How can I store an API-updated custom identity attribute without it being overwritten by aggregation

I am working in ISC and I want to maintain a custom identity attribute (e.g., mfaEnrollment) that I can update via API/Workflow.

My requirements are:

  • The attribute should be visible on the identity profile
  • It should be updateable via API (PATCH /v3/identities)
  • It should NOT be overwritten during identity aggregation or refresh
  • It should not depend on a source system value

I tried setting the attribute with:

  • No source mapping
  • No transform

But in this case, the attribute is not visible in the identity or behaves inconsistently.

What is the recommended SailPoint-supported approach to achieve a persistent, API/Workflow-controlled identity attribute that survives aggregation?

@thoomukb, could you please provide more info - what endpoint in the identities API are you referring to (please see the attached screen capture)? I’m not aware of any that have update functionality, afaik any modification to an identity attribute would need to come from an authoritative source via an identity profile.

For a directly connected Active Directory application, can the account attribute extensionAttribute11 be updated via an ISC workflow or API to set a value such as a random string or a status indicator (for example, Active or Non‑Active)?