Create and manage mappings
Identity provisioning
Map selected identity data to a target-system operation, validate one record, then deliver the work through jobs.
A mapping creates API calls for a target system. It does not make changes until you run it—normally as part of a job. The target system's available functions are defined by its connector.
Before you build a mappingDirect link to Before you build a mapping
| You need to… | Use… |
|---|---|
| Create, update, or remove a target resource | A mapping. |
| Maintain target-group membership as an access policy | A role. |
| Reuse a filtered population with an existence check | A filter lookup. |
| Compose usernames, email addresses, or passwords | A name generator or password generator. |
Create a mappingDirect link to Create a mapping
Select the system, table, and functionDirect link to Select the system, table, and function
- Go to Output > Mappings and select Add.
- Select the target System and Target table.
- Select the appropriate Function—for example,
UserCreatefor a Users table—and enter a descriptive mapping name. - Save the mapping.
The function must be compatible with the selected target table. For example, selecting a user-create function for a Groups table causes errors.
Provide the records to processDirect link to Provide the records to process
On the Mapping tab, select the filter—or configured lookup—that returns the records to process. NIM populates the Items pane with the available source values.
Optionally select a name generator or password generator when the mapping needs their outputs.
Build the target requestDirect link to Build the target request
Drag values from Items into the target attributes' Value Specification fields. Attributes with bold names are required. Add a custom target attribute or sub-mapping when the standard attributes are not sufficient.
Review one operation before productionDirect link to Review one operation before production
Use the single-operation test with a non-production record when possible. Verify the target result, correct the mapping if needed, then save it for inclusion in a job.
Map target attributesDirect link to Map target attributes
Target create and update functions expose the resource fields that their connector supports. Map a filter column directly when the source value already has the required format. Use a name or password generator when you need to compose a value first.
A mapping configures target-system attributes. To change which source fields are collected, use Choose columns to collect.
Map a custom target attributeDirect link to Map a custom target attribute
Use a custom target attribute only when the target connector supports the field but it is not already shown in the mapping's attribute list.
Open the mapping attribute listDirect link to Open the mapping attribute list
Edit the mapping and select Add Target Attribute. NIM adds a row at the bottom of the Attribute Mapping pane.
Define the target request fieldDirect link to Define the target request field
Enter the attribute Name, Type, Source, and Value Specification. Confirm each value matches the target system's resource schema.
Test before using itDirect link to Test before using it
Save the mapping and test a single operation before adding it to a production job. If required, add the corresponding attribute to the target resource schema outside NIM.
Map a sub-mappingDirect link to Map a sub-mapping
Some target attributes contain multiple structured values rather than one value—for example, Google Workspace user phone numbers or external IDs. Create a mapping for the child table, then use it as the parent attribute's source.
Map each child table firstDirect link to Map each child table first
Create one mapping for every target child table that will supply a structured attribute. For example, create a mapping for users_phones before mapping the phones attribute of users.
Select mapping as the sourceDirect link to Select mapping as the source
Edit the parent mapping. For each structured attribute, select mapping in Source, then choose the child mapping in Value Specification.
Confirm the complete requestDirect link to Confirm the complete request
Repeat for every structured attribute, save the parent mapping, and test a representative record to confirm the target system receives the expected nested values.
Test one mapping operationDirect link to Test one mapping operation
A single-operation test writes one real record to the target system. Unlike a job run, it does not write the result back into Vault data. Use a non-production record whenever possible and verify the target afterward.
- Edit the mapping and open the Run tab.
- Select a pending operation in the Operation pane.
- Select Run Selected Item.
- Review the result in the Item pane and confirm the change in the target system.
Edit, copy, rename, or remove a mappingDirect link to Edit, copy, rename, or remove a mapping
- Go to Output > Mappings.
- Select Edit Mapping to change its target, input, or attributes.
- Select Copy Object to duplicate a mapping and retain its filter, name-generator, and password-generator selections.
- Select Rename Object, enter the new name, and press Enter.
- Select Remove Mapping and confirm to delete an unused mapping.
Before removing a mapping, check the jobs that may still include it.
Mapping attribute referenceDirect link to Mapping attribute reference
Active Directory membership functionsDirect link to Active Directory membership functions
Use the Active Directory membership functions only for one-off or ad-hoc group changes that cannot be modeled with roles.
MembershipCreateDirect link to membershipcreate
| Attribute | Value specification |
|---|---|
group | objectGUID of the Active Directory group that receives the member. |
member | objectGUID of the Active Directory user to add. |
MembershipDeleteDirect link to membershipdelete
| Attribute | Value specification |
|---|---|
group | objectGUID of the Active Directory group from which the member is removed. |
member | objectGUID of the Active Directory user to remove. |
Windows file system attributesDirect link to Windows file system attributes
FolderCreateDirect link to FolderCreate
| Attribute | Value specification |
|---|---|
AccessProfile1 … AccessProfile3 | objectSid of the Active Directory user assigned to the home directory. |
FullName | Full path to create, for example C:\HomeFolders\bgreene. This is commonly mapped from the user's homeDirectory value. |
FolderUpdateDirect link to FolderUpdate
| Attribute | Value specification | Mode |
|---|---|---|
AccessProfile1 … AccessProfile3 | objectSid of the user assigned to the home directory. | add-only adds permissions without overwriting; copy overwrites existing permissions. |