User Sync Task
It can be used to synchronise data (e.g. import data from an LDAP directory into a database for Airlock IAM) and to convert data.
Data may be modified while importing. When using LDAP / AD, all context data is treated as string data.
sourceUserStore) If the sync flag is configured, this user store will be used to reset the sync flag.
targetUserStore) Note: If an imported user cannot be found using the target user store, the task attempts to restore the user (possibly removing a "deleted" flag). If restore was not successful, a new user is inserted.
attributeMappings) NOTE: The context data attributes must be supported by the source and the target user store.
The username column doesn't need to be referenced here, because it is automatically mapped.
importRoles) importAuthMethod) insertUsers) updateUsers) deleteUsers) syncFlag) true are synchronised. After successful synchronisation, this task modifies the user in the source user store by setting the sync flag to false. dataTransformers) - The username is available as attribute "username".
- The roles are available as attribute "roles".
- The authentication method is available as attribute "authMethod".
- Context data attributes of the source user are handed over to the transfomers. These attributes are not used by all transformers. Check the transformer documentation to learn if and how they can be used.
continueOnErrors) Errors related to reading users from the source user store are not recoverable and cause the task to fail even if this option is enabled.
realm)
type: UserSyncTask
id: UserSyncTask-xxxxxx
displayName:
comment:
properties:
attributeMappings:
continueOnErrors: false
dataTransformers:
deleteUsers: true
importAuthMethod: false
importRoles: false
insertUsers: true
realm:
sourceUserStore:
syncFlag:
targetUserStore:
updateUsers: true