NOTE: The Attributes tab only appears after you have successfully added a new asset and is accessed by editing the asset.
In the web client, the Attributes tab is used to add attributes to directory assets (including Active Directory and LDAP). For more information, see Adding identity and authentication providers.
IMPORTANT: Some Active Directory attributes are fixed and cannot be changed.
Safeguard for Privileged Passwords Attribute | Directory Attribute |
---|---|
User | |
ObjectClass |
Default: user for Active Directory, inetOrgPerson for LDAP Click Browse to select a class definition that defines the valid attributes for the user object class. |
Username |
sAMAccountName for Active Directory, cn for LDAP |
Password |
userPassword for LDAP |
Description |
description |
MemberOf |
Blank by default, this attribute can be set to a directory schema attribute that contains the list of directory groups of which the user is a member. |
Alternate Login Name |
userPrincipalName NOTE: By default the Alternate Login Name attribute for directories is set to userPrincipalName, however another directory attribute containing a UPN type account name can be used. This attribute can be used in conjunction with the API's UseAltLoginName setting (disabled by default) which will instead use the Alternate Login Name as the account name. The API is PUT https://<host>/service/core/v3/AccessPolicies/{id} where the {id} is the id of the accessPolicy where you'll set the UseAltLoginName to true. UseAltLoginName is a boolean field on the asset data object. |
Group | |
ObjectClass |
Default: group for Active Directory, groupOfNames for LDAP Click Browse to select a class definition that defines the valid attributes for the computer object class. |
Name |
sAMAccountName for Active Directory, cn for LDAP |
Member |
member |
Computer | |
ObjectClass |
Default: computer for Active Directory, ipHost for LDAP Click Browse to select a class definition that defines the valid attributes for the computer object class. |
Name |
cn |
Network Address |
dNSHostName for Active Directory, ipHostNumber for LDAP |
Operating System |
operatingSystem for Active Directory |
Operating System Version |
operatingSystemVersion for Active Directory |
Description |
description |