Skip to main content

Create and manage mappings

Identity provisioning

Map selected identity data to a target-system operation, validate one record, then deliver the work through jobs.

A mapping creates API calls for a target system. It does not make changes until you run it—normally as part of a job. The target system's available functions are defined by its connector.

Before you build a mappingDirect link to Before you build a mapping

You need to…Use…
Create, update, or remove a target resourceA mapping.
Maintain target-group membership as an access policyA role.
Reuse a filtered population with an existence checkA filter lookup.
Compose usernames, email addresses, or passwordsA name generator or password generator.

Create a mappingDirect link to Create a mapping

Select the system, table, and functionDirect link to Select the system, table, and function

  1. Go to Output > Mappings and select Add.
  2. Select the target System and Target table.
  3. Select the appropriate Function—for example, UserCreate for a Users table—and enter a descriptive mapping name.
  4. Save the mapping.

tip

The function must be compatible with the selected target table. For example, selecting a user-create function for a Groups table causes errors.

Step 1 of 4

Map target attributesDirect link to Map target attributes

Target create and update functions expose the resource fields that their connector supports. Map a filter column directly when the source value already has the required format. Use a name or password generator when you need to compose a value first.

info

A mapping configures target-system attributes. To change which source fields are collected, use Choose columns to collect.

Map a custom target attributeDirect link to Map a custom target attribute

Use a custom target attribute only when the target connector supports the field but it is not already shown in the mapping's attribute list.

Open the mapping attribute listDirect link to Open the mapping attribute list

Edit the mapping and select Add Target Attribute. NIM adds a row at the bottom of the Attribute Mapping pane.

Step 1 of 3

Map a sub-mappingDirect link to Map a sub-mapping

Some target attributes contain multiple structured values rather than one value—for example, Google Workspace user phone numbers or external IDs. Create a mapping for the child table, then use it as the parent attribute's source.

Map each child table firstDirect link to Map each child table first

Create one mapping for every target child table that will supply a structured attribute. For example, create a mapping for users_phones before mapping the phones attribute of users.

Step 1 of 3

Test one mapping operationDirect link to Test one mapping operation

warning

A single-operation test writes one real record to the target system. Unlike a job run, it does not write the result back into Vault data. Use a non-production record whenever possible and verify the target afterward.

  1. Edit the mapping and open the Run tab.
  2. Select a pending operation in the Operation pane.
  3. Select Run Selected Item.
  4. Review the result in the Item pane and confirm the change in the target system.

Edit, copy, rename, or remove a mappingDirect link to Edit, copy, rename, or remove a mapping

  1. Go to Output > Mappings.
  2. Select Edit Mapping to change its target, input, or attributes.
  3. Select Copy Object to duplicate a mapping and retain its filter, name-generator, and password-generator selections.
  4. Select Rename Object, enter the new name, and press Enter.
  5. Select Remove Mapping and confirm to delete an unused mapping.

caution

Before removing a mapping, check the jobs that may still include it.

Mapping attribute referenceDirect link to Mapping attribute reference

Active Directory membership functionsDirect link to Active Directory membership functions

Use the Active Directory membership functions only for one-off or ad-hoc group changes that cannot be modeled with roles.

MembershipCreateDirect link to membershipcreate

AttributeValue specification
groupobjectGUID of the Active Directory group that receives the member.
memberobjectGUID of the Active Directory user to add.

MembershipDeleteDirect link to membershipdelete

AttributeValue specification
groupobjectGUID of the Active Directory group from which the member is removed.
memberobjectGUID of the Active Directory user to remove.

Windows file system attributesDirect link to Windows file system attributes

FolderCreateDirect link to FolderCreate

AttributeValue specification
AccessProfile1 … AccessProfile3objectSid of the Active Directory user assigned to the home directory.
FullNameFull path to create, for example C:\HomeFolders\bgreene. This is commonly mapped from the user's homeDirectory value.

FolderUpdateDirect link to FolderUpdate

AttributeValue specificationMode
AccessProfile1 … AccessProfile3objectSid of the user assigned to the home directory.add-only adds permissions without overwriting; copy overwrites existing permissions.