Article Number
000036610
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Issue
This article shows the steps for adding a new user attribute for users in the internal database or for mapping an external user attribute from Active Directory.
While this article refers to steps to add an attribute for Active Directory, similar steps can be used with any external identity source supported with Authentication Manager.
Resolution
To add a new user attribute in Authentication Manager
- Login to the Security Console on the primary Authentication Manager server as a super admin.
- Click on Identity > Identity Attribute Definition > Add New.
- Under Identity Attribute Definition Basics, add the new Attribute Name and complete the other fields as desired.
- Under Format, add the Data Type, and other information as needed.
- Under Options, for Attribute Storage choose Store this attribute in the same location as the user record (internal database or external identity source).
- Under Identity Source Mapping:
- For the internal database: Define the attribute name you want to be saved in the database.
- For Active Directory: Provide the attribute name from the Active Directory to be mapped. Check the steps below on how to get the attribute name from Active Directory.
- Click Save. This new attribute is now seen when creating new users or when viewing existing user profiles.
How to get the attribute name in Active Directory
- Logon to the Windows machine of this Active Directory.
- Open Active Directory Users and Computers.
- Click on View > Advanced Features.
- Go to any user you have mapped.
- Right click on the user and select Properties.
- Click on Attribute Editor.
- Search for the attribute value you want to map and take a note of the attribute name. The screenshot below shows the Job Title attribute named here as title:
Image description
- Key in the correct attribute name in the Identity Source Mapping field for either the internal database or your external identity source.
For the internal database, the attribute will be created. For an external identity source, the attribute must already exist, and is read-only.
- Click Save or Save & Add Another.
Notes
After making this change when you edit or view the user attribute will be seen and will be available to add in user reports.