Hello,
I have a couple of questions regarding the default integration with a directory.
Multi valued attributes:
As far as I can tell, IG&L does not support multi valued attributes. Which, to me, is a bug.
Does anyone of you used the standard LDAP connector and use multi value attributes?
I've seen this: How create an AD account with multiple values in proxyAddresses attribute
Is that the recommended way to add/delete an attribute?
Object Class:
is there any way to add/remove an object class depending on an entitlement?
A brief example:
if a user requests a linux account. The ldap account should add an object class containing the attributes needed by the linux-system.
I haven't found anything on the community, but maybe my searching skills need to be tuned...
TiA
The following KB article describes a method to remove attributes using AFX.
000036921 - How to update an Active Directory Account Attribute to have no value <not set> using an Active Directory AFX Connector in RSA Identity Governance & Lifecycle
Again all the caveats in the discussion you already quoted apply.