User Correlation
App showcase
Connect existing accounts to authoritative user records before automation attempts to create them again.
User Correlation gives IT a way to bring accounts created outside NIM into the managed identity lifecycle. It also surfaces multiple accounts matched to the same person so the team can investigate and reconcile them.
Intended audience
IT teamTarget scope
All users, excluding service and administrative accountsRequired systems
AnyWhen to use itDirect link to When to use it
Use this pattern when an account was created manually outside the automation process and needs to be linked to the person's record in the authoritative dataset. For example, IT might discover an existing directory account for a new employee before a provisioning job runs. Correlating it first lets the workflow manage that account instead of creating another one.
Exclude service and administrative accounts from the app's user scope so they are not mistaken for ordinary person accounts.
How it helpsDirect link to How it helps
- Shows accounts that have no link to an authoritative user record.
- Lets IT review and establish the correct relationship before automated provisioning runs.
- Shows linked accounts so the team can confirm which account belongs to each person.
- Highlights duplicate matches for investigation and reconciliation.
Correlation flowDirect link to Correlation flow
Find
Match
Check
Continue
OutcomeDirect link to Outcome
Preexisting accounts can enter the normal automation lifecycle without an avoidable second account being created. Duplicate matches become visible for IT to investigate and reconcile.
App previewDirect link to App preview
These screenshots show an Active Directory demo of the User Correlation pattern. The underlying approach can be adapted to other connected systems; configure the candidate scope to exclude service and administrative accounts in your environment.