Configuring a Username Policy in ID Hub

RapidIdentity Platform Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

ID Hub generates unique usernames based on your username policy. When you create a policy, you can select attributes or text to include. The Example box in the Policy Builder menu displays the resulting username as you add criteria. For example, if you select the lastName attribute, then enter a period in the Custom Text field, then select the firstName attribute, the resulting username displays as Lastname.Firstname in the Example box. You can drag attributes and custom text to reorder them.

Jamf recommends generating usernames that are not too complex for a user to remember. Examples of recommended usernames include the following:
  • First initial, last name

  • First name, separator character, last name

  • First name, last name, and unique identifier that is not a social security number (for example, a student or employee identifier)

  • A standalone identifier that is not a social security number or other sensitive personally identifiable information

You can provide usernames via a manual process, or you can provide generic criteria as your username policy allows. For example, if you configure your username policy to use an employee ID, you can instruct all employees to log in with their employee ID and avoid providing individual usernames to each user. If you use QR ID badges, the username is still distributed to target systems.

When data changes in the source system, the username does not automatically change in ID Hub. For example, if your username policy includes lastName and a user changes their last name, their username remains unchanged unless you have a rename policy.

Requirements
  • An administrator account in RapidIdentity

  • A source of data synchronized to ID Hub

  • Roles configured in each source, with attributes standardized using the RapidIdentity Cloud Directory Schema

  1. Log in to your RapidIdentity administrator portal.
  2. In the Dashboard pop-up menu, choose "Identity Hub".
  3. Click the upper-left menu icon.
  4. In the Policies menu, choose a user group.
  5. Click Username Policy.
  6. Use the Enable switch to enable the policy.
  7. Click the Add Rule menu.
  8. To include custom text in the username, choose Add Custom Text, then enter your text in the Custom Text field.
  9. To include an attribute in the username, complete the following steps:
    1. Choose Add Attribute.
    2. In the Attribute menu, choose an attribute.
    3. In the Rule menu, choose whether to use the complete value, or whether to use a specified number of characters from the first or last part of the value.

      If you select Use First or Use Last, the Character(s) menu appears. You can click + or - in the menu to raise or lower the number of characters used from the beginning or end of the value.

    4. In the Case menu, choose whether to use uppercase or lowercase.
  10. (Optional) Enable advanced settings.
    1. Click Advanced Settings.
    2. Toggle Character Limit.
    3. Click + or - to raise or lower the number of characters allowed in the username.
    4. In the Collision Count menu, click + or - to choose a number at which to start the collision count.

      If a duplicate username is detected, this digit will be appended to the username, or the number will increase by one until a unique value is achieved.

  11. Click Save.

New usernames generated for the user group now conform to your username policy.