Overview
When you successfully register your Active Directory (AD) or Lightweight Directory Access Protocol (LDAP) server with inSync and create AD/LDAP mapping, inSync automatically queries the registered AD/LDAP at predefined intervals to import users in inSync based on the filter parameters that you define at the time of creating the AD/LDAP mapping.
However, there could be instances where users with the same name or similar email addresses are imported into inSync and it becomes challenging to differentiate one user from the other when it comes to performing administrator-specific actions on these users. In these situations, inSync provides you the option to configure a unique user-identifier attributethat enables you to precisely differentiate between users within the inSync user base.
You can do this by enabling the User-Identifier Custom Attribute in your AD/LDAP settings. When you enable the User-Identifier CustomAttribute, a unique attribute in your registered AD/LDAP can now be imported into inSync. You can also choose to either hide or display the User-Identifier Custom Attribute on the inSync UI. Some of the examples of the custom attribute are as follows, but not limited to:
EmployeeID
DeskID
GivenName
When you configure the User-Identifier Custom Attribute through AD/LDAP settings, inSync imports the user details from the registered AD/LDAP in the following sequence:
inSync queries your registered AD/LDAP server as per the pre-defined Auto sync interval.
inSync scans for any conflicting entries in the AD/LDAP user base for:
user name
user email address
user AD/LDAP user name
The user details in addition to the User-Identifier Custom Attribute are imported into inSync for all the users.
To configure the User-Identifier Custom Attribute:
Procedure:
From the Druva admin console > EndPoints/Microsoft 365
On the inSync Management Console menu bar, click Users > User Provisioning.
Click on the vertical ellipsis on the User Provisioning Summary page > Edit
Under the User-Identifier Custom Attribute section, select the Enable custom attribute checkbox.
Provide the appropriate information for each field:
Attribute Name:
Type the name of the unique attribute that you intend to use as the User-Identifier Custom Attribute.
For example,
If you want to use the employee identification code as the User-Identifier Custom Attribute in inSync then type EmployeeID.
If you want to use desk number as the User-Identifier Custom Attribute in inSync then type DeskID.
Attribute Label:
This is the name that represents the User-Identifier Custom Attribute on the User listing page, User details page, and inSync Reports.
Select Same as attribute name, if you want to reuse the Attribute Name as Attribute Label.
Select Custom Label if you want to provide a different name to the Attribute Label.
Hide custom attribute in Users page and inSync Reports:Select this checkbox if you do not want the User-Identifier Custom Attribute label to appear on the User listing page, User details page, and inSync Reports (except for Global Custodian Report).
Click Save.