RapidIdentity Cloud Account Attributes

RapidIdentity Platform Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

LDAP account entries must be part of an organizational unit. Therefore, they must be placed under ou=Groups, dc=meta.

LDAP account entries must contain the following values:
  • objectClass=idautoPerson

  • A unique idautoId value

  • At least one unique idautoPersonUserNameMV value

Format the Distinguished Name (DN) for accounts as follows:
idautoID=<idautoID_value>,ou=Accounts,dc=meta
Table 1. Core Attributes
Attribute NameFriendly NameData TypeMulti-ValuedUniqueIndexesDescription/Constraints
idautoIDIDUUIDNYeq Unique UUID of the account; must not be changed after initial creation
idautoPersonUserNameMVUsernamesStringYYeq, sub Unique usernames for the account
givenNameFirst NameStringNNeq, subAccount holder's first name
snLast NameStringNNeq, subAccount holder's last name
displayNameDisplay NameStringNNeq, subConstructed by RapidIdentity Connect, typically the account holder's first and last name
mailEmailStringNYeq, subPrimary organizational email account
idautoPersonEmailAddressesEmail AddressesStringYNeq, subCurrent and past email addresses
idautoPersonHomeEmailPersonal Email AddressStringNNeq, subPersonal email address for password reset and authentication
idautoDisabled-BooleanNNeqIf TRUE, the account is considered DISABLED in RapidIdentity. The attribute should be cleared rather than set to FALSE when re-enabling the account.
userPassword-BinaryNN-Hashed account password
idauto-pwdPrivate-BinaryNN-Encrypted password managed by the Identity Automation password filter (read-only)
idauto-pwdPrivateTS-DateTimeNNeqThe date and time when the idauto-pwdPrivate value was last set (read-only)
idautoPersonPhotoURLPhoto URLStringNN-The URL of the account holder's profile image
mobileMobile NumbersStringYN-The account holder's mobile phone numbers
managerManagerDNYNeqThe DNs of the account holder's managers
directReportsDirect ReportsDNYNeqThe DNs of the account holder's direct reports (read-only)
idautoPersonEndDateExpiration DateDateTimeNNeqExpiration date for sponsored accounts in the following format: yyyyMMddHHmmssZ. Can store disable date from source systems for non-sponsored student accounts.
employeeTypeRoleStringYNeqValid values: staff, student, teacher, sponsored, parent. ID Hub only supports policies for staff, student, and teacher. Displays as Account Type in RapidIdentity.
idautoChallengeSet-StringYN-Stores RapidIdentity challenge question and answer data. Existing data must not be updated by a RapidIdentity Connect Action Set.
idautoChallengeSetTimestamp-DateTimeNN-Date/time when the account holder last added challenge questions/answers. Can be cleared to force another challenge setup at next login.
idautoRequestAssociations-StringYNeqContains the IDs of all granted, bound workflow entitlements for the account holder. Data must not be updated by a RapidIdentity Connect Action Set.
idautoPersonClaimCodeClaim CodeStringNNeqStores an arbitrary claim code used by the default RapidIdentity claim policy. Minimum length of 8 characters.
idautoPersonClaimFlagClaimedBooleanNN-Set to TRUE by RapidIdentity when an account is successfully claimed. Used as a filter term in the default claim policy to prevent an account from being claimed more than once. The attribute should be cleared rather than set to FALSE when an account is unclaimed.
memberOf-DNYN-Read-only, slapo overlay for reverse group membership management
Table 2. Profile Attributes
Attribute NameFriendly NameData TypeMulti-ValuedIndexesDescription/Constraints
lCityStringYeq, sub Account holder's city
stStateStringYeq, subAccount holder's state
idautoPersonCountryCountryStringY-Account holder's country
idautoPersonStreetAddressStreet AddressStringY-Account holder's street address
postalCodePostal CodeStringY-Account holder's postal codes
idautoPersonMiddleNameMiddle NameStringN-Account holder's middle name or initial. Often used for username and email generation in a RapidIdentity Connect Action Set.
idautoPersonOfficePhoneOffice PhoneStringN-Account holder's office phone number
idautoPersonPhoneExtensionPhone ExtensionStringN-Account holder's phone extension
idautoPersonHomePhoneHome PhoneStringN-Account holder's home phone number
idautoPersonBirthdateBirthdateDateN-Account holder's birthdate in the following format: yyyy-MM-dd. Often used in the account claim process or for help desk identification.
idautoPersonTermDateSource Termination Date / Last Enroll DateDateN-Student account termination date originating from source systems in the following format: yyyy-MM-dd
idautoPersonGraduationDateGraduation DateDateN-Used to store graduation date for institutions that allow students to access their data beyond their graduation. Must be in the following format: yyyy-MM-dd
idautoPersonEmployeeTypesEmployee TypesStringYeqEmployee types beyond what is stored in employeeType. Examples include Teacher, Admin, and Para. Often used for dynamic role membership and other RapidIdentity access-control lists (ACLs).
idautoPersonDeptCodesDepartment CodesStringYeq, subCodes for all departments in which the account holder is a member. Often used for dynamic role membership and other RapidIdentity ACLs.
idautoPersonDeptCodePrimary Department CodeStringNeq, subAccount holder's primary department code. Often used for dynamic role membership, RapidIdentity ACLs and making decisions in a RapidIdentity Connect Action Set.
idautoPersonDeptDescrsDepartmentsStringYeq, subDescriptions for all departments in which the account holder is a member. Often used for dynamic role membership and other RapidIdentity ACLs. May display in delegation profiles.
idautoPersonDeptDescrDepartmentStringNeq, subAccount holder's primary department description. Often used for dynamic role membership and other RapidIdentity ACLs. May display in Delegation Profiles.
idautoPersonLocCodesLocation CodesStringYeq, subCodes for all locations associated with the account holder. Often used for dynamic role membership and other RapidIdentity ACLs.
idautoPersonLocCodePrimary Location CodeStringNeq, subAccount holder's primary location code. Often used for dynamic role membership, RapidIdentity ACLs, and making decisions in a RapidIdentity Connect Action Set.
idautoPersonLocNamesLocationsStringYeq, subNames for all locations associated with the account holder. Often used for dynamic role membership and other RapidIdentity ACLs. May display in delegation profiles.
idautoPersonLocNamePrimary LocationStringNeq, subAccount holder's primary location name. Often used for dynamic role membership and other RapidIdentity ACLs. May display in delegation profiles.
idautoPersonJobCodesJob CodesStringYeq, subCodes for all jobs associated with the account holder. Often used for dynamic role membership and other RapidIdentity ACLs.
idautoPersonJobCodeJob CodeStringNeq, subAccount holder's primary job code. Often used for dynamic role membership, RapidIdentity ACLs, and making decisions in a RapidIdentity Connect Action Set.
idautoPersonJobTitlesJob TitlesStringYeq, subTitles for all jobs associated with the account holder. Often used for dynamic role membership and other RapidIdentity ACLs. May display in delegation profiles.
idautoPersonJobTitleJob TitleStringNeq, subAccount holder's primary job title. Often used for dynamic role membership and other RapidIdentity ACLs. May display in delegation profiles.
idautoPersonAffiliationsAffiliationsStringYeq, subUsed to store granular affiliations such as Faculty, Staff, Emeritus, Retiree, Student Applicant, Student Admitted, Student Enrolled, Student Graduated, etc.
idautoPersonAffiliationPrimary AffiliationStringNeq, subUsed to store the primary affiliation associated with the account holder
idautoPersonGenderGenderStringN-Account holder's gender
idautoPersonPronounsPronounsStringY-Account holder's pronouns
idautoPersonProfileUrlProfile URLStringN-Account holder's online directory URL, contact cards, and biography page
idautoPersonADProfilePathAD Profile PathStringN-Account holder's Active Directory home directory
idautoPersonBadgeIDsBadge IDsStringY-Account holder's associated proximity badge IDs
idautoPersonEnrollDateStudent Enrollment DateDateNeqStudent's enrollment date in the following format: yyyyMMddHHmmssZ
idautoPersonStartDateStudent Start DateDateTimeNeqStudent's start date in the following format: yyyyMMddHHmmssZ
idautoPersonStaffStartDateStaff Start DateDateTimeNeqStaff member's start date in the following format: yyyyMMddHHmmssZ
idautoPersonStaffEndDateStaff End DateDateTimeNeqStaff member's end date in the following format: yyyyMMddHHmmssZ
idautoPersonStaffAccessTermDateStaff Access Termination DateDateTimeNeqStaff member's access termination date in the following format: yyyyMMddHHmmssZ
idautoPersonStaffLastDateWorkedStaff Last Date WorkedDateTimeNeqStaff member's final day of work in the following format: yyyyMMddHHmmssZ.
idautoPersonContractStartDateContractor Start DateDateTimeNeqContractor's start date in the following format: yyyyMMddHHmmssZ
idautoPersonContractEndDateContractor End DateDateTimeNeqContractor's end date in the following format: yyyyMMddHHmmssZ
idautoPersonContractAccessTermDateContractor Access Termination DateDateTimeNeqContractor's access termination date in the following format: yyyyMMddHHmmssZ
idautoPersonContractLastDateWorkedContractor Last Date WorkedDateTimeNeqContractor's final day of work in the following format: yyyyMMddHHmmssZ
idautoPersonAllAccessTermDateAll Access Termination DateDateTimeN-Account holder's complete access termination date (student, staff, contractor) in the following format: yyyyMMddHHmmssZ
Table 3. Education Attributes
Attribute NameFriendly NameData TypeMulti-ValuedIndexesDescription/Constraints
idautoPersonTeachersTeachersDNYeqDNs of all teachers associated with a student
idautoPersonStudentsStudentsDNYeqDNs of all students associated with a teacher (read-only)
idautoPersonGradeLevelGrade LevelStringYeqStudent grade level. In the rare case where an individual student is associated with multiple grade levels, contact Services to resolve with a RapidIdentity Connect Action Set.
idautoPersonSchoolCodesSchool CodesStringYeqCodes for all schools associated with the account holder. Used by the Insights module, dynamic role membership, and other RapidIdentity ACLs.
idautoPersonSchoolNamesSchool NamesStringYeq, subNames of all schools associated with the account holder. Often used for dynamic role membership and other RapidIdentity ACLs. May display in delegation profiles.
idautoPersonActivityCodesActivity CodesStringY-Activity codes used in determining permissions based on organizational attachment. For students, they are course-related values. For employees, they are related to positions and/or functions within the organization.
idautoPersonCourseIDsCourse IDsStringYeq, subCourse IDs for students
idautoPersonCourseCodesCourse CodesStringYeq, subCourse codes for students
idautoPersonWorkStreetAddressWork Street AddressStringY-Account holder's work street address in a multi-line format
idautoPersonWorkCityWork CityStringN-Account holder's work city
idautoPersonWorkStateWork StateStringN-Account holder's work state or region
idautoPersonWorkCountryWork CountryStringN-Account holder's work country
idautoPersonWorkPostalCodeWork Postal CodeStringN-Account holder's work postal code
idautoPersonManagedOrgsManaged OrgsStringY-IDs of the account holder's managed organizations
Table 4. Special Attributes
Attribute NameFriendly NameData TypeIndexesDescription/Constraints
idautoPersonStatusOverrideOverride Source StatusBooleaneqIf TRUE, the account's idautoDisabled value should not be changed automatically from source system data. The attribute should be cleared rather than set to FALSE.
idautoPersonStatusOverrideReasonOverride Source Status ReasonString-When a status override is applied to an account, this free text attribute can be used to note the reason.
idautoPersonStatusOverrideExpirationOverride Source Status ExpirationDateTime-Used to apply a long-term status override expiration date if it is known when the override should automatically expire. This allows a simple action set to revoke the status override on the specified date.
idautoPersonRenameUsernameRename UsernameString-The new username which will be assigned to the account on the rename date. Any value populated here should also be populated in the idautoPersonUserNameMV attribute. For ID Hub customers, this attribute is managed.
idautoPersonRenameOverrideOverride RenamesBooleaneqIf TRUE, the account's username should not be changed automatically from source system data. The attribute should be cleared instead rather than set to FALSE.
idautoPersonRenameFlagDateRename DateDateeqThe date in yyyy-MM-dd format in which the account will be renamed. Set by Connect Action Set to n days in the future, where n is specified by a customer-defined policy.
idautoPersonActivationDateActivation DateDate-The date in yyyy-MM-dd format on which the account should be automatically enabled. Used by Connect Action Set in cases where an account needs to be created now but not enabled until a specific date.
idautoPersonSourceStatusSource System StatusString-Contains an arbitrary status value from source system (e.g., HR). RapidIdentity Connect Action Sets will use this as a basis for automatic RapidIdentity status changes
idautoPersonToSystem1Sync Person to System 1Boolean-Indicates whether a RapidIdentity Connect Action Set should sync the account to "System 1"
idautoPersonToSystem2Sync Person to System 2Boolean-Indicates whether a RapidIdentity Connect Action Set should sync the account to "System 2"
idautoPersonToSystem3Sync Person to System 3Boolean-Indicates whether a RapidIdentity Connect Action Set should sync the account to "System 3"
idautoPersonToSystem4Sync Person to System 4Boolean-Indicates whether a RapidIdentity Connect Action Set should sync the account to "System 4"
idautoPersonToSystem5Sync Person to System 5Boolean-Indicates whether a RapidIdentity Connect Action Set should sync the account to "System 5"
idautoPersonSafeIdCompromisedDateAccount Compromised DateDateTimepresIndicates when a user's account was marked as compromised via the SafeID feature. Must be in yyyyMMddHHmmssZ format.
idautoPersonPreferredLanguagePreferred LanguageString-Account holder's preferred language
idautoPersonPreferredLastNamePreferred Last NameStringstringNThe account holder's preferred last name
idautoPersonPreferredNamePreferred NameStringstringThe name the account holder prefers to be referred to by
idautoPersonPasswordSetPassword SetBooleanbooleanNIndicates that a user's password has been set through some operation in RapidIdentity
idautoPersonSponsoredAccountStatusSponsored Account StatusStringstringNIndicates a delayed status result for sponsored account operations that are synced via ID Hub
Table 5. Other IDs
Attribute NameFriendly NameData TypeMulti-ValuedIndexesDescription/Constraints
idautoPersonHRIDEmployee IDStringNeq, subHolds the unique identifier from the HR system
idautoPersonStuIDStudent IDStringNeq, subHolds the unique identifier from the student information system
idautoPersonPayrollIDPayroll IDStringNeqHolds the unique identifier from the payroll system
idautoPersonSystem1IDSystem 1 IDStringNeqHolds the unique identifier from System 1
idautoPersonSystem2IDSystem 2 IDStringNeqHolds the unique identifier from System 2
idautoPersonSystem3IDSystem 3 IDStringNeqHolds the unique identifier from System 3
idautoPersonSystem4IDSystem 4 IDStringNeqHolds the unique identifier from System 4
idautoPersonSystem5IDSystem 5 IDStringNeqHolds the unique identifier from System 5
idautoPersonStateIDState IDStringNeqHolds the unique identifier for the account holder's state
idautoPersonDistrictIDDistrict IDStringNeqHolds the unique identifier for the account holder's district
idautoPersonSchoolIDSchool IDStringNeqHolds the unique identifier for the account holder's school
idautoPersonSAMAccountNameAD UsernameStringNeqHolds the account's current sAMAccountName value from AD
idautoPersonPrevSAMAccountNamesPrevious AD UsernamesStringYeqHolds all of the account's previous usernames
idautoPersonManagerIDManager IDStringNeqAccount holder's manager ID
idautoPersonNationalIDNational IDStringNeqAccount holder's national ID
Table 6. Extensible Attributes
Attribute NameFriendly NameData TypeMulti-ValuedUniqueIndexesDescription/Constraints
idautoPersonExt1Custom Attribute 1StringYNeq, subCustom account attribute
idautoPersonExt2Custom Attribute 2StringYNeq, subCustom account attribute
idautoPersonExt3Custom Attribute 3StringYNeq, subCustom account attribute
idautoPersonExt4Custom Attribute 4StringYNeq, subCustom account attribute
idautoPersonExt5Custom Attribute 5StringYNeq, subCustom account attribute
idautoPersonExt6Custom Attribute 6StringYNeq, subCustom account attribute
idautoPersonExt7Custom Attribute 7StringYNeq, subCustom account attribute
idautoPersonExt8Custom Attribute 8StringYNeq, subCustom account attribute
idautoPersonExt9Custom Attribute 9StringYNeq, subCustom account attribute
idautoPersonExt10Custom Attribute 10StringYNeq, subCustom account attribute
idautoPersonExt11Custom Attribute 11StringYNeq, subCustom account attribute
idautoPersonExt12Custom Attribute 12StringYNeq, subCustom account attribute
idautoPersonExt13Custom Attribute 13StringYNeq, subCustom account attribute
idautoPersonExt14Custom Attribute 14StringYNeq, subCustom account attribute
idautoPersonExt15Custom Attribute 15StringYNeq, subCustom account attribute
idautoPersonExt16Custom Attribute 16StringYNeq, subCustom account attribute
idautoPersonExt17Custom Attribute 17StringYNeq, subCustom account attribute
idautoPersonExt18Custom Attribute 18StringYNeq, subCustom account attribute
idautoPersonExt19Custom Attribute 19StringYNeq, subCustom account attribute
idautoPersonExt20Custom Attribute 20StringYNeq, subCustom account attribute
idautoPersonExt21Custom Attribute 21StringYNeq, subCustom account attribute
idautoPersonExt22Custom Attribute 22StringYNeq, subCustom account attribute
idautoPersonExt23Custom Attribute 23StringYNeq, subCustom account attribute
idautoPersonExt24Custom Attribute 24StringYNeq, subCustom account attribute
idautoPersonExt25Custom Attribute 25StringYNeq, subCustom account attribute
idautoPersonExtBool1Custom Boolean Attribute 1BooleanNNeqCustom flag. The attribute should be cleared rather than set to FALSE.
idautoPersonExtBool2Custom Boolean Attribute 2BooleanNNeqCustom flag. The attribute should be cleared rather than set to FALSE.
idautoPersonExtBool3Custom Boolean Attribute 3BooleanNNeqCustom flag. The attribute should be cleared rather than set to FALSE.
idautoPersonExtBool4Custom Boolean Attribute 4BooleanNNeqCustom flag. The attribute should be cleared rather than set to FALSE.
idautoPersonExtBool5Custom Boolean Attribute 5BooleanNNeqCustom flag. The attribute should be cleared rather than set to FALSE.
idautoPersonAppRoleFriendlyNamesApp Role Friendly NamesStringYN-The friendly names for app roles
idautoPersonAppRoles1Application 1 RolesStringYNeqArbitrary role values for "Application 1" (for example, AWS SAML Roles)
idautoPersonAppRoles2Application 2 RolesStringYNeqArbitrary role values for Application 2
idautoPersonAppRoles3Application 3 RolesStringYNeqArbitrary role values for Application 3
idautoPersonAppRoles4Application 4 RolesStringYNeqArbitrary role values for Application 4
idautoPersonAppRoles5Application 5 RolesStringYNeqArbitrary role values for Application 5
idautoPersonAppRoles6Application 6 RolesStringYNeqArbitrary role values for Application 6
idautoPersonAppRoles7Application 7 RolesStringYNeqArbitrary role values for Application 7
idautoPersonAppRoles8Application 8 RolesStringYNeqArbitrary role values for Application 8
idautoPersonAppRoles9Application 9 RolesStringYNeqArbitrary role values for Application 9
idautoPersonAppRoles10Application 10 RolesStringYNeqArbitrary role values for Application 10