Skip to main content
Skip table of contents

Custom data from Active Directory

With the configurations below, IdExchange can print custom data from Active Directory (that has not been enrolled into IDMS).

Available mappings:

The AsureID policy is based on the PIV print specifications. There are certain values on this policy that can be overwritten print custom data. These values are:

AsureID objects that can be mapped for custom data
EMPLOYEE_AFFILIATION_LINE_1
PHYS_CHAR_HEIGHT
PHYS_CHAR_EYE_COLOR

Checklist

  • AD Attribute defined in the system configuration of the directory the user resides
  • Mapping is in the IdExchange.UserCredentialPrintingOptions
  • The credentialType policy specifies the customattribute property.
  • The proper active directory must be specified with the exact spelling and exact case. Also, that attribute must be populated. The formatting instructions that to in to the IdExchange.UserCredentialPrintingOptions table must also be spelled exactly the same with the proper casing
  • AsureID policy has the objects defined

Configuration Steps

Step NumberProcedureExample
1

Go to the IdExchange.UserCredentialPrintingOptions and add the mappings

adattribute:employeeId EMPLOYEE_AFFILIATION_LINE_1

adattribute:givenName PHYS_CHAR_HEIGHT

2

In the system connections tab, locate the directory the user is in. Next, configure the connections to retrieve the additional data values from Active Directory.

*Note: the mail value must also be configured.

3

Go to the AureID template and verify that the following objects exist:

EMPLOYEE_AFFILIATION_LINE_1

PHYS_CHAR_HEIGHT

PHYS_CHAR_EYE_COLOR



4Locate the credential policy that will be used for printing. Within the Issuance and Printing Options, select the custom data print options. Save the policy.

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.