Missing State Attribute in MIM

What? No State…?

Missing State Attribute in MIM Screenshot: FIM User Account Contact Info
FIM User Account Contact Info

Something that I’ve always found peculiar is that “State/province” is not a default attribute in the MIM Portal. One of the main Directory Services systems that we synchronize with is Active Directory (AD). AD has “State/Province” because it’s useful information to include with a user’s identity. And when deploying MIM to an organization, one of the objectives is to provision users from the MIM Portal. In this blog post, I will detail the steps required to add State/province to the MIM Portal to make this possible.

Note: We are assuming that you have already configured user provisioning from the MIM Portal to AD and simply need to add the State attribute to the MIM Portal and synchronize the new State attribute to AD.

Create new Attribute/Binding in the MIM Portal

  1. From the MIM Portal, select Administration –> Schema Management –> All Attributes
  2. From the Schema Management – All Attributes menu, select New
  3. Create a new attribute with the following properties:

System name: State
Display Name: State/province
Data Type: Indexed string

  1. Select Administration –> Schema Management –> All Bindings
  2. From the Schema Management – All Bindings menu, select New

Resource Type: User
Attribute Type: State
Ensure that the MIM Sync Service is evaluating the “st” attribute

  1. Open the MIM Sync Tool and select the properties of the AD Management Agent
  2. Navigate to Select Attributes
  3. Ensure that “st” is checked

Configure attribute mappings

  1. Using the MIM Sync Tool, select the properties of the MIM MA
  2. Click on Configure Attribute Flow and Select Object Type: Person
  3. Add attribute Import mappings as follows:

Data source attribute: State
Metaverse attribute: st

Update your AD User Outbound Portal Sync Rule

  1. Using the MIM Portal, edit the AD User Outbound Synchronization Rule.
  2. On the Outbound Attribute Flow tabe, add the following:

Source: st
Destination: st

Update MPR to allow for synchronization of the new attribute

  1. Open the MIM Portal and navigate to Administration –> Management Policy Rules
  2. Search for “Synchronization: Synchronization account controls users it synchronizes”
  3. Open the properties of the MPR and select the Target Resources tab
  4. Add “State” to the list of specific attributes

Edit RCDC for User Create and Edit to add State

Showing you how to edit the RCDC so that the new State attribute shows up in the User create and User Edit forms is out of scope for this blog posting. There are plenty of “How to” articles on the internet that can be followed.

About Matthew Brooks

Over 15 years experience in the IdAM field.

Leave a Reply

Your email address will not be published.