Skip to main content

User Correlation

App showcase

Connect existing accounts to authoritative user records before automation attempts to create them again.

User Correlation gives IT a way to bring accounts created outside NIM into the managed identity lifecycle. It also surfaces multiple accounts matched to the same person so the team can investigate and reconcile them.

Intended audience

IT team

Target scope

All users, excluding service and administrative accounts

Required systems

Any

When to use itDirect link to When to use it

Use this pattern when an account was created manually outside the automation process and needs to be linked to the person's record in the authoritative dataset. For example, IT might discover an existing directory account for a new employee before a provisioning job runs. Correlating it first lets the workflow manage that account instead of creating another one.

Exclude service and administrative accounts from the app's user scope so they are not mistaken for ordinary person accounts.

How it helpsDirect link to How it helps

  • Shows accounts that have no link to an authoritative user record.
  • Lets IT review and establish the correct relationship before automated provisioning runs.
  • Shows linked accounts so the team can confirm which account belongs to each person.
  • Highlights duplicate matches for investigation and reconciliation.

Correlation flowDirect link to Correlation flow

Find

Review unlinked accountsIdentify accounts created outside the automated lifecycle

Match

Confirm the authoritative userVerify the person and link the existing account to the correct source record

Check

Review linked and duplicate accountsConfirm the relationship and investigate multiple matches

Continue

Run normal automationManage the existing account through the configured identity workflow
Review the identity match before saving a link or changing a duplicate account.

OutcomeDirect link to Outcome

Preexisting accounts can enter the normal automation lifecycle without an avoidable second account being created. Duplicate matches become visible for IT to investigate and reconcile.

App previewDirect link to App preview

These screenshots show an Active Directory demo of the User Correlation pattern. The underlying approach can be adapted to other connected systems; configure the candidate scope to exclude service and administrative accounts in your environment.

Find existing accounts that have not been linked to an authoritative user record.
Review accounts already linked to authoritative user records.
Identify records with more than one associated account for review.
Inspect the accounts in a duplicate group before making changes.