Workday to Active Directory User Provisioning and Renames

ritmo2k 811 Reputation points
2023-09-25T18:58:45.7866667+00:00

Hello,

Does anyone know how the Workday to Active Directory User Provisioning connector handles employee renames where changed data affects the sAMAccountName and userPrincipalName (and potentially the cn) in Active Directory?

Does the connector attempt to rename previously provisioned accounts that have a valid matching attribute?

Thank you.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft Security | Microsoft Entra | Other
0 comments No comments
{count} votes

Accepted answer
  1. Tech-Hyd-1989 5,816 Reputation points
    2023-09-26T09:43:07.5366667+00:00

    Hello ritmo2k

    Yes, the Workday to Active Directory User Provisioning connector does attempt to rename previously provisioned accounts that have a valid matching attribute. The connector will use the sAMAccountName or userPrincipalName attribute to match the Active Directory account to the Workday account. If the sAMAccountName or userPrincipalName attribute has changed in Workday, the connector will attempt to rename the Active Directory account to match the new value.

    If the Active Directory account is already in use by another user, the connector will fail to rename the account. In this case, you will need to manually rename the Active Directory account.

    Here is a more detailed explanation of how the connector handles employee renames:

    1. The connector will first check to see if the Workday account has a valid matching attribute in Active Directory. If the Workday account does not have a valid matching attribute, the connector will create a new Active Directory account.
    2. If the Workday account has a valid matching attribute in Active Directory, the connector will check to see if the sAMAccountName or userPrincipalName attribute has changed in Workday. If the sAMAccountName or userPrincipalName attribute has not changed, the connector will do nothing.
    3. If the sAMAccountName or userPrincipalName attribute has changed in Workday, the connector will attempt to rename the Active Directory account to match the new value. If the Active Directory account is already in use by another user, the connector will fail to rename the account.

    You can configure the connector to rename the Active Directory account using the following settings:

    • Rename AD account if sAMAccountName or userPrincipalName changes: This setting controls whether the connector will attempt to rename the Active Directory account if the sAMAccountName or userPrincipalName attribute changes in Workday.
    • Rename AD account if cn changes: This setting controls whether the connector will attempt to rename the Active Directory account if the cn attribute changes in Workday.

    I hope this helps! Let me know if you have any other questions.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.