It may be desired to change the order of the UPN suffix with is displayed in the dropdown menu in the Active Roles Console and the Active Roles Web Interface.
Examining the edsaUPNSuffix attribute shows that it is shaped by the Built-in Policy - Default Generation Rules but there is no such policy listed within Active Roles.
This particular policy comes directly from Active Directory Domains and Trusts.
The display order can be changed within Active Roles by creating a Property Generation and Validation policy on the edsaUPNSuffix. As long as the Active Roles Policy does not contain any values which are not also present in Active Directory Domains and Trusts, there will be no conflict, and the order can be changed or the list can be shortened if desired.
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center