Previous Topic: Well-Known Attributes for an LDAP User Store

Next Topic: Group Well-Known Attributes

User Well-Known Attributes

A list of user well-known attributes and the items to which they map follows:

%ADMIN_OF%

Maps to the list of groups for which the user is an administrator.

This well-known attribute can improve search performance at sites with many groups. Assume that the %ADMIN_OF% well-known attribute is specified. The CA Identity Manager looks for those groups that a user can manage in the %ADMIN_OF% attribute, instead of checking every group in the user store.

%ADMIN_ROLE_CONSTRAINT%

Maps to the list of admin roles of an administrator.

The physical attribute that mapped to %ADMIN_ROLE_CONSTRAINT% must be multivalued to accommodate multiple roles.

We recommend indexing the LDAP attribute that is mapped to %ADMIN_ROLE_CONSTRAINT%.

%CERTIFICATION_STATUS%

Maps to the certification status of a user.

This attribute is required to use the user certification feature.

Note: For more information about user certification, see the Administration Guide.

%DELEGATORS%

Maps to a list of users who have delegated work items to the current user.

This attribute is required to use delegation. The physical attribute that mapped to %DELEGATORS% must be multivalued and capable of holding strings.

Important! Editing this field directly using CA Identity Manager tasks or an external tool can cause significant security implications.

%EMAIL%

Maps to an email address of a user.

Required to use the email notification feature.

%ENABLED_STATE%

(Required)

Maps to the status of a user.

Note: This attribute must match the Disabled Flag user directory attribute in the SiteMinder user directory connection.

%FIRST_NAME%

Maps to the first name of a user.

%FULL_NAME%

Maps to the first and last names of a user.

%IDENTITY_POLICY%

Specifies the list of identity policies that have been applied to a user account.

CA Identity Manager uses this attribute to determine whether applying an identity policy to a user is required or not. Assume that the policy has the Apply Once setting enabled and the policy is listed in the %IDENTITY_POLICY% attribute. CA Identity Manager does not apply the changes in the policy to the user.

Note: For more information about identity policies, see the Administration Guide.

%LAST_CERTIFIED_DATE%

Maps to the date when the roles are certified to a user.

Required to use the user certification feature.

Note: For more information about user certification, see the Administration Guide.

%LAST_NAME%

Maps to the last name of a user.

%MEMBER_OF%

Maps to the list of groups of which the user is a member.

The physical attribute that mapped to %MEMBER_OF% must be multivalued to accommodate multiple groups.

Using this attribute improves response time when searching groups of a user.

You can use this attribute with Active Directory or any directory schema that maintains group membership of a user on the user object.

%ORG_MEMBERSHIP%

(Required)

Maps to the DN of the organization to which the user belongs.

CA Identity Manager uses this well-known attribute to determine structure of a directory.

This attribute is not required when the user directory does not include organizations.

%ORG_MEMBERSHIP_NAME%

(Required)

Maps to the user-friendly name of the organization in which the profile of the user exists.

This attribute is not required when the user directory does not include organizations.

%PASSWORD%

Maps to the password of a user.

Note: This attribute must match the Password Attribute in the SiteMinder user directory connection.

%PASSWORD_DATA%

(Required for password policy support)

Specifies the attribute that tracks password policy information.

%PASSWORD_HINT%

(Required)

Maps to a user-specified question and answer pair. The question and answer pair is used when users forget their passwords.

To support multiple question and answer pairs, make sure that the %PASSWORD_HINT% attribute is multivalued.

Note: If you are using Password Services feature of SiteMinder to manage passwords, the Password Hint attribute must match the Challenge/Response attribute in the SiteMinder user directory.

%USER_ID%

(Required)

Maps to the ID of a user.

More information:

Group Well-Known Attributes

Organization Well-Known Attributes

%ADMIN_ROLE_CONSTRAINT% Attribute

Configure Well-Known Attributes