Compound Ldap Attributes

From idenprotect Knowledge Base
Jump to: navigation, search


On the idenprotect server it is possible to create Extra Ldap Parameters within a customer account that map to multiple attributes within Active Directory or a combination of attributes and static text.

For more general information about extra ldap attributes refer to LDAP Extra Parameters

Creating a Compound Ldap Attribute

To create compound attributes you need to specify the Active Directory attributes within curly brackets, {}, and then other text will be treated as static text.

For example to create a compound attribute that was a users account name followed by "@domain" where "@domain" was the same for all users, then you would create a mapping under Extra Ldap Parameters that had a LDAP Field ID of {sAMAccountName}


A Compound Attribute can also map to multiple Active Directory Attributes, for example you can create your own Full Name field by combining the givenName and SN fields