the defaults. - Account attributes can drive icons. An extended account attribute such as
privilegedorservicecan show an icon in certifications and identity pages. You set this with anAccountIconConfigentry in the UIConfig object.
An auditor wants to filter the Identity Warehouse by an identity attribute called costCenter. The attribute exists, but it is not available as a search filter. What change makes it filterable?
Add costCenter to the account schema of the HR application.
Mark the identity attribute Searchable and make sure it maps to an extended or named column in the identity Hibernate mapping.
Store costCenter as a multi-valued attribute in the XML attributes map.
Run the Perform Maintenance task with the Prune option.
Which IdentityIQ object class stores extended attributes defined on the Global Settings > Account Mappings page?
Identity
ManagedAttribute
Link
Bundle
An engineer creates an extended identity attribute named department. The HR application's account schema also has an attribute named department. What risk does the documentation describe?
The identity attribute becomes read-only.
The attribute is automatically converted to a named column.
The HR application stops being authoritative.
Attribute values may not be updated correctly during aggregation because the extended attribute name duplicates a schema attribute.
When mapping an identity attribute to a named column declared as costCenter in IdentityExtended.hbm.xml, what name should be entered in the IdentityIQ UI?
costCenter, the Hibernate property name
cost_center, the database column name
extended1, the next numbered slot
spt_identity_cost_center_ci, the index name
Sections you finish are checked off in the contents.