Knowledge Article
Best Practices: Attribute Sync
Author
neil_mcglennon
SailPoint
- Overview
- What is Attribute Sync?
- Configuring Attribute Sync
- Key Considerations for Attribute Eligibility and Mapping:
- When Does Attribute Sync Kick In? Automatic and Manual Triggers
- Best Practices: Implementing Attribute Sync Effectively
- Testing Attribute Sync: A Staged Approach
- Deployment Recommendations: Controlled Rollout
- Tracking and Monitoring Attribute Sync
- Frequently Asked Questions (FAQs)
- Summary
Overview
In the complex world of Identity and Access Management (IAM), ensuring data consistency across distributed systems is a challenge. This is where attribute synchronization in Identity Security Cloud becomes an indispensable tool. Far more than a simple data replication mechanism, attribute sync is a core provisioning feature designed to keep your identity data harmonized across your enterprise.
This document is intended to supplement the product documentation (https://documentation.sailpoint.com/saas/help/provisioning/attr_sync.html) to provide recommendations for effectively configuring and using attribute sync in Identity Security Cloud. It also highlights planning, testing, deployment, and go-live considerations.
What is Attribute Sync?
At its heart, attribute synchronization is a system process that compares values of identity attributes to corresponding account attributes on a source. When these values diverge, Identity Security Cloud acts: it updates the account attribute to match the identity attribute and provisions that change to the target source. If the values are identical, no action is taken – they are considered "in sync."
It’s important to understand that attribute synchronization only applies to existing, correlated accounts. It will not create new accounts for identities, nor does it apply to uncorrelated accounts as they lack the necessary identity data for enforcement. When a new account is created for a user through another operation, attribute sync is enforced for that new account.
Configuring Attribute Sync
Setting up attribute sync involves specifying which account attributes on a given source should be kept in sync with their corresponding identity attributes.
To configure attribute sync:
- Navigate to Admin > Connections > Sources.
- Select or edit the desired source.
- In the Account Management section, choose Attribute Sync. Here, you'll see eligible attributes and their mappings as defined in the source's Create Account definition.
- In the Sync with Identity column, select the attributes you wish to synchronize.
Key Considerations for Attribute Eligibility and Mapping:
- An attribute must be included in the source's Create Account definition.
- It must be mapped directly from an account attribute within that definition using the identity attribute radio button.
- The built-in Manager identity attribute has a special caveat: While it can be used in the Create Account definition, it cannot be directly used for attribute sync. To sync manager names, you must define a custom identity attribute (e.g., managerToSync), populate it with the user's manager name through mapping, and then use that custom attribute in both your Create Account definition and Attribute Sync configuration.
- If an identity attribute is explicitly set to null by its identity profile mapping, attribute sync will propagate this null value to account attributes. Attributes with null values are generally considered unsynchronized. This can be mitigated by configuring transforms in the identity profile of the authoritative source
- Multi-valued attribute sync is supported, but it requires custom rules for implementation. For more information, refer to the developer community (https://developer.sailpoint.com/docs/extensibility/rules).
When Does Attribute Sync Kick In? Automatic and Manual Triggers
Attribute sync is dynamic, reacting to changes across your identity landscape. While it often operates silently in the background, provisioning updates as needed; you also have control over manual triggers.
Automatic Triggers:
- Authoritative Source Aggregation: When an authoritative source updates an identity attribute, attribute sync can automatically provision that change to configured sources.
- Native Source System Changes: If a change is detected on an account attribute made natively in the source system, Identity Security Cloud may override this change based on your sync configuration to maintain consistency with the identity attribute.
- Account Relocation/Correlation: If a source account is moved or correlated to a different identity that has differing attribute values, attribute sync will enforce consistency.
It's important to note that automatic syncs primarily capture and synchronize only the changes made by these processes. If you need to evaluate all configured attributes for an identity, a manual sync is required.
Manual Triggers:
- Bulk Sync: After initially defining new sync configurations, or when recovering from a sync failure, you can initiate a bulk attribute sync for all accounts on a source by selecting the Sync option on the Attribute Sync configuration page. This option is only available when the source is healthy. To limit provisioning traffic, this full sync can only be run up to 3 times in a 24-hour period per source.
- Single Identity Sync: For individual identities, you can manually trigger an attribute sync. This is useful for troubleshooting or immediate updates. To do this, go to Admin > Identity Management > Identities, find the identity, and select Actions > Synchronize Attributes. This immediately analyzes all accounts for that identity.
Best Practices: Implementing Attribute Sync Effectively
To truly leverage attribute sync without introducing performance bottlenecks or data integrity issues, you must adhere to best practices.
- Limit What You Sync:
- Just because you can, doesn't mean you should. Every synced attribute adds provisioning load to Identity Security Cloud, your network, and the target system.
- Consider the necessity: Only sync attributes that are necessary for consistency and business operations.
- Performance implications: Constantly changing attributes, when synced in high volume, can impact overall system performance.
- Aggregation Considerations:
- Frequent Aggregation: SailPoint recommends aggregating authoritative and attribute sync sources daily, or even multiple times a day, especially for critical attributes.
- Timely Data: Attribute sync relies on data recorded in Identity Security Cloud. Its effectiveness is directly tied to how frequently you aggregate data changes from authoritative sources.
- Connector Optimization: For optimal performance, utilize connector optimization features like delta aggregations whenever possible.
- Source Considerations:
- Direct-Connected Sources are Best: Attribute sync is most effective for direct-connected sources where provisioning is automated.
- Avoid Manual Fulfillment: If provisioning to a source requires manual fulfillment (e.g., via tasks) or relies on integrations like ServiceNow for ticket-based fulfillment, attribute sync might not be the best choice. It could generate a high volume of manual work assignments.
- Data Model Consistency is CRITICAL:
- This is perhaps one of the most vital best practices. Verify through rigorous testing that the data model representations of provisioned values match what is being aggregated.
- Common Mismatches and Solutions:
- Extra Whitespaces: "Austin" vs. "Austin ". Solution: Add trim transforms to data coming in or being provisioned out.
- Capitalization Differences: "Austin" vs. "AUSTIN". Solution: Implement case normalization transforms (e.g., capitalize first letter, make others lowercase) for data ingress or egress. Note that sync is case-sensitive and will be enforced if cases don't match.
- Dates / Times: "2018-01-01" vs. "2018-01-01T00:00:00Z". Solution: Use date normalization transforms. Consider dropping time components if only the date is relevant.
- Manage the Number of Attributes to Sync:
- While there's no hard technical limit, most organizations typically sync fewer than twenty attributes across all sources.
- Provisioning Load: Attribute sync generates provisioning events that are added to your provisioning queues, albeit at a lower priority. A large number of synced attributes, especially with frequent changes, can introduce delays in other provisioning processes.
- Target System Impact: These provisioning transactions also create load on the target systems themselves. Excessive attribute sync can inadvertently cause performance issues on systems with constantly changing data.
- Safeguards and Cautions:
- Built-in Safeguards: Identity Security Cloud has safeguards to prevent unnecessary repeated sync attempts when attribute values are logically in sync but appear different due to system-specific representations (e.g., leading/trailing spaces, null representations, boolean expressions).
- Avoid Syncing Rule-Modified Attributes: If your aggregation or provisioning processes modify attribute values through rules, those attributes should generally NOT be configured for attribute sync. This creates a high risk of a sync loop, where Identity Security Cloud repeatedly attempts to resynchronize values that are constantly being altered by rules, preventing them from ever truly aligning.
Testing Attribute Sync: A Staged Approach
Thorough testing is a pre-requisite for a successful attribute sync implementation and can help identify potential issues before production rollout.
- Test Environment:
- Always test in a test/sandbox environment using a limited, production-quality dataset that is representative of your actual data.
- The goal is to verify predictable behavior before moving configurations to production.
- Testing Process:
- Start Manual: Begin with manual attribute sync for single identities. This allows you to control the impact, easily verify preconditions, and isolate issues. (https://documentation.sailpoint.com/saas/help/provisioning/attr_sync.html#manually-synchronizing-a-single-identity)
- Avoid Large-Scale Automated Tests: Sandbox tenants don't have the same scalability as production. If you must test automated sync, use small, controlled datasets.
- Remember that event-based attribute sync will still run in response to data changes discovered during aggregations, even in testing.
- What to Look for During Testing:
- Bad Data: Identify differences in attribute values or how data is represented across systems.
- Attribute Sync Repetition: Look for instances where attribute sync repeatedly attempts to update values, especially if they appear to be the same. This often indicates a data model mismatch issue.
- Attribute Sync Errors: Monitor for provisioning errors or issues in the fulfillment of sync activities.
- Example Attribute Sync Test Case
- Typically, attribute sync test cases resemble this example.
Note: This attribute sync test case refers to an example scenario in which a "city" identity attribute is to be synced into the location account attribute "l" on users' Active Directory accounts.
- Typically, attribute sync test cases resemble this example.
Pre-Conditions:
- Active Directory account has been aggregated and correlated to an identity.
- Identity attribute 'city' has a different value than Active Directory attribute 'l'.
- Attribute sync is enabled on the Active Directory source, with identity attribute 'city' synced to account attribute 'l'
Test Steps:
- Look up the target identity in the admin user interface by going to Identities > Identity List.
- Verify that the identity attribute 'city' has a value. Note its value.
- Under the Accounts tab, click the Active Directory account.
- Verify that the account attribute 'l' has a value. Note its value.
- Compare values from Step 2 and Step 4; they should be different.
- Click Synchronize Attributes from the identity actions panel.
- Click Activities from the identity.
- Observe that there are attribute sync activities sent out. (May have to wait / refresh the page a few times.)
- Under the Accounts tab, click the Active Directory account.
- Click Aggregate Account under the Active Directory account options.
- Verify that the account attribute 'l' has a value. Note its value.
- Compare values from Step 2 and Step 11; they should be the same.
Expected Results:
An account attribute sync provisioning event should have been logged in the activities, and once aggregated, reflects the identity attribute which was sent.
Deployment Recommendations: Controlled Rollout
Once thoroughly tested in sandbox, deploy attribute sync to production with care and a phased approach.
- Controlled Rollout: Implement configurations slowly and in a controlled manner. This prevents overwhelming downstream systems with too many provisioning requests.
- Manual Tests: After defining configurations, perform manual attribute syncs with a few target identities. This allows you to address any last-minute issues before broader automated syncs occur.
- Source-by-Source, Attribute-by-Attribute: If multiple sources require attribute sync, enable it for one source at a time, and within that source, limit the number of attributes you enable at once.
- Timing for Major Changes: If attribute sync is expected to generate a significant volume of changes, consider enabling it during "off-hours", such as weekends or holidays.
- Continuous Monitoring: Once enabled, monitor the attribute sync status by watching the monitor and provisioning activities pages in the admin UI. Also, continue to run aggregations frequently and look for repetitive synchronization issues, just as you would during testing.
Tracking and Monitoring Attribute Sync
Monitoring your attribute sync activities is key to ensuring smooth operations and quickly addressing any issues. Please refer to the documentation to learn how to perform these tasks. https://documentation.sailpoint.com/saas/help/provisioning/attr_sync.html#tracking-attribute-sync
Frequently Asked Questions (FAQs)
Here are some common questions that arise during attribute sync implementation:
- How do I know when the attribute sync process is done? Event-based attribute sync records individual events for each impacted identity. You can search for Events labeled “Modify Account Passed” or “Modify Account Failed” to see records, values, and error messages. The history for scheduled attribute sync jobs is visible in Admin > Dashboard > Monitor.
- Can I run aggregations during an attribute sync? Absolutely. Event-driven attribute sync is initiated because of data changes discovered in aggregations, so they will often run concurrently. Attribute sync does not negatively impact the performance of other processing tasks like aggregation.
- Do all attributes get synced every time an identity or target account changes, or every time the job runs? No, not all attributes. Attribute sync only acts on values that need to be provisioned because they are part of a sync configuration and their values do not match. Once an account record matches the identity record (and is aggregated), attribute sync will not occur again until the data values change once more.
Summary
- Attribute synchronization in Identity Security Cloud is a powerful feature for maintaining data consistency across your enterprise.
- To implement an effective and resilient attribute sync strategy, technical professionals should:
- Understand its mechanics, which involve comparing identity and account attribute values and updating account attributes to match identity attributes when they differ.
- Adhere to best practices, covering areas such as configuration, aggregation, source considerations, and data models.
- Prioritize data model alignment, as mismatches in how values are represented (e.g., extra whitespaces, capitalization differences, or varying date/time formats) can lead to attributes never appearing in sync and cause repeated sync attempts.
- Employ cautious deployment strategies, including controlled rollouts, starting with manual tests, enabling sync source-by-source or attribute-by-attribute, and carefully evaluating impacts on target systems.
- Leverage monitoring tools to track sync activity, view sync percentages, and examine event records for provisioning actions