Owner Creation
The ownership creation rules allow users to configure how new identities are automatically created from one or more matching accounts. If an account cannot be mapped to an existing identity, then the create rules determine whether a new identity should be created to which the account can be mapped.
To filter the table view, use the checkboxes to enable/disable view options, like
- Default Rules: These are Hydden’s out of the box default rules, they can be viewed, but not edited.
- Custom Rules: These are rules created on your tenant.
Use Search to trim the view down to a specific context.
Creating an Owner Creation Rule
Navigate to Configuration | Identify and select the Owner Creation tab.
Click + Add Rule.
Specify the Rule Priority. A lower number specifies a higher priority in the evaluation order. By default the modal opens with a value of 1 (highest priority).
Enter a Name and Description for your rule for organizational clarity.
The Category field is prefilled based on this being a Create Owner rule.
Under the Owner Creation Requirements
The Account Type(optional) can be
- User Account (default)
- Service Account
- Resource Account
- Computer Account
- Vaulted Account
- Federated Account
If not specified, all types apply.
Note: If both account Type and classification are configured, then the rule will apply to an account that matches either the account type or classification.
An Account Classification (optional) if configured.
A RegEx Pattern to be match by the rule.
Under Require Email, select from
- Email or UPN
- UPN
If required, select Require a space in the display name.
Optionally, select Require two or more matching accounts before creating an identity.
User the RegEx test and Preview options to verify your rule.
Once you are ready to use the rule in your environment, check the Enable Rule checkbox at the top of the modal. The Actions column indicates if a custom rule is enabled or disabled. It will either have a checkmark for enabled or an x for disabled.
Click Add.
Also, refer to Testing a RegEx rule and Previewing a Rule under the Account Mapping topic.