Custom data from Active Directory
With the configurations below, IdExchange can print custom data from Active Directory (that has not been enrolled into IDMS).
Available mappings:
The AsureID policy is based on the PIV print specifications. There are certain values on this policy that can be overwritten print custom data. These values are:
AsureID objects that can be mapped for custom data |
---|
EMPLOYEE_AFFILIATION_LINE_1 |
PHYS_CHAR_HEIGHT |
PHYS_CHAR_EYE_COLOR |
Checklist
- AD Attribute defined in the system configuration of the directory the user resides
- Mapping is in the IdExchange.UserCredentialPrintingOptions
- The credentialType policy specifies the customattribute property.
- The proper active directory must be specified with the exact spelling and exact case. Also, that attribute must be populated. The formatting instructions that to in to the IdExchange.UserCredentialPrintingOptions table must also be spelled exactly the same with the proper casing
- AsureID policy has the objects defined
Configuration Steps
Step Number | Procedure | Example |
---|---|---|
1 | Go to the IdExchange.UserCredentialPrintingOptions and add the mappings adattribute:employeeId EMPLOYEE_AFFILIATION_LINE_1 adattribute:givenName PHYS_CHAR_HEIGHT | |
2 | In the system connections tab, locate the directory the user is in. Next, configure the connections to retrieve the additional data values from Active Directory. *Note: the mail value must also be configured. | |
3 | Go to the AureID template and verify that the following objects exist: EMPLOYEE_AFFILIATION_LINE_1 PHYS_CHAR_HEIGHT PHYS_CHAR_EYE_COLOR | |
4 | Locate the credential policy that will be used for printing. Within the Issuance and Printing Options, select the custom data print options. Save the policy. |