Starting in all Cloud Access Service (CAS) deployments in September 2026
At a Glance
| What is changing | All RSA Cloud Access Service (CAS) deployments can migrate from using each identity (ID) source’s native user schema to a single Common User Schema used across Policies, Applications, and other CAS features. |
| When it happens | Starting September 2026. Each deployment has a scheduled automatic migration date shown on the CAS Administration Console home page. |
| How it runs |
|
| Action required | Review the Common User Schema Migration Dashboard and resolve any blocking issues before your scheduled date. See Actions Required Before Migration. |
Schema Migration Dashboard
| Where to find it | Go to the Cloud Administration Console Home > Common User Schema Migration Dashboard |
| What it shows |
|
Actions Required Before Automatic Migration
| Purpose | Ensure your deployment is ready and resolve any issues that could block automatic migration. |
| Procedure |
|
|
Need help?
| If you cannot resolve an issue, contact RSA Technical Support. |
Background: Why This Change
|
What is a user schema?
| CAS pulls user data into Authentication & Access Policies, application configurations, User Self-Service flows, and other features. That data comes from an ID source, described by its user schema, which is the set of user attribute names defined for that ID source type. For example, the username attribute maps to sAMAccountName in Active Directory (AD) and uid in LDAP. |
|
Why was it simpler before?
|
At launch, CAS used the ID source's native schema as the only way to bring in user data. Only LDAP Directory and Active Directory ID sources were supported, and customers typically used one ID source type per deployment, so it was easy to manage.
|
|
Why is this now a challenge?
| In 2026, CAS supports six ID source types across four different user schemas. Using native schemas requires administrators to understand the schema of every identity source in their deployment. Only Policies fully support the use of multiple user schemas; configuring other features ranges from difficult to impossible. |
| The solution |
The 25 most commonly used user attributes in CAS are mapped to a Common User Schema within each identity source configuration. That common schema, not the native one, is then used across Policies, Applications, and other CAS features. |
Common Schema Attribute List Mapped to Native User Schema
The following table shows how Common User Schema attributes map to native user schema attributes for each supported identity source. The following terms are used in the table:
- NEW: Attribute newly added for this identity source type.
- N/A: No equivalent attribute exists for this identity source.
- No default: No native attribute is mapped by default; administrators may configure a mapping.
- Not passed by AM: The attribute may exist in the Authentication Manager Internal Database but is not passed from Authentication Manager to CAS.
|
Common Schema Display Name |
AD On-Prem |
LDAP |
SCIM Managed |
Local (SCIM Provisioning never enabled) |
Local (SCIM Provisioning enabled at any time) |
Entra ID |
AM Internal Database |
|
Username |
sAMAccountName |
uid |
userName |
userName |
userName |
userName |
userName |
|
External Unique Identifier |
distinguishedName |
entryDN |
N/A |
N/A |
N/A |
N/A |
N/A |
|
Secondary External Unique Identifier |
objectGUID |
entryUUID |
N/A |
N/A |
N/A |
N/A |
N/A |
|
Email Address |
|
|
emails.work.value |
|
emails.work.value |
emails.work.value |
emails.work.value |
|
First Name |
givenName |
givenName |
name.givenName |
givenName |
name.givenName |
name.givenName |
name.givenName |
|
Last Name |
sn |
sn |
name.familyName |
sn |
name.familyName |
name.familyName |
name.familyName |
|
User Status |
userAccountControl |
ds-pwp-account-disabled |
active |
active |
active |
active |
active |
|
User Account Expiration |
accountExpires |
ds-pwp-account-expiration-time |
N/A |
N/A |
N/A |
N/A |
N/A |
|
Manager |
manager |
manager |
extension.manager.value |
manager |
extension.manager.value |
extension.manager.value |
extension.manager.value |
|
Alternate Username |
userPrincipalName |
(no default) |
(no default) |
ALTERNATE_USERNAME |
(no default) |
(no default) |
displayName |
|
SMS OTP Phone |
mobile |
mobile |
phoneNumbers. |
SMS_PHONE |
phoneNumbers. |
phoneNumbers. |
phoneNumbers. |
|
Voice OTP Phone |
telephoneNumber |
telephoneNumber |
phoneNumbers. |
VOICE_PHONE |
phoneNumbers. |
phoneNumbers. |
phoneNumbers. |
|
Groups |
memberOf |
member |
N/A |
virtualGroups |
N/A |
N/A |
N/A |
|
Business Category |
businessCategory |
businessCategory |
(no default) |
NEW |
(no default) |
(no default) |
N/A |
|
Company or Organization |
company |
company |
enterprise.extension.organization |
NEW |
enterprise.extension.organization |
enterprise.extension.organization |
enterprise.extension.organization |
|
Country Code |
c |
c |
addresses.work.country |
NEW |
addresses.work.country |
addresses.work.country |
addresses.work.country |
|
Department |
department |
N/A |
enterprise.extension.department |
NEW |
enterprise.extension.department |
enterprise. |
enterprise. |
|
Description |
description |
description |
(no default) |
NEW |
(no default) |
(no default) |
N/A |
|
Display Name |
displayName |
displayName |
displayName |
NEW |
displayName |
displayName |
displayName |
|
Employee Number |
employeeNumber |
employeeNumber |
enterprise.extension. |
NEW |
enterprise.extension.employeeNumber |
enterprise. |
enterprise. |
|
Employee Type |
employeeType |
employeeType |
userType |
NEW |
userType |
userType |
userType |
|
Full Name |
cn |
cn |
name.formatted |
NEW |
name.formatted |
name.formatted |
name.formatted |
|
Home Email |
otherMailbox |
(no default) |
emails.home.value |
NEW |
emails.home.value |
emails.home.value |
emails.home.value |
|
Mobile |
mobile |
mobile |
phoneNumbers. |
NEW |
phoneNumbers.mobile.value |
phoneNumbers.mobile.value |
phoneNumbers.mobile.value |
|
Work Phone |
telephoneNumber |
telephoneNumber |
phoneNumbers. |
NEW |
phoneNumbers.work.value |
phoneNumbers.work.value | phoneNumbers.work.value (not passed by AM) |
Related Articles
RSA July 2026 Release Announcements 27Number of Views Cloud Access Service and Authenticators Historical Release Notes (April 2026 - August 2025) 202Number of Views July 2026 Cloud Access Service Release Notes 7Number of Views RSA Identity Governance and Lifecycle 7.0.2 upgrade fails during schema migration with 'ORA-06512: at "AVUSER.SIEM_INTEGRA… 287Number of Views Cloud Access Service and Authenticators Historical Release Notes (July 2021 - September 2020) 178Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Governance & Lifecycle 8.0.0 Installation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide Troubleshooting RSA MFA Agent for Microsoft Windows How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device