Dependent AD attribute value - Joiner Process

Hi

In a joiner process, if we have AD and ERP Application accounts to be provisioned .Can we set one of the attributes of ERP as dependent on AD value? Because currently I am getting error saying its not able to fetch the value when I have given that value as DEPENDENT on AD application’s mail attribute. I can see that the AD Account has created with mailnickname and mailbox assigned.

You have the option to populate the mentioned value after a successful creation of the AD. This can be done either through a separate workflow step or by utilizing the target mapping feature to populate the value using the AD mail attribute.

oh ok..then whats the purpose of Dependent value in the provisioning policy?

We have used dependent application functionality successfully for two applications. In your case, do you see the mail attribute populated on AD link immediately after provisioning? If not, try running targeted aggregation in after provisioning rule to make sure mail attribute us immediately populated in IIQ.

Thank you for responding.
Do you include aggregation as a workflow step? Or do you have schedule task running?

You can use after provisioning rule for AD application to aggregate and put the email back in provisioning plan.

ResourceObject resourceObject = aggregateADAccount(application, distinguishedName);
if(null != resourceObject){  
  String mail = resourceObject.get("mail");
  logger.trace("mail: "+mail);
  if(null != mail){
      accountRequest.add(new AttributeRequest("mail", ProvisioningPlan.Operation.Set, mail));
  }
}

Here is the example and aggregateADAccount has the logic to get the resource object.

Thank you for responding. Currently after successful provision, I can see the AD account correlated to the identity immediately without running aggregation. So I can use your above example after provisioning rule and set the mail attribute back. I will test it out and get back.

Hi @gaurav_jain

Should I return the modified plan in after prov plan or should I just add the account request to the plan?

There is no need to return modified plan.

I get the resource object and fetch the mail value as well but when I do the below, it gives the below error:-

if(null != mail){
      accountRequest.add(new AttributeRequest("mail", ProvisioningPlan.Operation.Set, mail));

Caused by: org.apache.bsf.BSFException: BeanShell script error: bsh.EvalError: Sourced file: inline evaluation of: ``import sailpoint.connector.Connector; import sailpoint.object.*; import org. . . . ‘’ : Attempt to resolve method: add() on undefined variable or class name: accountRequest : at Line: 65 : in file: inline evaluation of: ``import sailpoint.connector.Connector; import sailpoint.object.*; import org. . . . ‘’ : accountRequest .add ( new AttributeRequest ( “mail” , ProvisioningPlan .Operation .Set , mail ) )

So I had created the accountRequest object and added it to plan..Can you let me know how else can we resolve the above error?

You are getting that error because you don’t have the variable defined in your rule. To proceed, you have to retrieve the account request from the plan initially. Following that, you can utilize the provided line of code to add a new attribute request, similar to the following approach.

List acctReqs = plan.getAccountRequests(appName);
if (null != acctReqs || !acctReqs.isEmpty())
{
for (AccountRequest acctReq : acctReqs)
{

Add your condition and logic here.

}

}

Hi
But in this case, i need to fetch the mail value from resource object and update the plan with that account request, I dnt have to go through the exisiting account request, i have already done that to fetch the native identity and pass it on to fetch the resource object. I just need to now update the plan with the fetched mail attribute value. But when I create an accountrequest object and do an plan.add(accountrequest),it doesn’t work.

Can you share your complete rule or logic.

Hi  @ajmerasunny

Thank you for responding

Below is after provisioning rule snippet I have tested and it correctly fetches the mail attribute value but based on the snippet shared by  @gaurav_jain  , I tested the below but it didn’t work . Kindly let me know what could be the issue here.

String accni="";

log.error("AFTER PP ==" +plan.toXml());
AccountRequest accountRequest = new AccountRequest();

String appConnName = application.getConnector();
log.error("Application uses connector " + appConnName);

Connector appConnector = sailpoint.connector.ConnectorFactory.getConnector(application, null);
if (null == appConnector) {
errorMessage = "Failed to construct an instance of connector [" + appConnName + "]";
return errorMessage;
}

ResourceObject rObj = null;

AccountRequest acctReqs = plan.getAccountRequest("Active Directory");
String ntiden = acctReqs.getNativeIdentity();
rObj = (ResourceObject) appConnector.getObject("account", ntiden, null);
log.error("modified rObj" +rObj.toXml());
if(null != rObj){
String mail = rObj.get("mail");
log.error("mail: "+mail);
if(null != mail){
accountRequest.add(new AttributeRequest("mail", ProvisioningPlan.Operation.Set, mail));
// plan.add(accountRequest);
// log.error("modified plan" +plan);

}
}

I have added mail attribute in the provisioning policy in AD as well.

Hello,

I got it working. I was creating a new account request instead of updating the existing one . It worked after updating the existing account request. Thank you

Glad you figured it out.

Hello All, after adding dependency for erp app, even a enable of erp account, it is checking if AD account is present or not and then going ahead and creating an ad account and then enabling the erp account. Is this the expected behavior when using “dependencies” feature? How can I say it to use that only for creation and not when enabling or disabling the erp accounts?