openapi: 3.2.0 info: description: Use this API to create a connection in Saviynt Identity Cloud. title: Connection Management Connections API version: 1.0.0 servers: - url: http://localhost:3000 tags: - name: Connections paths: /ECM/api/v5/testConnection: post: operationId: createOrUpdate requestBody: content: application/json: schema: $ref: '#/components/schemas/createOrUpdate_request' required: true responses: '200': content: application/json: schema: $ref: '#/components/schemas/CreateOrUpdateResponse' description: Connection Successful headers: Access-Control-Allow-Credentials: explode: false schema: example: 'true' type: string style: simple Access-Control-Allow-Origin: explode: false schema: example: http://localhost type: string style: simple x-codegen-response-body-name: CreateOrUpdateConnectionResponse summary: Create a connection tags: - Connections /ECM/api/v5/getConnections: post: operationId: getConnections requestBody: content: application/json: schema: $ref: '#/components/schemas/getConnections_request' required: true responses: '200': content: application/json: schema: $ref: '#/components/schemas/getConnectionsResponse' description: Connection retreival successful headers: Access-Control-Allow-Credentials: explode: false schema: example: 'true' type: string style: simple Access-Control-Allow-Origin: explode: false schema: example: http://localhost type: string style: simple summary: Get list of connections tags: - Connections /ECM/api/v5/getConnectionDetails: post: operationId: getConnectionDetails requestBody: content: application/json: schema: $ref: '#/components/schemas/getConnectionDetails_request' required: true responses: '200': content: application/json: schema: $ref: '#/components/schemas/getConnectionDetailsResponse' description: Connection details retrieved successfully. summary: Get connection details tags: - Connections components: schemas: ADSIConnectionResponse: allOf: - $ref: '#/components/schemas/getConnectionDetails' - properties: connectionattributes: $ref: '#/components/schemas/ADSIConnectionAttributes' SalesforceConnector: allOf: - $ref: '#/components/schemas/BaseConnector' - properties: CLIENT_ID: type: string CLIENT_SECRET: type: string REFRESH_TOKEN: type: string REDIRECT_URI: example: https://@INSTANCE_NAME@.salesforce.com/services/oauth2/success type: string INSTANCE_URL: example: https://@INSTANCE_NAME@.salesforce.com type: string OBJECT_TO_BE_IMPORTED: example: Profile,Role,Group,PermissionSet type: string FEATURE_LICENSE_JSON: example: '{''Marketing User'': ''UserPermissionsMarketingUser'', ''Knowledge User'': ''UserPermissionsKnowledgeUser'', ''Offline User'': ''UserPermissionsOfflineUser'', ''Flow User'': ''UserPermissionsInteractionUser'', ''Site.com Contributor User'': ''UserPermissionsSiteforceContributorUser'', ''Site.com Publisher User'': ''UserPermissionsSiteforcePublisherUser'', ''Work.com User'': ''UserPermissionsWorkDotComUserFeature'', ''Apex Mobile User'': ''UserPermissionsMobileUser'', ''Salesforce CRM Content User'': ''UserPermissionsSFContentUser'', ''Chatter Answers User'': ''UserPermissionsChatterAnswersUser''} ' type: string CUSTOM_CREATEACCOUNT_URL: type: string CREATEACCOUNTJSON: example: '{''Alias'': ''${user?.getFirstname()}'', ''Email'': ''${user?.getEmail()}'', ''Username'': ''${user?.getEmail()}'', ''CommunityNickname'': ''${user?.getFirstname()}${user?.getLastname()}'', ''FirstName'': ''${user?.getFirstname()}'', ''LastName'': ''${user?.getLastname()}'', ''TimeZoneSidKey'': ''America/Los_Angeles'', ''LocaleSidKey'': ''en_US'', ''EmailEncodingKey'': ''ISO-8859-1'', ''ProfileId'': ''${profileId}'', ''LanguageLocaleKey'': ''en_US'', ''IsActive'': True, ''FederationIdentifier'': ''${user?.getEmail()}''} ' type: string ACCOUNT_FILTER_QUERY: type: string ACCOUNT_FIELD_QUERY: example: Id, Username, LastName, FirstName, Name, CompanyName, Email, IsActive, UserRoleId, ProfileId, UserType, ManagerId, LastLoginDate, LastPasswordChangeDate, CreatedDate, CreatedById, LastModifiedDate, LastModifiedById, SystemModstamp, ContactId, AccountId, FederationIdentifier, UserPermissionsSupportUser type: string FIELD_MAPPING_JSON: example: '{''accountfield_mapping'': {''accountID'': ''Id~#~char'', ''name'': ''Username~#~char'', ''customproperty2'': ''LastName~#~char'', ''customproperty1'': ''FirstName~#~char'', ''displayName'': ''Name~#~char'', ''customproperty3'': ''CompanyName~#~char'', ''customproperty4'': ''Email~#~char'', ''status'': ''IsActive~#~bool'', ''customproperty12'': ''IsActive~#~bool'', ''customproperty5'': ''UserRoleId~#~char'', ''customproperty6'': ''ProfileId~#~char'', ''accounttype'': ''UserType~#~char'', ''customproperty7'': ''ManagerId~#~char'', ''lastlogondate'': ''LastLoginDate~#~date'', ''lastpasswordchange'': ''LastPasswordChangeDate~#~date'', ''CREATED_ON'': ''CreatedDate~#~date'', ''creator'': ''CreatedById~#~char'', ''customproperty8'': ''LastModifiedDate~#~date'', ''updateUser'': ''LastModifiedById~#~char'', ''updatedate'': ''SystemModstamp~#~date'', ''customproperty9'': ''ContactId~#~char'', ''customproperty10'': ''AccountId~#~char'', ''customproperty13'': ''FederationIdentifier~#~char'', ''customproperty20'': ''UserPermissionsSupportUser~#~bool'', ''customproperty21'': ''featureLicense~#~char''}} ' type: string MODIFYACCOUNTJSON: example: '{''Alias'': ''${user?.getFirstname()}'', ''Email'': ''${user?.getEmail()}'', ''Username'': ''${user?.getEmail()}'', ''CommunityNickname'': ''${user?.getFirstname()}${user?.getLastname()}'', ''FirstName'': ''${user?.getFirstname()}'', ''LastName'': ''${user?.getLastname()}'', ''TimeZoneSidKey'': ''America/Los_Angeles'', ''LocaleSidKey'': ''en_US'', ''EmailEncodingKey'': ''ISO-8859-1'', ''ProfileId'': ''${profileId}'', ''LanguageLocaleKey'': ''en_US'', ''IsActive'': True, ''FederationIdentifier'': ''${user?.getEmail()}''} ' type: string STATUS_THRESHOLD_CONFIG: description: The attributes of statusAndThresholdConfig json example: '{''statusAndThresholdConfig'': {''accountThresholdValue'': 100, ''statusColumn'': ''customproperty12'', ''activeStatus'': [''true''], ''deleteLinks'': True, ''lockedStatusColumn'': ''customproperty22'', ''lockedStatusMapping'': {''Locked'': [''1''], ''Unlocked'': [''0'']}}} ' type: string CUSTOMCONFIGJSON: example: '{''disableAccountForRevokeTask'': False, ''defaultEntitlementId'': '''', ''connectionTimeoutConfig'': {''connectionTimeout'': 10, ''readTimeout'': 120, ''writeTimeout'': 120, ''retryWait'': 10, ''retryCount'': 5}} ' type: string PAM_CONFIG: example: '{''Connection'': ''SalesForce'', ''encryptionMechanism'': ''ENCRYPTED'', ''CONSOLE'': {''maxCredSessionRequestTime'': ''36000'', ''maxCredlessSessionRequestTime'': ''36000'', ''maxIDRequestableTime'': ''2592000'', ''shareableAccounts'': {''IDQueryCredentials'': "acc.name in (''cpamuser1'')", ''IDQueryCredentialless'': "acc.name in (''cpamuser2'', ''cpamuser3'')"}, ''endpointAttributeMappings'': [{''column'': ''accessquery'', ''value'': ''where users.USERNAME is not null'', ''feature'': ''endpointAccessQuery''}, {''column'': ''customproperty43'', ''value'': ''PAMDefaultUserAccountAccessControl'', ''feature'': ''accountVisibilityControl''}], ''endpointPamConfig'': {''maxConcurrentSession'': ''50''}, ''accountVisibilityConfig'': {''accountCustomProperty'': ''customproperty55'', ''accountMappingConfig'': [{''accountPattern'': ''cpamuser*'', ''mappingData'': ''roletest1'', ''override'': ''false''}, {''accountPattern'': ''cpamuser1,cpamuser2'', ''mappingData'': ''roletest2'', ''override'': ''false''}]}}} ' type: string UNIXConnectionResponse: allOf: - $ref: '#/components/schemas/getConnectionDetails' - properties: connectionattributes: $ref: '#/components/schemas/UNIXConnectionAttributes' WorkdayConnectionResponse: allOf: - $ref: '#/components/schemas/getConnectionDetails' - properties: connectionattributes: $ref: '#/components/schemas/WorkdayConnectionAttributes' ADSIConnector: allOf: - $ref: '#/components/schemas/BaseConnector' - properties: URL: description: Primary/root domain URL list (comma Separated) example: LDAP://dc01.domain1.com:636,LDAP://dc01.child.domain1.com:636 type: string USERNAME: description: Service account username example: adminuser@domain1.com type: string ENABLEGROUPMANAGEMENT: description: True implies group management capability limited to AD only. type: string example: null IMPORTDATACOOKIES: type: string MOVEACCOUNTJSON: description: JSON to specify movement action logic explicitely. If you have defined 'moveObjectToOU' parameter in your update/enable/disable actions implicitely, then no need to define this explicitely here type: string example: null PasswdPolicyJSON: description: Optional Password policy JSON, in case you have no password policy defined/assigned in your Security System. type: string example: null createUpdateMappings: description: Mapping used during group creation to specify which attribute of a group maps to which attribute on Saviynt. type: string example: null PASSWORD: description: Service account password format: password type: string CONNECTION_URL: description: ADSI remote agent Connection URL example: http://dc01.domain1.com:8090/api/v1/discover type: string PROVISIONING_URL: description: ADSI remote agent Provisioning URL example: http://dc01.domain1.com:8090/api/v1/objects type: string FORESTLIST: description: Forest List (Comma Separated) which we need to manage example: domain1.com,child.domain1.com type: string DEFAULT_USER_ROLE: description: Default SAV Role to be assigned to all the new users that gets imported via User Import example: ROLE_TASK_ADMIN type: string UPDATEUSERJSON: description: Specify the attribute Value which will be used to Update existing User example: ' {"objects":[{"objectClasses":["user"],"distinguishedName":"${account.COMMENTS?.replace('''', ''\'')?.replace(''/'',''/'')}","moveObjectToOU":"OU=TestContainer,DC=domain1,DC=com''}","attributes":{"displayName":"${user.displayname}","streetaddress":"${user.street}"}}]}' type: string ENDPOINTS_FILTER: description: Provide the configuration to create Child Endpoints and import associated accounts and entitlements example: '{"ADSI_Child_Endpoint":[{"memberOf":["CN=ADGroup15,OU=Groups,DC=domain1,DC=com"]}]}' type: string SEARCHFILTER: description: 'Account Search Filter to specify the starting point of the directory from where the accounts needs to be imported. You can have multiple BaseDNs here separated by ###.' example: DC=domain1,DC=com###DC=child,DC=domain1,DC=com type: string OBJECTFILTER: description: Object Filter is used to filter the objects that will be returned.This filter will be same for all domains. example: (&(objectCategory=person)(objectClass=user)) type: string ACCOUNT_ATTRIBUTE: description: Map EIC and AD attributes for account import (AD attributes must be in lower case) example: '[name::samaccountname#String,accountid::objectguid#String,displayname::cn#String,comments::distinguishedname#String,description::description#String,validthrough::accountexpires#millisec,updatedate::whenchanged#date,lastpasswordchange::pwdlastset#millisec,lastlogondate::lastlogon#millisec,accountclass::objectclass#String,customproperty1::samaccountname#String,customproperty2::userprincipalname#String,customproperty3::sn#String,customproperty4::co#String,customproperty5::givenname#String,customproperty6::title#String,customproperty7::telephonenumber#String,customproperty8::c#String,customproperty9::usncreated#String,customproperty10::logoncount#String,customproperty11::physicaldeliveryofficename#String,customproperty12::streetaddress#String,customproperty13::mailnickname#String,customproperty14::department#String,customproperty15::countrycode#String,customproperty16::manager#String,customproperty17::homephone#String,customproperty18::mobile#String,customproperty19::useraccountcontrol#String,customproperty21::company#String,customproperty22::objectguid#String,customproperty23::displayname#String,RECONCILATION_FIELD::accountid]' type: string STATUS_THRESHOLD_CONFIG: description: Account status and threshold related config example: '{"statusAndThresholdConfig":{"statusColumn":"customproperty24","activeStatus":["512","544","66048"],"deleteLinks":true,"accountThresholdValue":1000,"correlateInactiveAccounts":true,"inactivateAccountsNotInFile":false}}' type: string ENTITLEMENT_ATTRIBUTE: description: Account attribute that contains group membership example: memberOf type: string USER_ATTRIBUTE: description: Map EIC and AD attributes for user import (AD attributes must be in lower case) example: '["FIRSTNAME::givenname#String","LASTNAME::sn#String","CUSTOMPROPERTY1::samaccountname#String","USERNAME::distinguishedname#String","DISPLAYNAME::cn#String","CUSTOMPROPERTY25::description#String","CUSTOMPROPERTY3::sn#String","COMMENTS::distinguishedname#String","CUSTOMPROPERTY4::homedirectory#String","CUSTOMPROPERTY5::co#String","CUSTOMPROPERTY6::cn#String","CUSTOMPROPERTY7::givenname#String","CUSTOMPROPERTY8::title#String","CUSTOMPROPERTY9::telephonenumber#String","CUSTOMPROPERTY10::c#String","CUSTOMPROPERTY11::uSNCreated#String","ENDDATE::accountExpires#millisec","CUSTOMPROPERTY12::logonCount#String","CUSTOMPROPERTY13::physicaldeliveryofficenameute1#String","CUSTOMPROPERTY15::extensionattribute2#String","CUSTOMPROPERTY16::streetaddress#String","CUSTOMPROPERTY17::mailnickname#String","CUSTOMPROPERTY18::department#String","CUSTOMPROPERTY19::countrycode#String","CUSTOMPROPERTY2::samaccountname#String","CUSTOMPROPERTY20::userprincipalname#String","CUSTOMPROPERTY21::manager#String","CUSTOMPROPERTY22::homephone#String","CUSTOMPROPERTY23::mobile#String","CREATEDATE::whencreated#date","cstomproperty24::useraccountcontrol#String","CUSTOMPROPERTY26::distinguishedname#String","statuskey::useraccountcontrol#String","CUSTOMPROPERTY27::objectguid#String","RECONCILATION_FIELD::CUSTOMPROPERTY27","CUSTOMPROPERTY28::forest#String","CUSTOMPROPERTY29::domain#string"]' type: string groupSearchBaseDN: description: 'Group Search Filter to specify the starting point of the directory from where the groups needs to be imported. You can have multiple BaseDNs here separated by ###.' example: OU=Groups,DC=domain1,DC=Com type: string CHECKFORUNIQUE: description: Evaluate the uniqueness of an attribute example: '{"CheckForUnique":{"Attributes":[{"sAMAccountName":"customproperty1","RuleCheck":"${user.username}###${user.username}1###${user.username}2###${user.username}3"},{"userPrincipalName":"customproperty2","RuleCheck":"${user.username}@domain1.com###${user.username}1@domain1.com"}]}}' type: string STATUSKEYJSON: description: JSON configuration to specify Users status example: '{"STATUS_ACTIVE":["512","544"],"STATUS_INACTIVE":["546","514"]}' type: string groupImportMapping: description: Map AD group attribute to EIC entitlement attribute for import example: '{"importGroupHierarchy":"true","entitlementTypeName":"","performGroupAccountLinking":"true","groupObjectClass":"(objectclass=group)","entitlementOwnerAttribute":"managedby","tableFieldAttribute":"COMMENTS","mapping":"memberHash:memberof_char,customProperty1:samaccounttype_char,customProperty2:instancetype_char,customProperty3:usncreated_char,customProperty4:grouptype_char,customProperty5:dscorepropagationdata_char,customProperty12:dn_char,customProperty13:cn_char,lastscandate:whencreated_date,customProperty15:managedBy_char,entitlement_glossary:description_char,description:description_char,displayname:name_char,customProperty9:name_char,customProperty10:objectcategory_char,customProperty11:samaccounttype_char,entitlement_value:distinguishedname_char,entitlementid:objectguid_char,customProperty14:objectclass_char,updatedate:whenchanged_date,customProperty17:distinguishedname_char,RECONCILATION_FIELD:entitlementid,customProperty18:objectguid_char"}' type: string importNestedMembership: description: Specify if you want the connector to import all indirect or nested membership of an account or a group during access import example: 'FALSE' type: string PAGE_SIZE: description: Page size defines the number of objects to be returned from each AD operation. example: '1000' type: string ACCOUNTNAMERULE: description: Rule to generate account name. example: '{"AccountNameRule":{"Attributes":[{"cn":"ACCOUNTID","baseDN":"${''CN=Users,DC=domain1,DC=com''}","RuleCheck":"${user.lastname}, ${user.firstname}###${user.lastname}, ${user.firstname}1###${user.lastname}, ${user.firstname}2###${user.lastname}, ${user.firstname}3###${user.lastname}, ${user.firstname}4"}]}}' type: string CREATEACCOUNTJSON: description: Specify the attributes values which will be used to Create the New Account. example: '{"objects":[{"objectClasses":["user","top","Person","OrganizationalPerson"],"attributes":{"sn":"${user.lastname}","sAMAccountName":"${task.accountName}","cn":"${cn.replace('','', ''\\,'')}","userAccountControl":512,"co":"${user.country}","department":"${user.departmentname}","displayName":"${user.displayname}","employeeID":"${user.employeeid}","employeeType":"${user.employeeType}","givenName":"${user.firstname}","l":"${user.city}","mail":"${user.email}"},"baseDn":"${''CN=Users,DC=domain1,DC=com''}","password":"${password}"}]}' type: string UPDATEACCOUNTJSON: description: Specify the attributes values which will be used to Update existing Account. example: '{"objects":[{"objectClasses":["user"],"distinguishedName":"${account.COMMENTS.replace(''\'', ''\\'')?.replace(''/'', ''\/'')}","attributes":{"displayName":"${user.displayname}","streetAddress":"${user.street}"}}]}' type: string ENABLEACCOUNTJSON: description: Specify the actions and attribute updates to be performed for enabling an account. example: '{"objects":[{"objectClasses":["user"],"distinguishedName":"${account.COMMENTS.replace(''\'', ''\\'')?.replace(''/'', ''\/'')}","deleteAllGroups":false,"attributes":{"userAccountControl":512}}]}' type: string DISABLEACCOUNTJSON: description: Specify the actions and attributes updates to be performed for disabling an account. example: '{"objects":[{"objectClasses":["user"],"distinguishedName":"${account.COMMENTS.replace(''\'', ''\\'')?.replace(''/'', ''\/'')}","deleteAllGroups":true,"attributes":{"userAccountControl":514}}]}' type: string REMOVEACCOUNTJSON: description: Specify the actions to be performed for deleting an account. example: '{"objects":[{"distinguishedName":"${account.COMMENTS.replace(''\'', ''\\'')?.replace(''/'', ''\/'')}","removeAction":"DELETE","deleteChildObjects":false}]}' type: string ADDACCESSJSON: description: Configuration to ADD Access (cross domain/forest group membership) to an account. example: '{"objects":[{"objectClasses":["user"],"distinguishedName":"${account.COMMENTS?.replace(''\'', ''\\'')?.replace(''/'', ''\/'')}","addGroup":"${entitlement_values}"}],"requestConfiguration":{"grpMemExistenceChk":{"enable":true}}}' type: string REMOVEACCESSJSON: description: Configuration to REMOVE Access (cross domain/forest group membership) to an account. example: '{"objects":[{"objectClasses":["group"],"distinguishedName":"${account.COMMENTS?.replace(''\'', ''\\'')?.replace(''/'', ''\/'')}","removeGroup":"${entitlement_values}"}],"requestConfiguration":{"grpMemExistenceChk":{"enable":true}}}' type: string RESETANDCHANGEPASSWRDJSON: description: Configuration to Reset and Change Password. example: '{"objects":[{"objectClasses":["user"],"password":"${password}","distinguishedName":"${account.COMMENTS.replace(''\'', ''\\'')?.replace(''/'', ''\/'')}","attributes":{"pwdLastSet":"0"}}]}' type: string CREATEGROUPJSON: description: Configuration to Create a Group example: '{"objects":[{"objectClasses":["group"],"baseDn":"${role.customproperty24}","attributes":{"cn":"${role.displayname}","name":"${role.displayname}","description":"${role.description}","displayName":"${role.displayname}","groupType":"${role?.customproperty21 == ''Security'' && role?.customproperty22 == ''Global'' ? ''-2147483646'' : role?.customproperty21 == ''Security'' && role?.customproperty22 == ''Universal'' ? ''-2147483640'' : role?.customproperty21 == ''Security'' && role?.customproperty22 == ''Domain Local'' ? ''-2147483644'' : role?.customproperty21 == ''Distribution'' && role?.customproperty22 == ''Global'' ? ''2'' : role?.customproperty21 == ''Distribution'' && role?.customproperty22 == ''Universal'' ? ''8'' : role?.customproperty21 == ''Distribution'' && role?.customproperty22 == ''Domain Local'' ? ''4'' : ''''}"}}]}' type: string UPDATEGROUPJSON: description: Configuration to Update a Group example: '"objects":[{"objectClasses":["group"],"distinguishedName":"${role.role_name}","attributes":{"description":"${role.description}"}}]})' type: string REMOVEGROUPJSON: description: Configuration to Delete a Group example: '{"objects":[{"distinguishedName":"${role.role_name}","removeAction":"DELETE","deleteChildObjects":false}]}' type: string ADDACCESSENTITLEMENTJSON: description: Configuration to Add nested group hierarchy example: '{"objects":[{"objectClasses":["group"],"distinguishedName":"${ent1Value.entitlement_value?.replace(''\\'', ''\\\\'')?.replace(''/'', ''\\/'')}","addGroup":"${ent2Value.entitlement_value?.replace(''\\'', ''\\\\'')?.replace(''/'', ''\\/'')}"}],"requestConfiguration":{"grpMemExistenceChk":{"enable":true}}}' type: string CUSTOMCONFIGJSON: type: string REMOVEACCESSENTITLEMENTJSON: description: Configuration to Remove nested group hierarchy example: '{"objects":[{"objectClasses":["group"],"distinguishedName":"${ent1Value.entitlement_value?.replace(''\\'', ''\\\\'')?.replace(''/'', ''\\/'')}","addGroup":"${ent2Value.entitlement_value?.replace(''\\'', ''\\\\'')?.replace(''/'', ''\\/'')}"}],"requestConfiguration":{"grpMemExistenceChk":{"enable":true}}}' type: string CREATESERVICEACCOUNTJSON: description: Specify the Field Value which will be used to Create the New Service Account. example: '{"objects":[{"objectClasses":["msDS-GroupManagedServiceAccount"],"baseDn":"${''CN=Managed Service Accounts,DC=domain1,DC=com''}","attributes":{"sAMAccountName":"${task.accountName}","cn":"${task.accountName}","msDS-ManagedPasswordInterval":"10","userAccountControl":4096}}]}' type: string UPDATESERVICEACCOUNTJSON: description: Specify the Field Value which will be used to update the existing Service Account. example: '{"objects":[{"objectClasses":["msDS-GroupManagedServiceAccount"],"distinguishedName":"${account.COMMENTS?.replace(''\'', ''\\'')?.replace(''/'', ''\/'')}"}]}' type: string REMOVESERVICEACCOUNTJSON: description: Specify the actions to be performed while deleting a service account. example: '{"objects":[{"distinguishedName":"${account.COMMENTS?.replace(''\'', ''\\'')?.replace(''/'', ''\/'')}","removeAction":"DELETE","deleteChildObjects":false}]}' type: string PAM_CONFIG: description: JSON to specify Bootstrap Config. example: '{"Connection":"ADSI","encryptionMechanism":"ENCRYPTED","CONSOLE":{"maxCredSessionRequestTime":"36000","maxCredlessSessionRequestTime":"36000","maxIDRequestableTime":"2592000","shareableAccounts":{"IDQueryCredentials":"acc.name in (''cpamuser1'')","IDQueryCredentialless":"acc.name in (''cpamuser2'', ''cpamuser3'')"},"endpointAttributeMappings":[{"column":"accessquery","value":"where users.USERNAME is not null","feature":"endpointAccessQuery"},{"column":"customproperty43","value":"PAMDefaultUserAccountAccessControl","feature":"accountVisibilityControl"}],"endpointPamConfig":{"maxConcurrentSession":"50"},"accountVisibilityConfig":{"accountCustomProperty":"customproperty55","accountMappingConfig":[{"accountPattern":"cpamuser*","mappingData":"roletest1","override":"false"},{"accountPattern":"cpamuser1,cpamuser2","mappingData":"roletest2","override":"false"}]}}}' type: string MODIFYUSERDATAJSON: description: Specify this parameter to transform the data during user import. example: '{"COMPUTEDCOLUMNS":["DISPLAYNAME"],"PREPROCESSQUERIES":["UPDATE NEWUSERDATA SET DISPLAYNAME=city"]}' type: string required: - CONNECTION_URL - FORESTLIST - PASSWORD - URL - USERNAME getConnections_request: properties: connectionname: description: Specify the connection name for which you want to view the details. example: testConn type: string connectiontype: description: Specify a connection type to view all the connection in EIC for the connection type. example: AD type: string max: description: Specify the maximum number of results that can be returned in the response. example: '5' type: string offset: description: Specify the number of rows of the result to skip before any rows are retrieved. example: '1' type: string GithubRESTConnectionResponse: allOf: - $ref: '#/components/schemas/getConnectionDetails' - properties: connectionattributes: $ref: '#/components/schemas/GithubRESTConnectionAttributes' createOrUpdate_request: discriminator: mapping: AD: '#/components/schemas/ADConnector' ADSI: '#/components/schemas/ADSIConnector' SAP: '#/components/schemas/SAPConnector' Salesforce: '''#/components/schemas/SalesforceConnector' REST: '#/components/schemas/RESTConnector' D365: '#/components/schemas/D365Connector' Workday: '#/components/schemas/WorkdayConnector' DB: '#/components/schemas/DBConnector' EntraID: '#/components/schemas/EntraIDConnector' UNIX: '#/components/schemas/UNIXConnector' GithubREST: '#/components/schemas/GithubRESTConnector' Okta: '#/components/schemas/OktaConnector' WorkdaySOAP: '#/components/schemas/WorkdaySOAPConnector' SFTP: '#/components/schemas/SFTPConnector' propertyName: connectiontype oneOf: - $ref: '#/components/schemas/ADConnector' - $ref: '#/components/schemas/ADSIConnector' - $ref: '#/components/schemas/SAPConnector' - $ref: '#/components/schemas/SalesforceConnector' - $ref: '#/components/schemas/RESTConnector' - $ref: '#/components/schemas/D365Connector' - $ref: '#/components/schemas/WorkdayConnector' - $ref: '#/components/schemas/DBConnector' - $ref: '#/components/schemas/EntraIDConnector' - $ref: '#/components/schemas/UNIXConnector' - $ref: '#/components/schemas/GithubRESTConnector' - $ref: '#/components/schemas/OktaConnector' - $ref: '#/components/schemas/WorkdaySOAPConnector' - $ref: '#/components/schemas/SFTPConnector' SFTPConnectionAttributes: properties: HOST_NAME: example: 107.20.19.78 type: string PORT_NUMBER: example: '22' type: string USERNAME: example: scrumintgnsftpuser type: string AUTH_CREDENTIAL_TYPE: example: PASSWORD type: string AUTH_CREDENTIAL_VALUE: example: c6nOXxoO6ETfU8enegQXq6QZieFk+JW99isPx2wplsw= type: string PASSPHRASE: type: string FILES_TO_GET: type: string FILES_TO_PUT: type: string PAM_CONFIG: type: string connectionType: example: MS_BASED_CONNECTOR type: string isTimeoutSupported: example: true type: boolean isTimeoutConfigValidated: example: true type: boolean connectionTimeoutConfig: $ref: '#/components/schemas/ConnectionTimeoutConfig' CreateOrUpdateResponse: example: msg: Connection Successful connectionKey: 1909 errorCode: '0' properties: connectionKey: example: 1909 type: integer msg: example: Connection Successful type: string errorCode: example: '0' type: string EntraIDConnectionResponse: allOf: - $ref: '#/components/schemas/getConnectionDetails' - properties: connectionattributes: $ref: '#/components/schemas/EntraIDConnectionAttributes' DBConnectionAttributes: properties: PASSWORD_MIN_LENGTH: description: Minimum length of password example: '8' type: string CHANGEPASSJSON: example: ACp1raw6y9smEJ35WcND7Tzfcckk3YadHA9W12L0W43DtLA0rLFN9ldqbJ5/90oXND6hS0+h0DOPDt5hEutO2lqGC3qqC4MiT88QDXpp/fZSQxq7js5RwDGOfPuVfHZ/lU3HG98UkNaRgeNfRu6daULEU2x9HSoccmgZtNsap6cA9q0T6SLh8ldY8dzTiFedhMRFFFJrDXXKMZKybYXeXA== type: string ACCOUNTEXISTSJSON: example: '{\"AccountExistQry\":\"SELECT username FROM mysqllocal.users WHERE username = ${user.username}\"}' type: string ROLESIMPORT: type: string ROLEOWNERIMPORT: type: string CREATEACCOUNTJSON: example: '{"CreateAccountQry": ["INSERT INTO mysqllocal.users(username, firstname, lastname, statuskey, departmentname, displayname, manager, enabled, updatedate) VALUES ("${user.username}", "${user.firstname}", "${user.lastname}", "${user.statuskey}", "${user.departmentname}", "${user.displayname}", "${user.manager}", "${user.enabled}", CURRENT_TIMESTAMP)", "INSERT INTO mysqllocal.accounts(AccountName, EntitlementType, EntitlementValue, Status, UPDATEDATE) VALUES ("${user.username}", DEFAULT, BASE_ACCESS, 1, CURRENT_TIMESTAMP)"]}' type: string ENTITLEMENTEXISTJSON: type: string USERIMPORT: example: "\n \n \n \n \n \n \n \n false\n true\n NOACTION\n false\n false\n false\n CREATE,UPDATE\n username\n \n \n \n \n \n \n" type: string DISABLEACCOUNTJSON: example: '{"DisableAccountQry":["UPDATE mysqllocal.users SET enabled = 0, updatedate = CURRENT_TIMESTAMP WHERE username = ${user.username}","UPDATE mysqllocal.accounts SET Status = 0, UPDATEDATE = CURRENT_TIMESTAMP WHERE AccountName = ${user.username}"]}' type: string ENTITLEMENTVALUEIMPORT: example: "\n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n" type: string connectionTimeoutConfig: $ref: '#/components/schemas/ConnectionTimeoutConfig' UPDATEUSERJSON: example: '{"UpdateUserQry":["UPDATE mysqllocal.users SET firstname = ${user.firstname}, lastname = ${user.lastname}, departmentname = ${user.departmentname}, displayname = ${user.displayname}, manager = ${user.manager}, orgunitID = ${user.orgunitID}, updatedate = CURRENT_TIMESTAMP WHERE username =${user.username}"]}' type: string PASSWORD_NOOFSPLCHARS: example: '4' type: string REVOKEACCESSJSON: example: '{"ENTITLEMENT_TYPE1":["UPDATE mysqllocal.accounts SET Status = 0, UPDATEDATE = CURRENT_TIMESTAMP WHERE AccountName = ${user.username} AND EntitlementType = ${entitlement.type} AND EntitlementValue = ${entitlement.value}"]}' type: string connectionType: example: MS_BASED_CONNECTOR type: string URL: example: jdbc:mysql://34.139.69.20:3306 type: string UPDATEENTITLEMENTJSON: type: string SYSTEMIMPORT: type: string DRIVERNAME: example: com.mysql.jdbc.Driver type: string DELETEACCOUNTJSON: example: '"DeleteAccountQry":["DELETE FROM mysqllocal.users WHERE username = ${user.username}","DELETE FROM mysqllocal.accounts WHERE AccountName = ${user.username}"]}' type: string CREATEENTITLEMENTJSON: type: string STATUS_THRESHOLD_CONFIG: type: string USERNAME: example: connadmin type: string isTimeoutSupported: example: true type: boolean DELETEENTITLEMENTJSON: type: string PASSWORD_NOOFCAPSALPHA: type: string PASSWORD_NOOFDIGITS: type: string CONNECTIONPROPERTIES: type: string MODIFYUSERDATAJSON: type: string isTimeoutConfigValidated: example: false type: boolean ACCOUNTSIMPORT: example: "\n\t \n\t \n\t \n\t \n\t \n\t \n\t \n\t \n\t \n\t \n\t \n\t \n\t \n\t \n\t \n\t \n\t \n\t \n\t" type: string PASSWORD: example: password123 type: string ENABLEACCOUNTJSON: example: '{"EnableAccountQry":["UPDATE mysqllocal.users SET enabled = 1, updatedate = CURRENT_TIMESTAMP WHERE username = ${user.username}","UPDATE mysqllocal.accounts SET Status = 1, UPDATEDATE = CURRENT_TIMESTAMP WHERE AccountName = ${user.username}"]}' type: string PASSWORD_MAX_LENGTH: example: '16' type: string MAX_PAGINATION_SIZE: example: '100' type: string UPDATEACCOUNTJSON: example: '{"UpdateAccountQry":["UPDATE mysqllocal.users SET firstname =${user.firstname}, lastname = ${user.lastname}, departmentname = ${user.departmentname}, displayname = ${user.displayname}, manager = ${user.manager}, orgunitID = ${user.orgunitID}, updatedate = CURRENT_TIMESTAMP WHERE username = ${user.username}"]}' type: string GRANTACCESSJSON: example: '{"ENTITLEMENT_TYPE1":["INSERT INTO mysqllocal.accounts(AccountName, EntitlementType, EntitlementValue, Status, UPDATEDATE) VALUES(${user.username}, ${entitlement.type}, ${entitlement.value}, 1, CURRENT_TIMESTAMP)"],"ROLE_ACCESS":["INSERT INTO mysqllocal.roles(role_name, description, displayname, status, updatedate) VALUES(${role.name}, ${role.description}, ${role.displayname}, 1, CURRENT_TIMESTAMP)"]}' type: string CLI_COMMAND_JSON: type: string OktaConnectionResponse: allOf: - $ref: '#/components/schemas/getConnectionDetails' - properties: connectionattributes: $ref: '#/components/schemas/OktaConnectionAttributes' SFTPConnectionResponse: allOf: - $ref: '#/components/schemas/getConnectionDetails' - properties: connectionattributes: $ref: '#/components/schemas/SFTPConnectionAttributes' WorkdaySOAPConnectionResponse: allOf: - $ref: '#/components/schemas/getConnectionDetails' - properties: connectionattributes: $ref: '#/components/schemas/WorkdaySOAPConnectionAttributes' EntraIDConnectionAttributes: properties: UpdateUserJSON: type: string MICROSOFT_GRAPH_ENDPOINT: example: https://example.com type: string ENDPOINTS_FILTER: type: string ImportUserJSON: type: string connectionType: example: MS_BASED_CONNECTOR type: string EnableAccountJSON: example: '"call":[{"name":"call1","connection":"${connectionName}","url":"https://example.com/${account.accountID}","httpMethod":"PATCH","httpParams":"{\"accountEnabled\": true}","httpHeaders":{"Authorization":"${access_token}"},"httpContentType":"application/json","successResponses":{"statusCode":[200,201,204,205]}}]}' type: string ConnectionJSON: example: 2Zu5TzAaslOVICigob+xCt8PA2vO79ly17qVvzL1EDqdZ3bplvfOjTonpUDBeDOad/fkHgpHsfO6azHVdRz6oBpB6ELGaMdGQeI type: string CLIENT_ID: example: client_id type: string DeleteGroupJSON: type: string ConfigJSON: example: '{"connectionTimeoutConfig":{"connectionTimeout":10,"readTimeout":60,"retryWait":5,"retryCount":3}}' type: string ACCESS_TOKEN: example: access_token type: string AddAccessJSON: example: '{"call":[{"name":"SKU","connection":"${connectionName}","url":"https://example.com/users/${account.accountID}' type: string CreateChannelJSON: type: string UpdateAccountJSON: example: '{"call":[{"name":"call1","connection":"${connectionName}","url":"https://example.com/users/${account.accountID}","httpMethod":"PATCH","httpParams":"{\"userprincipalname\": \"${account.name}\"}","httpHeaders":{"Authorization":"${access_token}"},"httpContentType":"application/json","successResponses":{"statusCode":[200,201,204,205]}}]}' type: string isTimeoutSupported: example: true type: boolean RemoveServicePrincipalJSON: type: string IMPORT_DEPTH: example: FINE GRAINED type: string CreateAccountJSON: example: call":[{"name":"call1","connection":"${connectionName}","url":"https://example.com/users","httpMethod":"POST","httpParams":"{\"accountEnabled\":true,\"displayName\":\"${user.firstname}\",\"mailNickname\":\"${user.firstname}\",\"userPrincipalName\":\"${user.username}@saviyntlive.onmicrosoft.com\",\"passwordProfile\":{\"forceChangePasswordNextSignIn\":true,\"password\":\"${password}\"}}","httpHeaders":{"Authorization":"${access_token}"},"httpContentType":"application/json","successResponses":{"statusCode":[200,201,204,205]}}],"accountIdPath":"call1.message.id","dateFormat":"yyyy-MM-dd'T'HH:mm:ssXXX","responseColsToPropsMap":{"displayName":"call1.message.displayName~#~char","name":"call1.message.userPrincipalName~#~char"}} type: string PAM_CONFIG: type: string UpdateServicePrincipalJSON: type: string AZURE_MANAGEMENT_ENDPOINT: example: https://management.azure.com type: string ENTITLEMENT_ATTRIBUTE: type: string ACCOUNTS_FILTER: type: string WINDOWS_CONNECTOR_JSON: type: string DELTATOKENSJSON: type: string AZURE_MGMT_ACCESS_TOKEN: example: token type: string CreateTeamJSON: type: string connectionTimeoutConfig: $ref: '#/components/schemas/ConnectionTimeoutConfig' ENHANCEDDIRECTORYROLES: example: 'FALSE' type: string STATUS_THRESHOLD_CONFIG: example: '{ "statusAndThresholdConfig": { "accountThresholdValue": 1000, "appAccountThresholdValue": 500, "correlateInactiveAccounts": true, "statusColumn": "customproperty10", "activeStatus": ["true"], "deleteLinks": true, "inactivateAccountsNotInFile": false } }' type: string ACCOUNT_IMPORT_FIELDS: example: accountEnabled,mail,businessPhone,surname,givenName,displayName,userPrincipalName,id type: string RemoveAccountJSON: example: '{"call":[{"name":"call1","connection":"${connectionName}","url":"https://example.com/users/${account.accountID}","httpMethod":"DELETE","httpHeaders":{"Authorization":"${access_token}"},"httpContentType":"application/json","successResponses":{"statusCode":[200,201,204,205]}}]}' type: string ChangePassJSON: example: '{"call":[{"name":"call1","connection":"${connectionName}","url":"https://example.com/users/${account.accountID}","httpMethod":"PATCH","httpParams":"{\"passwordPolicies\" :\"DisableStrongPassword\",\"passwordProfile\" : {\"password\":\"${password}\",\"forceChangePasswordNextSignIn\": false}}","httpHeaders":{"Authorization":"${access_token}"},"httpContentType":"application/json","successResponses":{"statusCode":[200,201,204,205]}}]}' type: string CLIENT_SECRET: example: client_secret type: string ENTITLEMENT_FILTER_JSON: type: string SERVICE_ACCOUNT_ATTRIBUTES: type: string AddAccessToEntitlementJSON: type: string AUTHENTICATION_ENDPOINT: example: https://example.com type: string CreateServicePrincipalJSON: type: string MODIFYUSERDATAJSON: type: string isTimeoutConfigValidated: example: true type: boolean RemoveAccessJSON: type: string CREATEUSERS: example: 'NO' type: string RemoveAccessFromEntitlementJSON: type: string DisableAccountJSON: type: string CREATE_NEW_ENDPOINTS: example: 'NO' type: string MANAGED_ACCOUNT_TYPE: type: string ACCOUNT_ATTRIBUTES: type: string AAD_TENANT_ID: example: tenant_id type: string UpdateGroupJSON: type: string CreateGroupJSON: type: string DBConnectionResponse: allOf: - $ref: '#/components/schemas/getConnectionDetails' - properties: connectionattributes: $ref: '#/components/schemas/DBConnectionAttributes' OktaConnector: allOf: - $ref: '#/components/schemas/BaseConnector' - properties: IMPORTURL: description: '' example: '' type: string AUTHTOKEN: description: '' example: '' type: string ACCOUNTFIELDMAPPINGS: description: '' example: '' type: string USERFIELDMAPPINGS: description: '' example: '' type: string ENTITLEMENTTYPESMAPPINGS: description: '' example: '' type: string IMPORT_INACTIVE_APPS: description: '' example: '' type: string OKTA_APPLICATION_SECURITYSYSTEM: description: '' example: '' type: string OKTA_GROUPS_FILTER: description: '' example: '' type: string APPACCOUNTFIELDMAPPINGS: description: '' example: '' type: string STATUS_THRESHOLD_CONFIG: description: '' example: '' type: string AUDIT_FILTER: description: '' example: '' type: string MODIFYUSERDATAJSON: description: '' example: '' type: string ACTIVATE_ENDPOINT: description: '' example: '' type: string ConfigJSON: description: '' example: '' type: string PAM_CONFIG: description: '' example: '' type: string required: - AUTHTOKEN - IMPORTURL - OKTA_APPLICATION_SECURITYSYSTEM getConnectionsResponse: example: msg: Successful ConnectionList: - CONNECTIONTYPE: AD STATUS: 1 UPDATEDON: 2017-03-23 00:48:28+00:00 CREATEDON: 2017-03-23 00:48:28+00:00 UPDATEDBY: admin CREATEDBY: admin CONNECTIONNAME: test-conn CONNECTIONDESCRIPTION: Description of the connection - CONNECTIONTYPE: AD STATUS: 1 UPDATEDON: 2017-03-23 00:48:28+00:00 CREATEDON: 2017-03-23 00:48:28+00:00 UPDATEDBY: admin CREATEDBY: admin CONNECTIONNAME: test-conn CONNECTIONDESCRIPTION: Description of the connection displayCount: 50 errorCode: '0' totalCount: 130 properties: msg: example: Successful type: string errorCode: example: '0' type: string displayCount: example: 50 type: integer totalCount: example: 130 type: integer ConnectionList: description: A list of connections. items: $ref: '#/components/schemas/getConnectionsResponse_ConnectionList_inner' type: array OktaConnectionAttributes: properties: IMPORTURL: example: '' type: string AUTHTOKEN: example: '' type: string isTimeoutSupported: example: true type: boolean OKTA_GROUPS_FILTER: example: '' type: string ACCOUNTFIELDMAPPINGS: example: '' type: string IMPORT_INACTIVE_APPS: example: 'FALSE' type: string AUDIT_FILTER: example: '' type: string USERFIELDMAPPINGS: example: '' type: string APPACCOUNTFIELDMAPPINGS: example: '' type: string MODIFYUSERDATAJSON: example: '' type: string connectionTimeoutConfig: $ref: '#/components/schemas/ConnectionTimeoutConfig' connectionType: example: MS_BASED_CONNECTOR type: string isTimeoutConfigValidated: example: false type: boolean ACTIVATE_ENDPOINT: example: '' type: string ENTITLEMENTTYPESMAPPINGS: example: '' type: string OKTA_APPLICATION_SECURITYSYSTEM: example: '' type: string PAM_CONFIG: example: '' type: string ConfigJSON: example: '' type: string STATUS_THRESHOLD_CONFIG: example: '' type: string SFTPConnector: allOf: - $ref: '#/components/schemas/BaseConnector' - properties: HOST_NAME: description: SFTP server hostname or IP address type: string PORT_NUMBER: description: SFTP server port number type: string USERNAME: description: Username for SFTP authentication type: string AUTH_CREDENTIAL_TYPE: description: Type of authentication (password, key, etc.) type: string AUTH_CREDENTIAL_VALUE: description: Authentication credential (password or private key path) type: string PASSPHRASE: description: Passphrase for encrypted private key type: string FILES_TO_GET: description: Files to download from SFTP server type: string FILES_TO_PUT: description: Files to upload to SFTP server type: string PAM_CONFIG: description: PAM configuration for SFTP connection type: string required: - AUTH_CREDENTIAL_TYPE - AUTH_CREDENTIAL_VALUE - HOST_NAME - PORT_NUMBER - USERNAME WorkdayConnector: allOf: - $ref: '#/components/schemas/BaseConnector' - properties: USERS_LAST_IMPORT_TIME: description: Property for USERS_LAST_IMPORT_TIME type: string ACCOUNTS_LAST_IMPORT_TIME: description: Property for ACCOUNTS_LAST_IMPORT_TIME type: string ACCESS_LAST_IMPORT_TIME: description: Property for ACCESS_LAST_IMPORT_TIME type: string BASE_URL: description: Base URL of the Workday tenant instance example: https://wd2-impl-services1.workday.com type: string API_VERSION: description: Version of the SOAP API used for the connection. example: v34.0 type: string TENANT_NAME: description: The name of your tenant. type: string REPORT_OWNER: description: Account name of the report owner required for constructing the default URLs of RaaS reports type: string USE_OAUTH: description: By default, the reports are accessed through OAuth authentication example: 'FALSE' type: string INCLUDE_REFERENCE_DESCRIPTORS: description: if it is TRUE, descriptor attribute will be avialable in response. example: 'FALSE' type: string USE_ENHANCED_ORGROLE: description: Set TRUE to utilize enhanced Organizational Role setup example: 'TRUE' type: string USE_X509AUTH_FOR_SOAP: description: ' it is TRUE certificate based authentication will happen.' example: 'FALSE' type: string X509_KEY: description: Specify the privateKey to be used type: string X509_CERT: description: Specify the certificate to be used type: string USERNAME: description: The username to use for SOAP authentication. type: string PASSWORD: description: The password of the username used for authentication. type: string CLIENT_ID: type: string CLIENT_SECRET: type: string REFRESH_TOKEN: type: string PAGE_SIZE: description: Specify the number of objects to return in a page for each import request from Workday example: '100' type: string USER_IMPORT_PAYLOAD: description: Define the request payload for importing users example: ... type: string USER_IMPORT_MAPPING: description: Specify the User import Mapping type: string ACCOUNT_IMPORT_PAYLOAD: description: Define the request payload for importing accounts example: 'falsefalsefalse ${INCREMENTAL_IMPORT_CRITERIA}${PAGE_NUMBER}${PAGE_SIZE}truetruefalsetruefalsefalsetruetruetruetruetruetruetruetruetruetruetruetruetruefalsefalsefalsefalsefalsefalsefalsefalsefalsefalsefalsefalsefalsefalsefalsefalsefalsefalsefalsefalsefalsefalsefalsefalsefalsefalsefalsetruetruetruetruetruetruetruetruetruetrue ' type: string ACCOUNT_IMPORT_MAPPING: description: Specify the Account import Mapping example: '{''ImportType'': ''SOAP'', ''ResponsePath'': ''Body.Get_Workers_Response.Response_Data.Worker'', ''ImportMapping'': {''NAME'': ''Worker_Data.User_ID'', ''ACCOUNTID'': "Worker_Reference.ID(@wd:type==''WID'')", ''CUSTOMPROPERTY30'': ''Worker_Data.Employment_Data.Worker_Status_Data.Active'', ''CUSTOMPROPERTY1'': "Worker_Data.Personal_Data.Identification_Data.Custom_ID.Custom_ID_Data(ID_Type_Reference->ID==''CustomID_NTID'').ID", ''CUSTOMPROPERTY2'': "Worker_Data.Personal_Data.Identification_Data.Custom_ID.Custom_ID_Data(ID_Type_Reference - > ID == ''CustomID_GPID'').ID", ''CUSTOMPROPERTY3'': "Worker_Data.Personal_Data.Identification_Data.Custom_ID.Custom_ID_Data(ID_Type_Reference - > ID == ''CustomID_UPN'').ID", ''CUSTOMPROPERTY4'': "Worker_Data.Personal_Data.Contact_Data.Email_Address_Data(Usage_Data - > Type_Data - > Type_Reference - > ID == ''WORK'').Email_Address", ''CUSTOMPROPERTY5'': ''Worker_Data.Personal_Data.Name_Data.Legal_Name_Data.Name_Detail_Data.First_Name'', ''CUSTOMPROPERTY6'': ''Worker_Data.Personal_Data.Name_Data.Legal_Name_Data.Name_Detail_Data.Last_Name'', ''CUSTOMPROPERTY7'': "Worker_Data.Personal_Data.Name_Data.Legal_Name_Data.Name_Detail_Data.Country_Reference.ID(@type == ''ISO_3166-1_Alpha-3_Code'')", ''CUSTOMPROPERTY9'': "Worker_Data.Role_Data.Organization_Role_Data.Organization_Role.Organization_Role_Reference.ID(@type == ''Organization_Role_ID'')", ''CUSTOMPROPERTY11'': ''Worker_Data.Worker_ID'', ''CUSTOMPROPERTY12'': "Worker_Data.Personal_Data.Identification_Data.Custom_ID(Custom_ID_Data - > ID_Type_Reference - > ID == ''CustomID_GPID'').Custom_ID_Shared_Reference.ID(@type == ''Custom_Identifier_Reference_ID'')", ''CUSTOMPROPERTY13'': "Worker_Data.Personal_Data.Identification_Data.Custom_ID(Custom_ID_Data - > ID_Type_Reference - > ID == ''CustomID_UPN'').Custom_ID_Shared_Reference.ID(@type == ''Custom_Identifier_Reference_ID'')"}} ' type: string ACCESS_IMPORT_LIST: description: Specify the access types to import in a comma separated list example: Security Group,Domain Security Policy,Business Process Security Policy,Business Process Definitions,Organizational Role,Organization,Tasks And Reports type: string RAAS_MAPPING_JSON: description: Use this parameter if you want to override the default report mapping example: '{''reportUrlMapping'': [{''accessType'': ''Account'', ''url'': ''${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_Accounts?format=xml''}, {''accessType'': ''Security Group'', ''url'': ''${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_SecurityGroups?format=xml'', ''mappingUrl'': ''${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_WorkersToSecurityGroups?format=xml'', ''inc_url'': ''${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_SecurityGroupsWorkers?format=xml'', ''enable_chunked_retrieval'': 0, ''locationHierarchyUrl'': ''${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_LocationHierarchies'', ''locationHierarchies'': [], ''countryReportUrl'': ''${BASE_URL}/ccx/service/systemreport2/${TENANT_NAME}/Country_Summary'', ''countryCodes'': []}, {''accessType'': ''Domain Security Policy'', ''url'': ''${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_DomainSecurityPermissions?format=xml'', ''inc_url'': ''${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_Domains?format=xml&Include_Changes_to_Security_Groups=0''}, {''accessType'': ''Business Process Security Policy'', ''url'': ''${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_BusinessProcessPermissions?format=xml'', ''inc_url'': ''${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_BusinessProcesses?format=xml&Include_Changes_to_Security_Groups=0''}, {''accessType'': ''Business Process Definitions'', ''url'': ''${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_BusinessProcessDefinitions?format=xml''}, {''accessType'': ''Organizational Role'', ''url'': ''${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_OrgRolesWorkers?format=xml'', ''enhancedUrl'': ''${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_RoleSecurityGroups?format=xml''}, {''accessType'': ''Tasks And Reports'', ''url'': ''${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_ReportsTasksGetPut?Include_Inactive=0,${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_ReportsTasksViewModify?Include_Inactive=0''}, {''accessType'': ''Organization''}], ''auditReportUrlMapping'': [{''reportName'': ''userActivity'', ''url'': ''${BASE_URL}/ccx/service/systemreport2/${TENANT_NAME}/View_User_Activity?format=xml'', ''importDateStep'': ''6'', ''indexName'': ''audit'', ''auditDateStart'': ''${CURRENT_TIMESTAMP_MINUS_24HRS}'', ''ImportMapping'': {''fileCreateTime'': ''wd:Request_Time'', ''sourceTranslatedAddress'': ''wd:IP_Address'', ''requestClientApplication'': ''wd:User_Agent'', ''suser'': ''wd:System_Account.wd:Descriptor'', ''filePath'': ''wd:Task'', ''filePermission'': ''wd:Activity_Category'', ''duser'': ''wd:Target.wd:Descriptor'', ''duid'': ''wd:Target.wd:ID[1].wd:type''}}]} ' type: string ACCESS_IMPORT_MAPPING: description: Define the access attribute mapping in addition to the default non-editable mapping for the Workday access objects example: '{''Security Group'': {''ImportMapping'': {''displayname'': ''wd:Security_Group.wd:Descriptor~#~char'', ''description'': ''wd:Comment~#~char''}}, ''Domain Security Policy'': {''ImportMapping'': {}}, ''Business Process Security Policy'': {''ImportMapping'': {}}, ''Business Process Definitions'': {''ImportMapping'': {}}, ''Organizational Role'': {''ImportMapping'': {}}, ''Organization'': {''ImportMapping'': {}}, ''Tasks And Reports'': {''ImportMapping'': {}}} ' type: string ORGROLE_IMPORT_PAYLOAD: description: Specify the custom SOAP body for the organization role import example: '1${INCREMENTAL_IMPORT_CRITERIA}${PAGE_NUMBER}${PAGE_SIZE}1000 ' type: string STATUS_THRESHOLD_CONFIG: description: Specify this parameter if you want to read and import the status of an account and an entitlement. example: '{''statusAndThresholdConfig'': {''statusColumn'': ''customproperty30'', ''deleteLinks'': False, ''accountThresholdValue'': 1000, ''correlateInactiveAccounts'': False, ''inactivateAccountsNotInFile'': False}} ' type: string CREATE_ACCOUNT_PAYLOAD: description: Define the request payload for creating an account in Workday example: '${accountName}${password} ' type: string UPDATE_ACCOUNT_PAYLOAD: description: Define the request payload for updating an account in Workday example: 'truetrue${user.customproperty1}${CURRENT_PROV_TIMESTAMP}${user.email}WORK ' type: string UPDATE_USER_PAYLOAD: description: Define the request payload for updating an user in Workday example: ... type: string ASSIGN_ORGROLE_PAYLOAD: description: Define the request payload for assigning an organizational role to an account in Workday example: '1${user.customproperty1}0${Organization_Reference_ID}${entitlementID}01${user.customproperty1}0 ' type: string REMOVE_ORGROLE_PAYLOAD: description: Define the request payload for assigning an organizational role to an account in Workday example: '1${user.customproperty1}0${Organization_Reference_ID}${entitlementID}01${user.customproperty1}0 ' type: string STATUS_KEY_JSON: description: Specify the mapping of user status type: string USERATTRIBUTEJSON: description: JSON that specifies which job related attributes are to be stored as User Attributes type: string CUSTOM_CONFIG: example: '{''connectionTimeoutConfig'': {''SOAP'': {''connectionTimeout'': 10, ''readTimeout'': 900, ''writeTimeout'': 300, ''retryWait'': 2, ''retryCount'': 3}}} ' type: string PAM_CONFIG: example: '{''Connection'': ''Workday'', ''encryptionMechanism'': ''ENCRYPTED'', ''CONSOLE'': {''maxCredSessionRequestTime'': ''10'', ''maxCredlessSessionRequestTime'': ''10'', ''maxIDRequestableTime'': ''100'', ''shareableAccounts'': {''IDQueryCredentials'': "acc.name in (''cpamuser1'')", ''IDQueryCredentialless'': "acc.name in (''cpamuser2'', ''cpamuser3'')"}, ''endpointPamConfig'': {''maxConcurrentSession'': ''2''}, ''accountVisibilityConfig'': {''accountCustomProperty'': ''customproperty55'', ''accountMappingConfig'': [{''accountPattern'': ''cpamuser*'', ''mappingData'': ''roletest1'', ''override'': ''false''}, {''accountPattern'': ''cpamuser1,cpamuser2'', ''mappingData'': ''roletest2'', ''override'': ''false''}]}, ''endpointAttributeMappings'': [{''column'': ''accessquery'', ''value'': ''where users.USERNAME is not null'', ''feature'': ''endpointAccessQuery''}, {''column'': ''allowChangePassword_sqlquery'', ''value'': "AC.ACCOUNTTYPE != ''Platform Service Account''", ''feature'': ''allowChangepasswordquery''}, {''column'': ''customproperty43'', ''value'': ''PAMDefaultUserAccountAccessControl'', ''feature'': ''accountVisibilityControl''}]}} ' type: string MODIFYUSERDATAJSON: type: string required: - USE_OAUTH ConnectionTimeoutConfig: example: retryWait: 0 tokenRefreshMaxTryCount: 6 retryFailureStatusCode: 1 retryWaitMaxValue: 5 retryCount: 5 readTimeout: 2 connectionTimeout: 7 authErrorWithStatusCode: null properties: retryWait: description: Wait time before retrying a failed connection. type: integer tokenRefreshMaxTryCount: description: Maximum number of retries for token refresh. type: integer retryFailureStatusCode: type: integer retryWaitMaxValue: description: Maximum wait time for retries. type: integer retryCount: description: Number of retry attempts allowed. type: integer readTimeout: description: Read timeout duration (in seconds). type: integer connectionTimeout: description: Connection timeout duration (in seconds). type: integer authErrorWithStatusCode: description: HTTP status code that indicates authentication error requiring retry. type: integer nullable: true SAPConnectionResponse: allOf: - $ref: '#/components/schemas/getConnectionDetails' - properties: connectionattributes: $ref: '#/components/schemas/SAPConnectionAttributes' D365Connector: allOf: - $ref: '#/components/schemas/BaseConnector' - properties: BASEURL: example: https://@INSTANCE_NAME@.cloudax.dynamics.com type: string TENANT_ID: type: string LOGIN_URL: example: https://login.microsoftonline.com type: string CLIENT_ID: type: string CLIENT_SECRET: type: string USER_FILTER: description: Property for USER_FILTER type: string USER_IMPORT_MAPPING: description: Property for USER_IMPORT_MAPPING type: string ACCOUNT_IMPORT_MAPPING: example: '{''accountID'': ''UserID~#~char'', ''customproperty1'': ''Alias~#~char'', ''customproperty10'': ''Enabled~#~char'', ''customproperty45'': ''WorkflowLineItemNotificationFormat~#~char'', ''customproperty11'': ''DocumentHandlingActive~#~char'', ''customproperty12'': ''UserInfo_defaultPartition~#~char'', ''customproperty13'': ''GlobalListPageLinkMode~#~char'', ''customproperty14'': ''GlobalExcelExportMode~#~char'', ''customproperty15'': ''ShowAttachmentStatus~#~char'', ''customproperty16'': ''EventPopUpLinkDestination~#~char'', ''customproperty17'': ''NetworkDomain~#~char'', ''customproperty18'': ''Company~#~char'', ''customproperty19'': ''SqmGUID~#~char'', ''customproperty2'': ''Email~#~char'', ''customproperty20'': ''SendNotificationsInEmail~#~char'', ''customproperty21'': ''Density~#~char'', ''customproperty22'': ''DefaultCountryRegion~#~char'', ''customproperty23'': ''SendAlertAsEmailMessage~#~char'', ''customproperty24'': ''SqmEnabled~#~char'', ''customproperty25'': ''GlobalExcelExportFilePath~#~char'', ''customproperty26'': ''Language~#~char'', ''customproperty27'': ''EventPopUpDisplayWhen~#~char'', ''customproperty28'': ''EventPollFrequency~#~char'', ''customproperty29'': ''EventWorkflowShowPopup~#~char'', ''customproperty3'': ''EmailProviderID~#~char'', ''customproperty30'': ''StartPage~#~char'', ''customproperty31'': ''PreferredTimeZone~#~char'', ''customproperty32'': ''HomePageRefreshDuration~#~char'', ''customproperty33'': ''UserInfo_language~#~char'', ''customproperty34'': ''AutoLogOff~#~char'', ''customproperty35'': ''Theme~#~char'', ''customproperty36'': ''MarkEmptyLinks~#~char'', ''customproperty37'': ''Enabled~#~char'', ''customproperty38'': ''ShowNotificationsInTheMicrosoftDynamicsAX7Client~#~char'', ''customproperty39'': ''Helplanguage~#~char'', ''customproperty4'': ''PersonName~#~char'', ''customproperty40'': ''EventPopUps~#~char'', ''customproperty41'': ''PreferredCalendar~#~char'', ''customproperty42'': ''PreferredLocale~#~char'', ''customproperty43'': ''ExternalUser~#~char'', ''customproperty44'': ''AutomaticUrlUpdate~#~char'', ''displayName'': ''UserName~#~char'', ''name'': ''UserName~#~char''} ' type: string ORGANIZATION_FILTER: example: LegalEntities,OperatingUnits,Departments,BusinessUnits,CostCenters type: string STATUS_THRESHOLD_CONFIG: example: '{''statusAndThresholdConfig'': {''statusColumn'': ''customproperty37'', ''activeStatus'': [''true''], ''deleteLinks'': True, ''accountThresholdValue'': 1000, ''correlateInactiveAccounts'': False, ''inactivateAccountsNotInFile'': False}} ' type: string ConfigJSON: type: string SCOPE: description: If present - 2.0 API will be used. Accepts space separated values. If blank 1.0 API is used example: https://@INSTANCE_NAME@.cloudax.dynamics.com/.default type: string CreateAccountJSON: description: JSON to specify the Field Value which will be used to Create the New Account example: '{''accountIdPath'': ''call1.message.UserID'', ''call'': [{''name'': ''call1'', ''connection'': ''userAuth'', ''url'': ''https://@INSTANCE_NAME@.cloudax.dynamics.com/Data/SystemUsers'', ''httpMethod'': ''POST'', ''httpParams'': ''{"UserID":"${user.username}","NetworkDomain":"https://sts.windows.net","Company":"DAT","Alias":"${user.email}","DefaultCountryRegion":"${user.country}","StartPage":"DefaultDashboard","UserInfo_language":"en-us","Enabled":true,"UserName":"${user.username}","AccountType":"ClaimsUser","ExternalUser":false,"Helplanguage":"en-us"}'', ''httpHeaders'': {''Authorization'': ''${access_token}'', ''Accept'': ''application/json'', ''OData-Version'': ''4.0''}, ''httpContentType'': ''application/json'', ''successResponses'': {''statusCode'': [201, 200]}, ''unsuccessResponses'': {''statusCode'': [400, 401, 404, 405, 500]}}]} ' type: string UpdateAccountJSON: description: JSON to specify the Field Value which will be used to Update existing Account example: '{''call'': [{''name'': ''call1'', ''connection'': ''userAuth'', ''url'': "https://@INSTANCE_NAME@.cloudax.dynamics.com/Data/SystemUsers(UserID=''${account.accountID}'')", ''httpMethod'': ''PATCH'', ''httpParams'': ''{"Alias":"${user.email}"}'', ''httpHeaders'': {''Authorization'': ''${access_token}'', ''Accept'': ''application/json'', ''OData-Version'': ''4.0''}, ''httpContentType'': ''application/json'', ''successResponses'': {''statusCode'': [200, 201, 204]}}]} ' type: string EnableAccountJSON: description: JSON to specify the different attributes to be checked and action to be performed for enabling a disabled account example: '{''call'': [{''name'': ''call1'', ''connection'': ''userAuth'', ''url'': "https://@INSTANCE_NAME@.cloudax.dynamics.com/Data/SystemUsers(UserID=''${account.accountID}'')", ''httpMethod'': ''PATCH'', ''httpParams'': ''{"Enabled":true}'', ''httpHeaders'': {''Authorization'': ''${access_token}'', ''Accept'': ''application/json'', ''OData-Version'': ''4.0''}, ''httpContentType'': ''application/json'', ''successResponses'': {''statusCode'': [200, 201, 204]}}]} ' type: string DisableAccountJSON: description: JSON to specify the different attributes to be checked and action to be performed for disabling a enabled account example: '{''call'': [{''name'': ''call1'', ''connection'': ''userAuth'', ''url'': "https://@INSTANCE_NAME@.cloudax.dynamics.com/Data/SystemUsers(UserID=''${account.accountID}'')", ''httpMethod'': ''PATCH'', ''httpParams'': ''{"Enabled":false}'', ''httpHeaders'': {''Authorization'': ''${access_token}'', ''Accept'': ''application/json'', ''OData-Version'': ''4.0''}, ''httpContentType'': ''application/json'', ''successResponses'': {''statusCode'': [200, 201, 204]}}]} ' type: string AddAccessJSON: description: JSON to ADD Access to an account example: '{''call'': [{''name'': ''Roles'', ''connection'': ''userAuth'', ''url'': ''https://@INSTANCE_NAME@.cloudax.dynamics.com/Data/SecurityUserRoles'', ''httpMethod'': ''POST'', ''httpParams'': ''{"UserId":"${account.accountID}","SecurityRoleIdentifier":"${entitlementValue.entitlementID}","SecurityRoleName":"${entitlementValue.entitlement_value}","AssignmentStatus": "Enabled","AssignmentMode": "Manual","UserLicenseType": "Activity"}'', ''httpHeaders'': {''Authorization'': ''${access_token}'', ''Accept'': ''application/json'', ''OData-Version'': ''4.0''}, ''httpContentType'': ''application/json'', ''unsuccessResponses'': {''statusCode'': [400, 401]}, ''successResponses'': {''statusCode'': [200, 201, 204]}}, {''name'': ''Organizations'', ''connection'': ''userAuth'', ''url'': ''https://@INSTANCE_NAME@.cloudax.dynamics.com/Data/SecurityUserRoleOrganizations'', ''httpMethod'': ''POST'', ''httpParams'': ''{"UserId":"${account.accountID}","SecurityRoleIdentifier":"${requestAccessAttributes.SecurityRoleIdentifier}","OrganizationType": "${entitlementValue.entclass}","OrganizationId": "${entitlementValue.customproperty7}","OperatingUnitType": "${entitlementValue.customproperty1}"}'', ''httpHeaders'': {''Authorization'': ''${access_token}'', ''Accept'': ''application/json'', ''OData-Version'': ''4.0''}, ''httpContentType'': ''application/json'', ''unsuccessResponses'': {''statusCode'': [400, 401]}, ''successResponses'': {''statusCode'': [200, 201, 204]}}]} ' type: string RemoveAccessJSON: description: JSON to REMOVE Access from an account example: '{''call'': [{''name'': ''Roles'', ''connection'': ''userAuth'', ''url'': "https://@INSTANCE_NAME@.cloudax.dynamics.com/Data/SecurityUserRoles(UserId=''${account.accountID}'',SecurityRoleIdentifier=''${entitlementValue.entitlementID}'')", ''httpMethod'': ''DELETE'', ''httpHeaders'': {''Authorization'': ''${access_token}'', ''Accept'': ''application/json'', ''OData-Version'': ''4.0''}, ''httpContentType'': ''application/json'', ''unsuccessResponses'': {''statusCode'': [400, 401]}, ''successResponses'': {''statusCode'': [200, 201, 204]}}, {''name'': ''Organizations'', ''connection'': ''userAuth'', ''url'': "https://@INSTANCE_NAME@.cloudax.dynamics.com/Data/SecurityUserRoleOrganizations(UserId=''${account.accountID}'',SecurityRoleIdentifier=''${requestAccessAttributes.SecurityRoleIdentifier}'',OrganizationId=''${entitlementValue.customproperty7}'',OrganizationType=Microsoft.Dynamics.DataEntities.OMInternalOrganizationType''${entitlementValue.entclass}'')", ''httpMethod'': ''DELETE'', ''httpHeaders'': {''Authorization'': ''${access_token}'', ''Accept'': ''application/json'', ''OData-Version'': ''4.0''}, ''httpContentType'': ''application/json'', ''unsuccessResponses'': {''statusCode'': [400, 401]}, ''successResponses'': {''statusCode'': [200, 201, 204]}}]} ' type: string RemoveAccountJSON: description: JSON to specify the different attributes to be checked and action to be performed for deleting/suspending an account example: '{''call'': [{''name'': ''call1'', ''connection'': ''userAuth'', ''url'': "https://@INSTANCE_NAME@.cloudax.dynamics.com/Data/SystemUsers(UserID=''${account.accountID}'')", ''httpMethod'': ''DELETE'', ''httpHeaders'': {''Authorization'': ''${access_token}'', ''Accept'': ''application/json'', ''OData-Version'': ''4.0''}, ''httpContentType'': ''application/json'', ''unsuccessResponses'': {''statusCode'': [400, 401]}, ''successResponses'': {''statusCode'': [200, 201, 204]}}]} ' type: string required: - BASEURL - CLIENT_ID - CLIENT_SECRET - LOGIN_URL - TENANT_ID RESTConnectionResponse: allOf: - $ref: '#/components/schemas/getConnectionDetails' - properties: connectionattributes: $ref: '#/components/schemas/RESTConnectionAttributes' GithubRESTConnectionAttributes: properties: isTimeoutSupported: example: true type: boolean ConnectionJSON: type: string PAM_CONFIG: type: string ORGANIZATION_LIST: type: string ImportAccountEntJSON: type: string STATUS_THRESHOLD_CONFIG: type: string ACCESS_TOKENS: type: string connectionTimeoutConfig: $ref: '#/components/schemas/ConnectionTimeoutConfig' connectionType: type: string isTimeoutConfigValidated: example: false type: boolean ADConnectionResponse: allOf: - $ref: '#/components/schemas/getConnectionDetails' - properties: connectionattributes: $ref: '#/components/schemas/ADConnectionAttributes' example: msg: success emailtemplate: '' updatedby: admin(adminfname adminlname) connectionname: AD connectionkey: 120 description: Workday connectionattributes: LAST_IMPORT_TIME: 2017-03-23 00:48:28 CREATEACCOUNTJSON: '{''createaccountqry'': "INSERT IGNORE INTO users (id,displayname,email,empid,firstname,lastname,systemname,username,password) values (${user.id}, ''${user.displayname}'', ''${user.email}'', ''${user.employeeid}'', ''${user.firstname}'',''${user.lastname}'',''${user.systemusername}'', ''${user.username}'',''${randompassword}'')"} ' ENDPOINTS_FILTER: ENDPOINTS_FILTER DISABLEACCOUNTJSON: '{"userAccountControl":"546","deleteAllGroups":"No"}' groupSearchBaseDN: CN=Users,DC=Saviynt,DC=ABC,DC=Com connectionType: MS_BASED_CONNECTOR PASSWORD_NOOFSPLCHARS: '1' STATUSKEYJSON: '{"STATUS_ACTIVE":["512","544"],"STATUS_INACTIVE":["514","546"]}' DEFAULT_USER_ROLE: ROLE_TASK_ADMIN ConfigJSON: '{"connectionTimeoutConfig":{"connectionTimeout":10,"readTimeout":50,"retryWait":2,"retryCount":3}}' CREATEORGJSON: CREATEORGJSON REMOVEACCOUNTACTION: '{"removeAction":"DELETE"}' USERNAME: administrator@saviyntlabs.com ACCOUNTNAMERULE: uid=${task.accountName.toString().toLowerCase()},ou=People,dc=racf,dc=com SETRANDOMPASSWORD: SETRANDOMPASSWORD SETDEFAULTPAGESIZE: SETDEFAULTPAGESIZE isTimeoutSupported: true REUSEINACTIVEACCOUNT: 'true' PASSWORD_NOOFDIGITS: '5' IMPORTJSON: '{"envproperties":{"com.sun.jndi.ldap.connect.timeout":"10000","com.sun.jndi.ldap.read.timeout":"50000"}}' createUpdateMappings: '{"cn":"${role?.customproperty27}","objectCategory":"CN=Group,CN=Schema,CN=Configuration,@DOMCONTRDN@","displayName":"${role?.displayname}","SamAccountName":"${role?.customproperty27}","description":"${role?.description}","objectClass":"group","name":"${role?.customproperty27}"}' ACCOUNT_ATTRIBUTE: '["ACCOUNTID::objectGUID#Binary","NAME::sAMAccountName#String","ACCOUNTCLASS::objectClass#String","DISPLAYNAME::name#String","DESCRIPTION::description#String","LASTLOGONDATE::lastLogon#millisec","VALIDTHROUGH::accountExpires#millisec","COMMENTS::distinguishedName#String","UPDATEDATE::whenChanged#date","LASTPASSWORDCHANGE::pwdLastSet#millisec","CREATED_ON::whenCreated#date","CUSTOMPROPERTY1::cn#String","CUSTOMPROPERTY2::userPrincipalName#String","CUSTOMPROPERTY3::sn#String","CUSTOMPROPERTY4::homeDirectory#String","CUSTOMPROPERTY5::co#String","CUSTOMPROPERTY6::employeeNumber#String","CUSTOMPROPERTY7::givenName#String","CUSTOMPROPERTY8::title#String","CUSTOMPROPERTY9::telephoneNumber#String","CUSTOMPROPERTY10::c#String","CUSTOMPROPERTY11::uSNCreated#String","CUSTOMPROPERTY12::logonCount#String","CUSTOMPROPERTY13::physicalDeliveryOfficeName#String","CUSTOMPROPERTY30::userAccountControl#String","CUSTOMPROPERTY28::primaryGroupID#String","CUSTOMPROPERTY25::company#String","CUSTOMPROPERTY16::streetAddress#String","CUSTOMPROPERTY18::department#String","CUSTOMPROPERTY19::countryCode#String","CUSTOMPROPERTY21::manager#String","CUSTOMPROPERTY22::homePhone#String","CUSTOMPROPERTY23::mobile#String","CUSTOMPROPERTY24::userAccountControl#String","CUSTOMPROPERTY27::objectSid#Binary","CUSTOMPROPERTY26::objectGUID#Binary","RECONCILATION_FIELD::CUSTOMPROPERTY26"]' saveconnection: N PASSWORD: password ADVANCE_FILTER_JSON: ADVANCE_FILTER_JSON ORGIMPORTJSON: ORGIMPORTJSON PAM_CONFIG: '{"Connection":"AD","encryptionMechanism":"ENCRYPTED","CONSOLE":{"maxCredSessionRequestTime":"36000","maxCredlessSessionRequestTime":"36000","shareableAccounts":{"IDQueryCredentials":"acc.name in (''cpamuser1'')","IDQueryCredentialless":"acc.name in (''cpamuser2'', ''cpamuser3'')","IDQueryCredentiallessViewPwd":"acc.name in (''cpamuser2'')"},"endpointAttributeMappings":[{"column":"accessquery","value":"where users.USERNAME is not null","feature":"endpointAccessQuery"},{"column":"customproperty43","value":"PAMDefaultUserAccountAccessControl","feature":"accountVisibilityControl"}],"endpointPamConfig":{"maxConcurrentSession":"50"},"accountVisibilityConfig":{"accountCustomProperty":"customproperty55","accountMappingConfig":[{"accountPattern":"cpamuser*","mappingData":"roletest1","override":"false"},{"accountPattern":"cpamuser1,cpamuser2","mappingData":"roletest2","override":"false"}]}}}' PAGE_SIZE: '1000' SEARCHFILTER: OU=Users,DC=domainname,DC=com MAX_CHANGENUMBER: MAX_CHANGENUMBER PASSWORD_MIN_LENGTH: '8' ENTITLEMENT_ATTRIBUTE: memberOf INCREMENTAL_CONFIG: INCREMENTAL_CONFIG CHECKFORUNIQUE: CHECKFORUNIQUE DC_LOCATOR: DC_LOCATOR connectionTimeoutConfig: retryWait: 0 tokenRefreshMaxTryCount: 6 retryFailureStatusCode: 1 retryWaitMaxValue: 5 retryCount: 5 readTimeout: 2 connectionTimeout: 7 UPDATEUSERJSON: '{"mail":"${user.email}","sn":"${user.lastname}","givenName":"${user.firstname}"}' URL: LDAP://sample.com READ_OPERATIONAL_ATTRIBUTES: 'FALSE' BASE: CN=Users LDAP_OR_AD: AD ORG_BASE: ORG_BASE STATUS_THRESHOLD_CONFIG: '{"statusAndThresholdConfig":{"statusColumn":"CUSTOMPROPERTY4","activeStatus":["n"],"deleteLinks":false,"accountThresholdValue":1000,"correlateInactiveAccounts":true,"inactivateAccountsNotInFile":false}}' UPDATEORGJSON: UPDATEORGJSON groupImportMapping: '{"entitlementTypeName":"memberOf", "performGroupAccountLinking":"true", ...}' FILTER: FILTER RESETANDCHANGEPASSWRDJSON: '{"RESET":{"pwdLastSet":"0","title":"password reset"},"CHANGE":{"pwdLastSet":"-1","title":"password changed"}}' systemname: Dummyapplication USER_ATTRIBUTE: '["USERNAME::sAMAccountName#String", "DISPLAYNAME::displayName#String", ...]' PASSWORD_NOOFCAPSALPHA: '2' MODIFYUSERDATAJSON: MODIFYUSERDATAJSON isTimeoutConfigValidated: true ADVSEARCH: ADVSEARCH SUPPORTEMPTYSTRING: 'FALSE' UNLOCKACCOUNTJSON: '{"lockoutTime":"0"}' ENABLEGROUPMANAGEMENT: 'TRUE' ENABLEACCOUNTJSON: '{"USEDNFROMACCOUNT":"NO","ENABLEACCOUNTOU":"OU=ActiveUsers,OU=TestUsers,dc=test,dc=com"}' PASSWORD_MAX_LENGTH: '12' REUSEACCOUNTJSON: '{"ATTRIBUTESTOCHECK":{"userAccountControl":"514","sn":"${user.lastname}"},"REUSEACCOUNTOU":"OU=ActiveUsers,DC=domainname,DC=com"}' ENFORCE_TREE_DELETION: 'TRUE' OBJECTFILTER: (objectClass=inetorgperson) ORGANIZATION_ATTRIBUTE: ORGANIZATION_ATTRIBUTE UPDATEACCOUNTJSON: '{"uid":"${task.accountName.toString().toLowerCase()}","description":"AS 400 Integration with Saviynt"}' createdon: 2020-03-12 11:49:15+00:00 defaultsavroles: '' createdby: admin(null null) connectiontype: Workday-SOAP errorcode: 0 status: 1 RESTConnector: allOf: - $ref: '#/components/schemas/BaseConnector' - properties: ConnectionJSON: type: string ImportUserJSON: description: Property for ImportUserJSON type: string ImportAccountEntJSON: example: '{''accountParams'': {''connection'': ''Slack'', ''processingType'': ''SequentialAndIterative'', ''statusAndThresholdConfig'': {''statusColumn'': ''customproperty1'', ''activeStatus'': [''true''], ''deleteLinks'': True, ''accountThresholdValue'': 5, ''correlateInactiveAccounts'': False, ''inactivateAccountsNotInFile'': True, ''deleteAccEntForActiveAccounts'': True}, ''call'': {''call1'': {''callOrder'': 0, ''stageNumber'': 0, ''http'': {''url'': ''https://api.slack.com/scim/v1/Users?startIndex=1&count=1000'', ''httpContentType'': ''application/x-www-form-urlencoded'', ''httpMethod'': ''GET'', ''httpHeaders'': {''Authorization'': ''${access_token}'', ''Accept'': ''application/x-www-form-urlencoded''}}, ''listField'': ''Resources'', ''keyField'': ''accountID'', ''colsToPropsMap'': {''accountID'': ''id~#~char'', ''name'': ''userName~#~char'', ''displayName'': ''displayName~#~char'', ''status'': ''active~#~char'', ''customproperty1'': ''active~#~char'', ''customproperty31'': ''STORE#ACC#ENT#MAPPINGINFO~#~char''}, ''pagination'': {''nextUrl'': {''nextUrlPath'': "${response?.objectList?.size()>0?''https://api.slack.com/scim/v1/Users?startIndex=''+Math.addExact(response.completeResponseMap.itemsPerPage,response.completeResponseMap.startIndex)+''&count=''+response.completeResponseMap.itemsPerPage:null}"}}}}, ''acctEntMappings'': {''Group'': {''listPath'': ''groups'', ''idPath'': ''value'', ''keyField'': ''entitlementID''}}}, ''entitlementParams'': {''connection'': ''Slack'', ''processingType'': ''SequentialAndIterative'', ''entTypes'': {''Group'': {''entTypeOrder'': 0, ''entTypeLabels'': {''customproperty1'': ''meta_created''}, ''call'': {''call1'': {''connection'': ''Slack'', ''callOrder'': 0, ''stageNumber'': 0, ''http'': {''httpHeaders'': {''Authorization'': ''${access_token}''}, ''url'': ''https://api.slack.com/scim/v1/Groups?count=1000&startIndex=1'', ''httpContentType'': ''application/json'', ''httpMethod'': ''GET''}, ''listField'': ''Resources'', ''keyField'': ''entitlementID'', ''colsToPropsMap'': {''entitlementID'': ''id~#~char'', ''entitlement_value'': ''displayName~#~char'', ''description'': ''displayName~#~char'', ''customproperty1'': ''meta.created~#~char''}, ''pagination'': {''nextUrl'': {''nextUrlPath'': "${response?.objectList?.size()>0?''https://api.slack.com/scim/v1/Groups?startIndex=''+Math.addExact(response.completeResponseMap.itemsPerPage,response.completeResponseMap.startIndex)+''&count=''+response.completeResponseMap.itemsPerPage:null}"}}, ''disableDeletedEntitlements'': True}}}, ''Channels'': {''entTypeOrder'': 1, ''entTypeLabels'': {''customproperty1'': ''Is_Channel'', ''customproperty2'': ''is_group'', ''customproperty3'': ''is_im'', ''customproperty4'': ''created'', ''customproperty5'': ''is_archived'', ''customproperty6'': ''is_shared'', ''customproperty7'': ''creator'', ''customproperty8'': ''is_ext_shared'', ''customproperty9'': ''is_org_shared'', ''customproperty10'': ''is_member'', ''customproperty11'': ''is_private'', ''customproperty12'': ''is_mpim'', ''customproperty13'': ''num_members'', ''customproperty14'': ''purpose.value''}, ''call'': {''call1'': {''callOrder'': 0, ''stageNumber'': 0, ''http'': {''url'': ''https://slack.com/api/conversations.list?limit=500'', ''httpContentType'': ''application/x-www-form-urlencoded'', ''httpMethod'': ''GET'', ''httpHeaders'': {''Authorization'': ''${access_token}'', ''Accept'': ''application/x-www-form-urlencoded''}}, ''listField'': ''channels'', ''keyField'': ''entitlementID'', ''colsToPropsMap'': {''entitlementID'': ''id~#~char'', ''entitlement_value'': ''name~#~char'', ''customproperty1'': ''is_channel~#~char'', ''customproperty2'': ''is_group~#~char'', ''customproperty3'': ''is_im~#~char'', ''customproperty4'': ''created~#~char'', ''customproperty5'': ''is_archived~#~char'', ''customproperty6'': ''is_shared~#~char'', ''customproperty7'': ''creator~#~char'', ''customproperty8'': ''is_ext_shared~#~char'', ''customproperty9'': ''is_org_shared~#~char'', ''customproperty10'': ''is_member~#~char'', ''customproperty11'': ''is_private~#~char'', ''customproperty12'': ''is_mpim~#~char'', ''customproperty13'': ''num_members~#~char'', ''customproperty14'': ''purpose.value~#~char''}, ''pagination'': {''nextUrl'': {''nextUrlPath'': ''${(response?.completeResponseMap?.response_metadata?.next_cursor == null) || (response?.completeResponseMap?.response_metadata?.next_cursor.equals(""))?null:\''https://slack.com/api/conversations.list?limit=500&cursor=\''+response?.completeResponseMap?.response_metadata?.next_cursor}''}}, ''disableDeletedEntitlements'': True}}}}}, ''acctEntParams'': {''connection'': ''Slack'', ''entTypes'': {''Channels'': {''call'': {''call1'': {''processingType'': ''httpEntToAcct'', ''callOrder'': 0, ''stageNumber'': 1, ''connection'': ''Slack'', ''http'': {''httpHeaders'': {''Authorization'': ''${access_token}''}, ''url'': ''https://slack.com/api/conversations.members?channel=${id}&limit=10'', ''httpContentType'': ''application/x-www-form-urlencoded'', ''httpMethod'': ''GET''}, ''listField'': ''members'', ''acctKeyField'': ''accountID'', ''entKeyField'': ''entitlementID'', ''acctIdPath'': '''', ''pagination'': {''nextUrl'': {''nextUrlPath'': ''${(response?.completeResponseMap?.response_metadata?.next_cursor == null) || (response?.completeResponseMap?.response_metadata?.next_cursor.equals(""))?null:\''https://slack.com/api/conversations.list?limit=500&cursor=\''+response?.completeResponseMap?.response_metadata?.next_cursor}''}}}}}, ''Group'': {''call'': {''call1'': {''callOrder'': 0, ''stageNumber'': 0, ''processingType'': ''acctToEntMapping''}}}}}} ' type: string STATUS_THRESHOLD_CONFIG: type: string CreateAccountJSON: example: '{''accountIdPath'': ''call1.message.id'', ''dateFormat'': "yyyy-MM-dd''T''HH:mm:ssXXX", ''responseColsToPropsMap'': {''name'': ''call1.message.username~#~char'', ''displayName'': ''call1.message.displayName~#~char'', ''updatedate'': ''call1.message.meta.created~#~date'', ''comments'': ''call1.message.emails[0].value~#~char''}, ''call'': [{''name'': ''call1'', ''connection'': ''Slack'', ''url'': ''https://api.slack.com/scim/v1/Users'', ''httpMethod'': ''POST'', ''httpParams'': ''{"schemas":["urn:scim:schemas:core:1.0"],"userName": "${user.username}","nickName": "${user.firstname}", "name": {"givenName": "${user.firstname}","familyName": "${user.lastname}"},"active": false,"emails": [{"value": "${user.email}", "primary": true}]}'', ''httpHeaders'': {''Authorization'': ''${access_token}''}, ''httpContentType'': ''application/json'', ''successResponses'': {''statusCode'': [201]}, ''unsuccessResponses'': {''statusCode'': [400, 500]}}]} ' type: string UpdateAccountJSON: example: '{''call'': [{''name'': ''call1'', ''connection'': ''Slack'', ''url'': ''https://api.slack.com/scim/v1/Users/${account.accountID}'', ''httpMethod'': ''PATCH'', ''httpParams'': ''{"schemas":["urn:scim:schemas:core:1.0"],"active":false,"userName":"${user.username}","nickName":"${user.username}","name":{"givenName":"${user.firstname}","familyName":"${user.lastname}"},"displayName":"${user.displayname}","emails":[{"value":"${user.email}","primary":true}]}'', ''httpHeaders'': {''Authorization'': ''${access_token}''}, ''httpContentType'': ''application/json'', ''successResponses'': {''statusCode'': [200]}, ''unsuccessResponses'': {''statusCode'': [400, 500]}}]} ' type: string EnableAccountJSON: example: '{''call'': [{''name'': ''call1'', ''connection'': ''Slack'', ''url'': ''https://api.slack.com/scim/v1/Users/${account.accountID}'', ''httpMethod'': ''PATCH'', ''httpParams'': ''{"active" : true}'', ''httpHeaders'': {''Authorization'': ''${access_token}''}, ''httpContentType'': ''application/json'', ''successResponses'': {''statusCode'': [200]}, ''unsuccessResponses'': {''statusCode'': [400, 500]}}]} ' type: string DisableAccountJSON: example: '{''call'': [{''name'': ''call1'', ''connection'': ''Slack'', ''url'': ''https://api.slack.com/scim/v1/Users/${account.accountID}'', ''httpMethod'': ''PATCH'', ''httpParams'': ''{"active" : false}'', ''httpHeaders'': {''Authorization'': ''${access_token}''}, ''httpContentType'': ''application/json'', ''successResponses'': {''statusCode'': [200]}, ''unsuccessResponses'': {''statusCode'': [400, 500]}}]} ' type: string AddAccessJSON: example: '{''call'': [{''name'': ''Group'', ''connection'': ''Slack'', ''url'': ''https://api.slack.com/scim/v1/Groups/${entitlementValue.entitlementID}'', ''httpMethod'': ''PATCH'', ''httpParams'': ''{"schemas": ["urn:scim:schemas:core:1.0"],"members": [{"value": "${account.accountID}"}]}'', ''httpHeaders'': {''Authorization'': ''${access_token}'', ''Accept'': ''application/json''}, ''httpContentType'': ''application/json'', ''successResponses'': {''statusCode'': [204]}}, {''name'': ''Channels'', ''connection'': ''Slack'', ''url'': ''https://slack.com/api/conversations.invite?channel=${entitlementValue.entitlementID}&users=${account.accountID}'', ''httpMethod'': ''POST'', ''httpHeaders'': {''Authorization'': ''${access_token}'', ''Accept'': ''application/x-www-form-urlencoded''}, ''httpContentType'': ''application/x-www-form-urlencoded'', ''successResponses'': {''statusCode'': [200]}}]} ' type: string RemoveAccessJSON: example: '{''call'': [{''name'': ''Group'', ''connection'': ''Slack'', ''url'': ''https://api.slack.com/scim/v1/Groups/${entitlementValue.entitlementID}'', ''httpMethod'': ''PATCH'', ''httpParams'': ''{"schemas": ["urn:scim:schemas:core:1.0"],"members": [{"value": "${account.accountID}","operation": "delete"}]}'', ''httpHeaders'': {''Authorization'': ''${access_token}'', ''Accept'': ''application/json''}, ''httpContentType'': ''application/json'', ''successResponses'': {''statusCode'': [204]}}, {''name'': ''Channels'', ''connection'': ''Slack'', ''url'': ''https://slack.com/api/conversations.kick?channel=${entitlementValue.entitlementID}&user=${account.accountID}'', ''httpMethod'': ''POST'', ''httpHeaders'': {''Authorization'': ''${access_token}'', ''Accept'': ''application/x-www-form-urlencoded''}, ''httpContentType'': ''application/x-www-form-urlencoded'', ''successResponses'': {''statusCode'': [200]}}]} ' type: string UpdateUserJSON: description: Property for UpdateUserJSON type: string ChangePassJSON: type: string RemoveAccountJSON: example: '{''call'': [{''name'': ''call1'', ''connection'': ''Slack'', ''url'': ''https://api.slack.com/scim/v1/Users/${account.accountID}'', ''httpMethod'': ''DELETE'', ''httpHeaders'': {''Authorization'': ''${access_token}''}, ''httpContentType'': ''application/json'', ''successResponses'': {''statusCode'': [200, 204, 201]}}]} ' type: string TicketStatusJSON: type: string CreateTicketJSON: type: string ENDPOINTS_FILTER: type: string PasswdPolicyJSON: type: string ConfigJSON: description: We can use this attribute to define the provisioningLimit,showLogs and connectionTimeoutConfig. example: '{''connectionTimeoutConfig'': {''connectionTimeout'': 10, ''readTimeout'': 60, ''writeTimeout'': 60, ''retryCount'': 3, ''retryWait'': 2}} ' type: string AddFFIDAccessJSON: type: string RemoveFFIDAccessJSON: type: string MODIFYUSERDATAJSON: type: string SendOtpJSON: type: string ValidateOtpJSON: type: string PAM_CONFIG: type: string CreateEntitlementJSON: type: string DeleteEntitlementJSON: type: string UpdateEntitlementJSON: type: string ApplicationDiscoveryJSON: type: string AppType: description: For CUA configuration type: string ADConnectionAttributes: example: LAST_IMPORT_TIME: 2017-03-23 00:48:28 CREATEACCOUNTJSON: '{''createaccountqry'': "INSERT IGNORE INTO users (id,displayname,email,empid,firstname,lastname,systemname,username,password) values (${user.id}, ''${user.displayname}'', ''${user.email}'', ''${user.employeeid}'', ''${user.firstname}'',''${user.lastname}'',''${user.systemusername}'', ''${user.username}'',''${randompassword}'')"} ' ENDPOINTS_FILTER: ENDPOINTS_FILTER DISABLEACCOUNTJSON: '{"userAccountControl":"546","deleteAllGroups":"No"}' groupSearchBaseDN: CN=Users,DC=Saviynt,DC=ABC,DC=Com connectionType: MS_BASED_CONNECTOR PASSWORD_NOOFSPLCHARS: '1' STATUSKEYJSON: '{"STATUS_ACTIVE":["512","544"],"STATUS_INACTIVE":["514","546"]}' DEFAULT_USER_ROLE: ROLE_TASK_ADMIN ConfigJSON: '{"connectionTimeoutConfig":{"connectionTimeout":10,"readTimeout":50,"retryWait":2,"retryCount":3}}' CREATEORGJSON: CREATEORGJSON REMOVEACCOUNTACTION: '{"removeAction":"DELETE"}' USERNAME: administrator@saviyntlabs.com ACCOUNTNAMERULE: uid=${task.accountName.toString().toLowerCase()},ou=People,dc=racf,dc=com SETRANDOMPASSWORD: SETRANDOMPASSWORD SETDEFAULTPAGESIZE: SETDEFAULTPAGESIZE isTimeoutSupported: true REUSEINACTIVEACCOUNT: 'true' PASSWORD_NOOFDIGITS: '5' IMPORTJSON: '{"envproperties":{"com.sun.jndi.ldap.connect.timeout":"10000","com.sun.jndi.ldap.read.timeout":"50000"}}' createUpdateMappings: '{"cn":"${role?.customproperty27}","objectCategory":"CN=Group,CN=Schema,CN=Configuration,@DOMCONTRDN@","displayName":"${role?.displayname}","SamAccountName":"${role?.customproperty27}","description":"${role?.description}","objectClass":"group","name":"${role?.customproperty27}"}' ACCOUNT_ATTRIBUTE: '["ACCOUNTID::objectGUID#Binary","NAME::sAMAccountName#String","ACCOUNTCLASS::objectClass#String","DISPLAYNAME::name#String","DESCRIPTION::description#String","LASTLOGONDATE::lastLogon#millisec","VALIDTHROUGH::accountExpires#millisec","COMMENTS::distinguishedName#String","UPDATEDATE::whenChanged#date","LASTPASSWORDCHANGE::pwdLastSet#millisec","CREATED_ON::whenCreated#date","CUSTOMPROPERTY1::cn#String","CUSTOMPROPERTY2::userPrincipalName#String","CUSTOMPROPERTY3::sn#String","CUSTOMPROPERTY4::homeDirectory#String","CUSTOMPROPERTY5::co#String","CUSTOMPROPERTY6::employeeNumber#String","CUSTOMPROPERTY7::givenName#String","CUSTOMPROPERTY8::title#String","CUSTOMPROPERTY9::telephoneNumber#String","CUSTOMPROPERTY10::c#String","CUSTOMPROPERTY11::uSNCreated#String","CUSTOMPROPERTY12::logonCount#String","CUSTOMPROPERTY13::physicalDeliveryOfficeName#String","CUSTOMPROPERTY30::userAccountControl#String","CUSTOMPROPERTY28::primaryGroupID#String","CUSTOMPROPERTY25::company#String","CUSTOMPROPERTY16::streetAddress#String","CUSTOMPROPERTY18::department#String","CUSTOMPROPERTY19::countryCode#String","CUSTOMPROPERTY21::manager#String","CUSTOMPROPERTY22::homePhone#String","CUSTOMPROPERTY23::mobile#String","CUSTOMPROPERTY24::userAccountControl#String","CUSTOMPROPERTY27::objectSid#Binary","CUSTOMPROPERTY26::objectGUID#Binary","RECONCILATION_FIELD::CUSTOMPROPERTY26"]' saveconnection: N PASSWORD: password ADVANCE_FILTER_JSON: ADVANCE_FILTER_JSON ORGIMPORTJSON: ORGIMPORTJSON PAM_CONFIG: '{"Connection":"AD","encryptionMechanism":"ENCRYPTED","CONSOLE":{"maxCredSessionRequestTime":"36000","maxCredlessSessionRequestTime":"36000","shareableAccounts":{"IDQueryCredentials":"acc.name in (''cpamuser1'')","IDQueryCredentialless":"acc.name in (''cpamuser2'', ''cpamuser3'')","IDQueryCredentiallessViewPwd":"acc.name in (''cpamuser2'')"},"endpointAttributeMappings":[{"column":"accessquery","value":"where users.USERNAME is not null","feature":"endpointAccessQuery"},{"column":"customproperty43","value":"PAMDefaultUserAccountAccessControl","feature":"accountVisibilityControl"}],"endpointPamConfig":{"maxConcurrentSession":"50"},"accountVisibilityConfig":{"accountCustomProperty":"customproperty55","accountMappingConfig":[{"accountPattern":"cpamuser*","mappingData":"roletest1","override":"false"},{"accountPattern":"cpamuser1,cpamuser2","mappingData":"roletest2","override":"false"}]}}}' PAGE_SIZE: '1000' SEARCHFILTER: OU=Users,DC=domainname,DC=com MAX_CHANGENUMBER: MAX_CHANGENUMBER PASSWORD_MIN_LENGTH: '8' ENTITLEMENT_ATTRIBUTE: memberOf INCREMENTAL_CONFIG: INCREMENTAL_CONFIG CHECKFORUNIQUE: CHECKFORUNIQUE DC_LOCATOR: DC_LOCATOR connectionTimeoutConfig: retryWait: 0 tokenRefreshMaxTryCount: 6 retryFailureStatusCode: 1 retryWaitMaxValue: 5 retryCount: 5 readTimeout: 2 connectionTimeout: 7 UPDATEUSERJSON: '{"mail":"${user.email}","sn":"${user.lastname}","givenName":"${user.firstname}"}' URL: LDAP://sample.com READ_OPERATIONAL_ATTRIBUTES: 'FALSE' BASE: CN=Users LDAP_OR_AD: AD ORG_BASE: ORG_BASE STATUS_THRESHOLD_CONFIG: '{"statusAndThresholdConfig":{"statusColumn":"CUSTOMPROPERTY4","activeStatus":["n"],"deleteLinks":false,"accountThresholdValue":1000,"correlateInactiveAccounts":true,"inactivateAccountsNotInFile":false}}' UPDATEORGJSON: UPDATEORGJSON groupImportMapping: '{"entitlementTypeName":"memberOf", "performGroupAccountLinking":"true", ...}' FILTER: FILTER RESETANDCHANGEPASSWRDJSON: '{"RESET":{"pwdLastSet":"0","title":"password reset"},"CHANGE":{"pwdLastSet":"-1","title":"password changed"}}' systemname: Dummyapplication USER_ATTRIBUTE: '["USERNAME::sAMAccountName#String", "DISPLAYNAME::displayName#String", ...]' PASSWORD_NOOFCAPSALPHA: '2' MODIFYUSERDATAJSON: MODIFYUSERDATAJSON isTimeoutConfigValidated: true ADVSEARCH: ADVSEARCH SUPPORTEMPTYSTRING: 'FALSE' UNLOCKACCOUNTJSON: '{"lockoutTime":"0"}' ENABLEGROUPMANAGEMENT: 'TRUE' ENABLEACCOUNTJSON: '{"USEDNFROMACCOUNT":"NO","ENABLEACCOUNTOU":"OU=ActiveUsers,OU=TestUsers,dc=test,dc=com"}' PASSWORD_MAX_LENGTH: '12' REUSEACCOUNTJSON: '{"ATTRIBUTESTOCHECK":{"userAccountControl":"514","sn":"${user.lastname}"},"REUSEACCOUNTOU":"OU=ActiveUsers,DC=domainname,DC=com"}' ENFORCE_TREE_DELETION: 'TRUE' OBJECTFILTER: (objectClass=inetorgperson) ORGANIZATION_ATTRIBUTE: ORGANIZATION_ATTRIBUTE UPDATEACCOUNTJSON: '{"uid":"${task.accountName.toString().toLowerCase()}","description":"AS 400 Integration with Saviynt"}' properties: URL: description: Host Name for connection example: LDAP://sample.com type: string connectionType: description: Connection type example: MS_BASED_CONNECTOR type: string LAST_IMPORT_TIME: description: Timestamp of the last import operation. example: 2017-03-23 00:48:28 type: string CREATEACCOUNTJSON: description: JSON template for creating an account. example: '{''createaccountqry'': "INSERT IGNORE INTO users (id,displayname,email,empid,firstname,lastname,systemname,username,password) values (${user.id}, ''${user.displayname}'', ''${user.email}'', ''${user.employeeid}'', ''${user.firstname}'',''${user.lastname}'',''${user.systemusername}'', ''${user.username}'',''${randompassword}'')"} ' type: string DISABLEACCOUNTJSON: description: JSON to specify the different attributes to be checked and action to be performed for disabling an active account. example: '{"userAccountControl":"546","deleteAllGroups":"No"}' type: string groupSearchBaseDN: description: Base DN for group search in LDAP. example: CN=Users,DC=Saviynt,DC=ABC,DC=Com type: string PASSWORD_NOOFSPLCHARS: description: Number of special characters in password. example: '1' type: string PASSWORD_NOOFDIGITS: description: Specify the Number of digits required for the random password. example: '5' type: string STATUSKEYJSON: description: JSON configuration for account statuses. example: '{"STATUS_ACTIVE":["512","544"],"STATUS_INACTIVE":["514","546"]}' type: string SEARCHFILTER: description: LDAP search filter. example: OU=Users,DC=domainname,DC=com type: string ConfigJSON: description: We can use this attribute to define the connectionTimeoutConfig. example: '{"connectionTimeoutConfig":{"connectionTimeout":10,"readTimeout":50,"retryWait":2,"retryCount":3}}' type: string REMOVEACCOUNTACTION: description: Action performed on account removal. example: '{"removeAction":"DELETE"}' type: string ACCOUNT_ATTRIBUTE: description: Map LDAP user attribute to EIC account attribute for import example: '["ACCOUNTID::objectGUID#Binary","NAME::sAMAccountName#String","ACCOUNTCLASS::objectClass#String","DISPLAYNAME::name#String","DESCRIPTION::description#String","LASTLOGONDATE::lastLogon#millisec","VALIDTHROUGH::accountExpires#millisec","COMMENTS::distinguishedName#String","UPDATEDATE::whenChanged#date","LASTPASSWORDCHANGE::pwdLastSet#millisec","CREATED_ON::whenCreated#date","CUSTOMPROPERTY1::cn#String","CUSTOMPROPERTY2::userPrincipalName#String","CUSTOMPROPERTY3::sn#String","CUSTOMPROPERTY4::homeDirectory#String","CUSTOMPROPERTY5::co#String","CUSTOMPROPERTY6::employeeNumber#String","CUSTOMPROPERTY7::givenName#String","CUSTOMPROPERTY8::title#String","CUSTOMPROPERTY9::telephoneNumber#String","CUSTOMPROPERTY10::c#String","CUSTOMPROPERTY11::uSNCreated#String","CUSTOMPROPERTY12::logonCount#String","CUSTOMPROPERTY13::physicalDeliveryOfficeName#String","CUSTOMPROPERTY30::userAccountControl#String","CUSTOMPROPERTY28::primaryGroupID#String","CUSTOMPROPERTY25::company#String","CUSTOMPROPERTY16::streetAddress#String","CUSTOMPROPERTY18::department#String","CUSTOMPROPERTY19::countryCode#String","CUSTOMPROPERTY21::manager#String","CUSTOMPROPERTY22::homePhone#String","CUSTOMPROPERTY23::mobile#String","CUSTOMPROPERTY24::userAccountControl#String","CUSTOMPROPERTY27::objectSid#Binary","CUSTOMPROPERTY26::objectGUID#Binary","RECONCILATION_FIELD::CUSTOMPROPERTY26"]' type: string ACCOUNTNAMERULE: description: Rule to generate account name. example: uid=${task.accountName.toString().toLowerCase()},ou=People,dc=racf,dc=com type: string ADVSEARCH: description: Advanced search criteria. type: string USERNAME: description: LDAP or system admin username. example: administrator@saviyntlabs.com type: string PASSWORD: description: Set the Password example: password type: string LDAP_OR_AD: description: Type of Endpoint - LDAP or AD, default value is AD example: AD type: string ENTITLEMENT_ATTRIBUTE: description: Attribute used for entitlements. example: memberOf type: string SETRANDOMPASSWORD: description: Set random password option. type: string example: null PASSWORD_MIN_LENGTH: description: Minimum password length. example: '8' type: string PASSWORD_MAX_LENGTH: description: Maximum password length. example: '12' type: string PASSWORD_NOOFCAPSALPHA: description: Specify the number of special characters required for the random password. example: '2' type: string SETDEFAULTPAGESIZE: description: Default page size for data retrieval. type: string isTimeoutSupported: description: Indicates if timeout is supported. type: boolean REUSEINACTIVEACCOUNT: description: Flag to determine if inactive accounts can be reused. example: 'true' type: string IMPORTJSON: description: JSON import configurations. example: '{"envproperties":{"com.sun.jndi.ldap.connect.timeout":"10000","com.sun.jndi.ldap.read.timeout":"50000"}}' type: string createUpdateMappings: description: Mapping used during group creation and updation. example: '{"cn":"${role?.customproperty27}","objectCategory":"CN=Group,CN=Schema,CN=Configuration,@DOMCONTRDN@","displayName":"${role?.displayname}","SamAccountName":"${role?.customproperty27}","description":"${role?.description}","objectClass":"group","name":"${role?.customproperty27}"}' type: string ADVANCE_FILTER_JSON: description: Advanced filter criteria in JSON format. type: string ORGIMPORTJSON: description: JSON configuration for importing organizations. type: string PAM_CONFIG: description: JSON to specify Bootstrap Config. example: '{"Connection":"AD","encryptionMechanism":"ENCRYPTED","CONSOLE":{"maxCredSessionRequestTime":"36000","maxCredlessSessionRequestTime":"36000","shareableAccounts":{"IDQueryCredentials":"acc.name in (''cpamuser1'')","IDQueryCredentialless":"acc.name in (''cpamuser2'', ''cpamuser3'')","IDQueryCredentiallessViewPwd":"acc.name in (''cpamuser2'')"},"endpointAttributeMappings":[{"column":"accessquery","value":"where users.USERNAME is not null","feature":"endpointAccessQuery"},{"column":"customproperty43","value":"PAMDefaultUserAccountAccessControl","feature":"accountVisibilityControl"}],"endpointPamConfig":{"maxConcurrentSession":"50"},"accountVisibilityConfig":{"accountCustomProperty":"customproperty55","accountMappingConfig":[{"accountPattern":"cpamuser*","mappingData":"roletest1","override":"false"},{"accountPattern":"cpamuser1,cpamuser2","mappingData":"roletest2","override":"false"}]}}}' type: string PAGE_SIZE: description: LDAP pagination page size. example: '1000' type: string BASE: description: LDAP base DN. example: CN=Users type: string DC_LOCATOR: description: Domain Controller locator. type: string STATUS_THRESHOLD_CONFIG: description: JSON configuration for account status thresholds. example: '{"statusAndThresholdConfig":{"statusColumn":"CUSTOMPROPERTY4","activeStatus":["n"],"deleteLinks":false,"accountThresholdValue":1000,"correlateInactiveAccounts":true,"inactivateAccountsNotInFile":false}}' type: string RESETANDCHANGEPASSWRDJSON: description: JSON actions for password reset/change. example: '{"RESET":{"pwdLastSet":"0","title":"password reset"},"CHANGE":{"pwdLastSet":"-1","title":"password changed"}}' type: string SUPPORTEMPTYSTRING: description: Set to TRUE to send an empty value or null string during provisioning. example: 'FALSE' type: string READ_OPERATIONAL_ATTRIBUTES: description: Set to TRUE to send an empty value or null string during provisioning. example: 'FALSE' type: string ENABLEACCOUNTJSON: description: JSON configuration to enable account actions. example: '{"USEDNFROMACCOUNT":"NO","ENABLEACCOUNTOU":"OU=ActiveUsers,OU=TestUsers,dc=test,dc=com"}' type: string USER_ATTRIBUTE: description: Map LDAP user attribute to EIC user attribute for import. example: '["USERNAME::sAMAccountName#String", "DISPLAYNAME::displayName#String", ...]' type: string DEFAULT_USER_ROLE: description: Default SAV Role to be assigned to all the new users imported via User Import. example: ROLE_TASK_ADMIN type: string ENDPOINTS_FILTER: description: Configuration to create Child Endpoints and import associated accounts and entitlements. type: string UPDATEACCOUNTJSON: description: To update an existing account, specify the value of the UPDATEACCOUNTJSON parameter. example: '{"uid":"${task.accountName.toString().toLowerCase()}","description":"AS 400 Integration with Saviynt"}' type: string REUSEACCOUNTJSON: description: To retain the suspended user accounts, specify the value of the REUSEACCOUNTJSON parameter. example: '{"ATTRIBUTESTOCHECK":{"userAccountControl":"514","sn":"${user.lastname}"},"REUSEACCOUNTOU":"OU=ActiveUsers,DC=domainname,DC=com"}' type: string ENFORCE_TREE_DELETION: description: Enforce tree deletion in LDAP. example: 'TRUE' type: string FILTER: description: Filters the objects that will be returned. type: string OBJECTFILTER: description: LDAP object filter. example: (objectClass=inetorgperson) type: string UPDATEUSERJSON: description: JSON template for updating user attributes. example: '{"mail":"${user.email}","sn":"${user.lastname}","givenName":"${user.firstname}"}' type: string saveconnection: description: Flag to save connection permanently. example: N type: string systemname: description: Associated system name. example: Dummyapplication type: string groupImportMapping: description: Mapping for importing groups. example: '{"entitlementTypeName":"memberOf", "performGroupAccountLinking":"true", ...}' type: string UNLOCKACCOUNTJSON: description: JSON template for unlocking accounts. example: '{"lockoutTime":"0"}' type: string ENABLEGROUPMANAGEMENT: description: Specify TRUE to enable Group Management for AD. example: 'TRUE' type: string MODIFYUSERDATAJSON: description: JSON template for modifying user data. type: string ORG_BASE: description: Base DN for organization searches. type: string ORGANIZATION_ATTRIBUTE: description: Attribute used for organization management. type: string CREATEORGJSON: description: JSON template for creating an organization. type: string UPDATEORGJSON: description: JSON template for updating an organization. type: string MAX_CHANGENUMBER: description: Maximum change number for incremental syncs. type: string INCREMENTAL_CONFIG: description: Configuration for incremental data sync. type: string CHECKFORUNIQUE: description: Rules for checking unique users in JSON format. type: string connectionTimeoutConfig: $ref: '#/components/schemas/ConnectionTimeoutConfig' isTimeoutConfigValidated: description: Indicates if timeout configuration is validated. type: boolean DBConnector: allOf: - $ref: '#/components/schemas/BaseConnector' - properties: URL: description: Host Name for connection example: '' type: string USERNAME: description: Username for connection example: '' type: string PASSWORD: description: Password for connection example: '' type: string DRIVERNAME: description: Driver name for the connection example: oracle.jdbc.OracleDriver type: string CONNECTIONPROPERTIES: description: Properties that needs to be added when connecting to the database example: '{''sslConnection'': ''false''} ' type: string PASSWORD_MIN_LENGTH: description: Specify the Min length for the random password example: oracle.jdbc.OracleDriver type: string PASSWORD_MAX_LENGTH: description: Specify the Max length for the random password example: oracle.jdbc.OracleDriver type: string PASSWORD_NOOFCAPSALPHA: description: Specify the Number of Upper case alphabets required for the random password example: oracle.jdbc.OracleDriver type: string PASSWORD_NOOFDIGITS: description: Specify the Number of digits required for the random password example: oracle.jdbc.OracleDriver type: string PASSWORD_NOOFSPLCHARS: description: Specify the Number of special chars required for the random password example: oracle.jdbc.OracleDriver type: string CREATEACCOUNTJSON: description: JSON to specify the Queries/stored procedures which will be used to Create the New Account,Objects Exposed-(randomPassword,task,user,accountName,role,endpoint and all the objects defined in Dynamic Attributes ) example: '{''createaccountqry'': "INSERT IGNORE INTO users (id,displayname,email,empid,firstname,lastname,systemname,username,password) values (${user.id}, ''${user.displayname}'', ''${user.email}'', ''${user.employeeid}'', ''${user.firstname}'',''${user.lastname}'',''${user.systemusername}'', ''${user.username}'',''${randompassword}'')"} ' type: string UPDATEACCOUNTJSON: description: JSON to specify the Queries/stored procedures which will be used to Update an existing Account,Objects Exposed-(randomPassword,task,user,accountName,role,endpoint and all the objects defined in Dynamic Attributes ). example: '{''updateaccountqry'': "update users set displayname = ''${user.displayname}'' , email = ''${user.email}'', employeeid = ''${user.employeeid}'' , username=''${user.username}'' ,firstname=''${user.firstname}'' where userkey=''${user.id}''"} ' type: string GRANTACCESSJSON: description: 'JSON to specify the Queries/stored procedures which will be used to provide acccess,Objects Exposed-(task,user,accountName,role,endpoint and all the objects defined in Dynamic Attributes ). ' example: '{''entitlement_type1'': "call grantent1(''${accountname}'', ''${task.entitlement_valuekey.customproperty7}'', ''${task.entitlement_valuekey.entitlement_value}'')", ''entitlement_type2'': "call grantent2(''${accountname}'', ''${task.entitlement_valuekey.customproperty7}'', ''${task.entitlement_valuekey.entitlement_value}'')"} ' type: string REVOKEACCESSJSON: description: JSON to specify the Queries/stored procedures which will be used to revoke access,Objects Exposed-(task,user,accountName,role,endpoint and all the objects defined in Dynamic Attributes ). example: '{''entitlement_type1'': "call revokeent1(''${accountname}'', ''${task.entitlement_valuekey.customproperty7}'', ''${task.entitlement_valuekey.entitlement_value}'')", ''entitlement_type2'': "call revokeent2(''${accountname}'', ''${task.entitlement_valuekey.customproperty7}'', ''${task.entitlement_valuekey.entitlement_value}'')"} ' type: string CHANGEPASSJSON: description: 'JSON to specify the Queries/stored procedures which will be used to change password,Objects Exposed-(randomPassword,task,user,accountName,role,endpoint and all the objects defined in Dynamic Attributes ). ' example: '{''changepasswordqry'': "update users set password=''${task.password}'' where userkey = ${user.id}"} ' type: string DELETEACCOUNTJSON: description: JSON to specify the Queries/stored procedures which will be used to delete an account,Objects Exposed-(task,user,accountName,role,endpoint and all the objects defined in Dynamic Attributes ). example: '{''deleteaccountqry'': "call deleteaccount(''${accountName}'')"} ' type: string ENABLEACCOUNTJSON: description: JSON to specify the Queries/stored procedures which will be used to Enable,Objects Exposed-(task,user,accountName,role,endpoint and all the objects defined in Dynamic Attributes ). example: '{''enableaccountqry'': ''update users set enabled = 1 where userkey = ${user.id}''} ' type: string DISABLEACCOUNTJSON: description: JSON to specify the Queries/stored procedures which will be used to Disable Account,Objects Exposed-(task,user,accountName,role,endpoint and all the objects defined in Dynamic Attributes ). example: '{''disableaccountqry'': ''update users set enabled = 0 where userkey = ${user.id}''} ' type: string ACCOUNTEXISTSJSON: description: JSON to specify the Query which will be used to check whether an account exists,Objects Exposed-(task,user,accountName,role,endpoint and all the objects defined in Dynamic Attributes ). example: '{''AccountExistQry'': ''SELECT * FROM USERS where USERKEY =${user.id}''} ' type: string UPDATEUSERJSON: description: JSON to specify the Queries/stored procedures which will be used to Update an existing Account,Objects Exposed-(randomPassword,task,user,accountName,role,updatetaskuser,endpoint and all the objects defined in Dynamic Attributes ). example: oracle.jdbc.OracleDriver type: string ACCOUNTSIMPORT: description: Accounts Import XML file content example: ' ' type: string ENTITLEMENTVALUEIMPORT: description: Entitlement Value Import XML file content example: ' ' type: string ROLEOWNERIMPORT: description: Role Owner Import XML file contentT example: oracle.jdbc.OracleDriver type: string ROLESIMPORT: description: Roles Import XML file content example: oracle.jdbc.OracleDriver type: string SYSTEMIMPORT: description: System Import XML file content example: oracle.jdbc.OracleDriver type: string USERIMPORT: description: User Import XML file content example: oracle.jdbc.OracleDriver type: string MODIFYUSERDATAJSON: description: Property for MODIFYUSERDATAJSON example: oracle.jdbc.OracleDriver type: string STATUS_THRESHOLD_CONFIG: description: 'Applicable for Accounts full import only.If this config isdefined with status/threshold values, it will take precedence over account_not_in_file_action defined in ACCOUNTIMPORT xml.If this config is defined with only correlateInactiveAccounts, then account_not_in_file_action will used as normal.The attributes of statusAndThresholdConfig json are:statusColumn: Property in saviynt which stores the status of target system.activeStatus:All possible values that denotes the Active status of the target system.accountThresholdValue: No. of accounts to be deleted in Saviynt >= accountThresholdValue, it performs NO ACTION, else it disables the accounts.inactivateAccountsNotInFile: If true,accounts not in file are marked as Inactive. If false, accounts not in file are marked as SUSPENDED FROM IMPORT SERVICE.CorrelateInactiveAccounts: If true, correlates disabled accounts as well with the users.' example: '{''statusAndThresholdConfig'': {''accountThresholdValue'': 1000, ''accountEntThresholdValue'': 1000, ''entThresholdValue'': 1000, ''deleteAccEntForActiveAccounts'': True, ''statusColumn'': ''status'', ''deleteLinks'': False, ''correlateInactiveAccounts'': True, ''inactivateAccountsNotInFile'': False, ''inactivateEntsNotInFeed'': True, ''activeStatus'': [''1'', ''Active''], ''inactiveStatus'': [''0'', ''Inactive''], ''lockedStatusColumn'': ''userlock'', ''lockedStatusMapping'': {''Locked'': [''1''], ''Unlocked'': [''0'']}}} ' type: string MAX_PAGINATION_SIZE: description: Defines the max number of records from the target to be processed in each page example: oracle.jdbc.OracleDriver type: string CLI_COMMAND_JSON: description: JSON to specify the commands which can be executed in target server. example: oracle.jdbc.OracleDriver type: string CREATEENTITLEMENTJSON: type: string DELETEENTITLEMENTJSON: type: string ENTITLEMENTEXISTJSON: type: string UPDATEENTITLEMENTJSON: type: string required: - DRIVERNAME - PASSWORD - URL - USERNAME getConnectionDetails_request: properties: connectionname: description: Name of the connection example: test-conn type: string connectionkey: description: Connection key example: '1092' type: string getConnectionsResponse_ConnectionList_inner: example: CONNECTIONTYPE: AD STATUS: 1 UPDATEDON: 2017-03-23 00:48:28+00:00 CREATEDON: 2017-03-23 00:48:28+00:00 UPDATEDBY: admin CREATEDBY: admin CONNECTIONNAME: test-conn CONNECTIONDESCRIPTION: Description of the connection properties: CONNECTIONNAME: description: Name of the Connection example: test-conn type: string CONNECTIONTYPE: description: Type of the Connection example: AD type: string CONNECTIONDESCRIPTION: description: Connection description example: Description of the connection type: string STATUS: description: Connection status example: 1 type: integer CREATEDBY: description: User who created the connection example: admin type: string CREATEDON: description: Connection creation time example: 2017-03-23 00:48:28+00:00 type: string UPDATEDBY: description: User who updated the connection example: admin type: string UPDATEDON: description: Time of connection updation example: 2017-03-23 00:48:28+00:00 type: string SalesforceConnectionAttributes: properties: isTimeoutSupported: example: true type: boolean CLIENT_SECRET: example: client_secret type: string OBJECT_TO_BE_IMPORTED: type: string FEATURE_LICENSE_JSON: type: string CREATEACCOUNTJSON: type: string REDIRECT_URI: example: https://example.com type: string REFRESH_TOKEN: example: refresh_token type: string connectionTimeoutConfig: $ref: '#/components/schemas/ConnectionTimeoutConfig' MODIFYACCOUNTJSON: type: string connectionType: example: MS_BASED_CONNECTOR type: string isTimeoutConfigValidated: example: true type: boolean CLIENT_ID: example: client_id type: string PAM_CONFIG: type: string CUSTOMCONFIGJSON: type: string FIELD_MAPPING_JSON: type: string STATUS_THRESHOLD_CONFIG: type: string ACCOUNT_FIELD_QUERY: type: string CUSTOM_CREATEACCOUNT_URL: type: string ACCOUNT_FILTER_QUERY: type: string INSTANCE_URL: example: https://example.salesforce.com type: string RESTConnectionAttributes: properties: UpdateUserJSON: description: Property for UpdateUserJSON type: string ChangePassJSON: type: string CreateEntitlementJSON: type: string UpdateEntitlementJSON: type: string DeleteEntitlementJSON: type: string ApplicationDiscoveryJSON: type: string RemoveAccountJSON: example: '{''call'': [{''name'': ''call1'', ''connection'': ''Slack'', ''url'': ''https://api.slack.com/scim/v1/Users/${account.accountID}'', ''httpMethod'': ''DELETE'', ''httpHeaders'': {''Authorization'': ''${access_token}''}, ''httpContentType'': ''application/json'', ''successResponses'': {''statusCode'': [200, 204, 201]}}]} ' type: string TicketStatusJSON: type: string CreateTicketJSON: type: string connectionType: description: Type of connection, e.g., MS_BASED_CONNECTOR. example: MS_BASED_CONNECTOR type: string ENDPOINTS_FILTER: type: string PasswdPolicyJSON: type: string ConfigJSON: description: We can use this attribute to define the provisioningLimit,showLogs and connectionTimeoutConfig. example: '{''connectionTimeoutConfig'': {''connectionTimeout'': 10, ''readTimeout'': 60, ''writeTimeout'': 60, ''retryCount'': 3, ''retryWait'': 2}} ' type: string AddFFIDAccessJSON: type: string RemoveFFIDAccessJSON: type: string STATUS_THRESHOLD_CONFIG: description: JSON configuration for account status thresholds. example: '{"statusAndThresholdConfig":{"statusColumn":"CUSTOMPROPERTY4","activeStatus":["n"],"deleteLinks":false,"accountThresholdValue":1000,"correlateInactiveAccounts":true,"inactivateAccountsNotInFile":false}}' type: string MODIFYUSERDATAJSON: type: string SendOtpJSON: type: string ValidateOtpJSON: type: string PAM_CONFIG: type: string connectionTimeoutConfig: $ref: '#/components/schemas/ConnectionTimeoutConfig' CreateAccountJSON: example: '{''accountIdPath'': ''call1.message.id'', ''dateFormat'': "yyyy-MM-dd''T''HH:mm:ssXXX", ''responseColsToPropsMap'': {''name'': ''call1.message.username~#~char'', ''displayName'': ''call1.message.displayName~#~char'', ''updatedate'': ''call1.message.meta.created~#~date'', ''comments'': ''call1.message.emails[0].value~#~char''}, ''call'': [{''name'': ''call1'', ''connection'': ''Slack'', ''url'': ''https://api.slack.com/scim/v1/Users'', ''httpMethod'': ''POST'', ''httpParams'': ''{"schemas":["urn:scim:schemas:core:1.0"],"userName": "${user.username}","nickName": "${user.firstname}", "name": {"givenName": "${user.firstname}","familyName": "${user.lastname}"},"active": false,"emails": [{"value": "${user.email}", "primary": true}]}'', ''httpHeaders'': {''Authorization'': ''${access_token}''}, ''httpContentType'': ''application/json'', ''successResponses'': {''statusCode'': [201]}, ''unsuccessResponses'': {''statusCode'': [400, 500]}}]} ' type: string UpdateAccountJSON: example: '{''call'': [{''name'': ''call1'', ''connection'': ''Slack'', ''url'': ''https://api.slack.com/scim/v1/Users/${account.accountID}'', ''httpMethod'': ''PATCH'', ''httpParams'': ''{"schemas":["urn:scim:schemas:core:1.0"],"active":false,"userName":"${user.username}","nickName":"${user.username}","name":{"givenName":"${user.firstname}","familyName":"${user.lastname}"},"displayName":"${user.displayname}","emails":[{"value":"${user.email}","primary":true}]}'', ''httpHeaders'': {''Authorization'': ''${access_token}''}, ''httpContentType'': ''application/json'', ''successResponses'': {''statusCode'': [200]}, ''unsuccessResponses'': {''statusCode'': [400, 500]}}]} ' type: string EnableAccountJSON: example: '{''call'': [{''name'': ''call1'', ''connection'': ''Slack'', ''url'': ''https://api.slack.com/scim/v1/Users/${account.accountID}'', ''httpMethod'': ''PATCH'', ''httpParams'': ''{"active" : true}'', ''httpHeaders'': {''Authorization'': ''${access_token}''}, ''httpContentType'': ''application/json'', ''successResponses'': {''statusCode'': [200]}, ''unsuccessResponses'': {''statusCode'': [400, 500]}}]} ' type: string DisableAccountJSON: example: '{''call'': [{''name'': ''call1'', ''connection'': ''Slack'', ''url'': ''https://api.slack.com/scim/v1/Users/${account.accountID}'', ''httpMethod'': ''PATCH'', ''httpParams'': ''{"active" : false}'', ''httpHeaders'': {''Authorization'': ''${access_token}''}, ''httpContentType'': ''application/json'', ''successResponses'': {''statusCode'': [200]}, ''unsuccessResponses'': {''statusCode'': [400, 500]}}]} ' type: string AddAccessJSON: example: '{''call'': [{''name'': ''Group'', ''connection'': ''Slack'', ''url'': ''https://api.slack.com/scim/v1/Groups/${entitlementValue.entitlementID}'', ''httpMethod'': ''PATCH'', ''httpParams'': ''{"schemas": ["urn:scim:schemas:core:1.0"],"members": [{"value": "${account.accountID}"}]}'', ''httpHeaders'': {''Authorization'': ''${access_token}'', ''Accept'': ''application/json''}, ''httpContentType'': ''application/json'', ''successResponses'': {''statusCode'': [204]}}, {''name'': ''Channels'', ''connection'': ''Slack'', ''url'': ''https://slack.com/api/conversations.invite?channel=${entitlementValue.entitlementID}&users=${account.accountID}'', ''httpMethod'': ''POST'', ''httpHeaders'': {''Authorization'': ''${access_token}'', ''Accept'': ''application/x-www-form-urlencoded''}, ''httpContentType'': ''application/x-www-form-urlencoded'', ''successResponses'': {''statusCode'': [200]}}]} ' type: string RemoveAccessJSON: example: '{''call'': [{''name'': ''Group'', ''connection'': ''Slack'', ''url'': ''https://api.slack.com/scim/v1/Groups/${entitlementValue.entitlementID}'', ''httpMethod'': ''PATCH'', ''httpParams'': ''{"schemas": ["urn:scim:schemas:core:1.0"],"members": [{"value": "${account.accountID}","operation": "delete"}]}'', ''httpHeaders'': {''Authorization'': ''${access_token}'', ''Accept'': ''application/json''}, ''httpContentType'': ''application/json'', ''successResponses'': {''statusCode'': [204]}}, {''name'': ''Channels'', ''connection'': ''Slack'', ''url'': ''https://slack.com/api/conversations.kick?channel=${entitlementValue.entitlementID}&user=${account.accountID}'', ''httpMethod'': ''POST'', ''httpHeaders'': {''Authorization'': ''${access_token}'', ''Accept'': ''application/x-www-form-urlencoded''}, ''httpContentType'': ''application/x-www-form-urlencoded'', ''successResponses'': {''statusCode'': [200]}}]} ' type: string ImportUserJSON: type: string isTimeoutSupported: type: boolean ImportAccountEntJSON: type: string isTimeoutConfigValidated: type: boolean ConnectionJSON: type: string AppType: description: For CUA configuration type: string GithubRESTConnector: allOf: - $ref: '#/components/schemas/BaseConnector' - properties: ConnectionJSON: description: Property for ConnectionJSON type: string ImportAccountEntJSON: description: Property for ImportAccountEntJSON type: string ACCESS_TOKENS: description: Property for ACCESS_TOKENS type: string ORGANIZATION_LIST: description: Property for ORGANIZATION_LIST type: string STATUS_THRESHOLD_CONFIG: description: Property for STATUS_THRESHOLD_CONFIG type: string PAM_CONFIG: description: Property for PAM_CONFIG type: string UNIXConnectionAttributes: properties: GROUPS_FILE: type: string SSH_KEY: type: string ACCOUNT_ENTITLEMENT_MAPPING_COMMAND: type: string REMOVE_ACCESS_COMMAND: type: string PEM_KEY_FILE: type: string PassThroughConnectionDetails: type: string DISABLE_ACCOUNT_COMMAND: type: string connectionTimeoutConfig: $ref: '#/components/schemas/ConnectionTimeoutConfig' PORT_NUMBER: type: string connectionType: example: MS_BASED_CONNECTOR type: string CREATE_GROUP_COMMAND: type: string ACCOUNTS_FILE: type: string PASSPHRASE: type: string DELETE_GROUP_COMMAND: type: string HOST_NAME: example: 255.255.255.255 type: string ADD_GROUP_OWNER_COMMAND: type: string STATUS_THRESHOLD_CONFIG: example: "{\n\t\"statusAndThresholdConfig\": {\n\t\t\"statusColumn\": \"status\",\n\t\t\"activeStatus\": [\"1\", \"active\"],\n\t\t\"deleteLinks\": true,\n\t\t\"accountThresholdValue\": 1000,\n\t\t\"correlateInactiveAccounts\": false,\n\t\t\"inactivateAccountsNotInFile\": false\n\t}\n}" type: string USERNAME: example: username type: string INACTIVE_LOCK_ACCOUNT: type: string ADD_ACCESS_COMMAND: example: sudo usermod -aG ${entitlement_Value} ${username} type: string UPDATE_ACCOUNT_COMMAND: type: string SSHPassThroughPassphrase: type: string SHADOW_FILE: type: string isTimeoutSupported: example: true type: boolean SSHPassThroughSSHKEY: type: string PROVISION_ACCOUNT_COMMAND: type: string FIREFIGHTERID_GRANT_ACCESS_COMMAND: type: string UNLOCK_ACCOUNT_COMMAND: type: string DEPROVISION_ACCOUNT_COMMAND: type: string CHANGE_PASSWRD_JSON: type: string SSHPassThroughPassword: type: string FIREFIGHTERID_REVOKE_ACCESS_COMMAND: type: string ADD_PRIMARY_GROUP_COMMAND: type: string isTimeoutConfigValidated: example: false type: boolean LOCK_ACCOUNT_COMMAND: type: string PASSWORD: example: pass123 type: string CUSTOM_CONFIG_JSON: type: string ENABLE_ACCOUNT_COMMAND: type: string SERVER_TYPE: type: string getConnectionDetails: properties: msg: description: API response message example: success type: string emailtemplate: description: Email template for the connection example: '' type: string updatedby: description: Updator account for the connection example: admin(adminfname adminlname) type: string connectionname: description: Name of the connection example: AD type: string connectionkey: description: Connection key example: 120 type: integer description: description: Description for the connection example: Workday type: string connectiontype: description: Connection type example: Workday-SOAP type: string createdon: description: Connection creation time example: 2020-03-12 11:49:15+00:00 type: string createdby: description: Creator account for the connection example: admin(null null) type: string errorcode: description: Error code example: 0 type: integer status: example: 1 type: integer defaultsavroles: example: '' type: string WorkdayConnectionAttributes: properties: USE_OAUTH: example: 'FALSE' type: string USER_IMPORT_MAPPING: type: string ACCOUNTS_LAST_IMPORT_TIME: example: 'null' type: string STATUS_KEY_JSON: type: string connectionTimeoutConfig: $ref: '#/components/schemas/ConnectionTimeoutConfig' connectionType: example: MS_BASED_CONNECTOR type: string RAAS_MAPPING_JSON: example: '{"reportUrlMapping":[{"accessType":"Account","url":"${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_Accounts?format=xml"},{"accessType":"Security Group","url":"${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_SecurityGroups?format=xml","mappingUrl":"${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_WorkersToSecurityGroups?format=xml","inc_url":"${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_SecurityGroupsWorkers?format=xml","enable_chunked_retrieval":0,"locationHierarchyUrl":"${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_LocationHierarchies","locationHierarchies":[],"countryReportUrl":"${BASE_URL}/ccx/service/systemreport2/${TENANT_NAME}/Country_Summary","countryCodes":[]},{"accessType":"Domain Security Policy","url":"${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_DomainSecurityPermissions?format=xml","inc_url":"${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_Domains?format=xml&Include_Changes_to_Security_Groups=0"},{"accessType":"Business Process Security Policy","url":"${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_BusinessProcessPermissions?format=xml","inc_url":"${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_BusinessProcesses?format=xml&Include_Changes_to_Security_Groups=0"},{"accessType":"Business Process Definitions","url":"${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_BusinessProcessDefinitions?format=xml"},{"accessType":"Organizational Role","url":"${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_OrgRolesWorkers?format=xml","enhancedUrl":"${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_RoleSecurityGroups?format=xml"},{"accessType":"Tasks And Reports","url":"${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_ReportsTasksGetPut?Include_Inactive=0,${BASE_URL}/ccx/service/customreport2/${TENANT_NAME}/${REPORT_OWNER}/SAV_ReportsTasksViewModify?Include_Inactive=0"},{"accessType":"Organization"}],"auditReportUrlMapping":[{"reportName":"userActivity","url":"${BASE_URL}/ccx/service/systemreport2/${TENANT_NAME}/View_User_Activity?format=xml","importDateStep":"6","indexName":"audit","auditDateStart":"${CURRENT_TIMESTAMP_MINUS_24HRS}","ImportMapping":{"fileCreateTime":"wd:Request_Time","sourceTranslatedAddress":"wd:IP_Address","requestClientApplication":"wd:User_Agent","suser":"wd:System_Account.wd:Descriptor","filePath":"wd:Task","filePermission":"wd:Activity_Category","duser":"wd:Target.wd:Descriptor","duid":"wd:Target.wd:ID[1].wd:type"}}]}' type: string ACCOUNT_IMPORT_PAYLOAD: example: svc:Get_Workers_Request bsvc:version="${API_VERSION}">falsefalse type: string UPDATE_ACCOUNT_PAYLOAD: example: truetrue${user.customproperty1}${CURRENT_PROV_TIMESTAMP}${user.email}WORK type: string CLIENT_ID: type: string STATUS_THRESHOLD_CONFIG: example: '{"statusAndThresholdConfig":{"statusColumn":"customproperty30","deleteLinks":false,"accountThresholdValue":1000,"correlateInactiveAccounts":false,"inactivateAccountsNotInFile":false}}' type: string USERNAME: example: username type: string ACCESS_IMPORT_LIST: example: Security Group,Domain Security Policy type: string isTimeoutSupported: example: true type: boolean ACCOUNT_IMPORT_MAPPING: example: '"ImportType":"SOAP","ResponsePath":"Body.Get_Workers_Response.Response_Data.Worker","ImportMapping":{"NAME":"Worker_Data.User_ID","ACCOUNTID":"Worker_Reference.ID(@wd:type==''WID'')","CUSTOMPROPERTY30":"Worker_Data.Employment_Data.Worker_Status_Data.Active","CUSTOMPROPERTY1":"Worker_Data.Personal_Data.Identification_Data.Custom_ID.Custom_ID_Data(ID_Type_Reference->ID==''CustomID_NTID'').ID","CUSTOMPROPERTY2":"Worker_Data.Personal_Data.Identification_Data.Custom_ID.Custom_ID_Data(ID_Type_Reference - > ID == ''CustomID_GPID'').ID","CUSTOMPROPERTY3":"Worker_Data.Personal_Data.Identification_Data.Custom_ID.Custom_ID_Data(ID_Type_Reference - > ID == ''CustomID_UPN'').ID","CUSTOMPROPERTY4":"Worker_Data.Personal_Data.Contact_Data.Email_Address_Data(Usage_Data - > Type_Data - > Type_Reference - > ID == ''WORK'').Email_Address","CUSTOMPROPERTY5":"Worker_Data.Personal_Data.Name_Data.Legal_Name_Data.Name_Detail_Data.First_Name","CUSTOMPROPERTY6":"Worker_Data.Personal_Data.Name_Data.Legal_Name_Data.Name_Detail_Data.Last_Name","CUSTOMPROPERTY7":"Worker_Data.Personal_Data.Name_Data.Legal_Name_Data.Name_Detail_Data.Country_Reference.ID(@type == ''ISO_3166-1_Alpha-3_Code'')","CUSTOMPROPERTY9":"Worker_Data.Role_Data.Organization_Role_Data.Organization_Role.Organization_Role_Reference.ID(@type == ''Organization_Role_ID'')","CUSTOMPROPERTY11":"Worker_Data.Worker_ID","CUSTOMPROPERTY12":"Worker_Data.Personal_Data.Identification_Data.Custom_ID(Custom_ID_Data - > ID_Type_Reference - > ID == ''CustomID_GPID'').Custom_ID_Shared_Reference.ID(@type == ''Custom_Identifier_Reference_ID'')","CUSTOMPROPERTY13":"Worker_Data.Personal_Data.Identification_Data.Custom_ID(Custom_ID_Data - > ID_Type_Reference - > ID == ''CustomID_UPN'').Custom_ID_Shared_Reference.ID(@type == ''Custom_Identifier_Reference_ID'')"}}' type: string CLIENT_SECRET: example: secret type: string ORGROLE_IMPORT_PAYLOAD: example: bsvc:Get_Organizations_Request bsvc:version="${API_VERSION}">1${INCREMENTAL_IMPORT_CRITERIA}${PAGE_NUMBER}${PAGE_SIZE}1000 type: string ASSIGN_ORGROLE_PAYLOAD: example: type: string ACCESS_IMPORT_MAPPING: example: '{"Security Group":{"ImportMapping":{"displayname":"wd:Security_Group.wd:Descriptor~#~char","description":"wd:Comment~#~char"}},"Domain Security Policy":{"ImportMapping":{}},"Business Process Security Policy":{"ImportMapping":{}},"Business Process Definitions":{"ImportMapping":{}},"Organizational Role":{"ImportMapping":{}},"Organization":{"ImportMapping":{}},"Tasks And Reports":{"ImportMapping":{}}}' type: string API_VERSION: example: v0.1 type: string REMOVE_ORGROLE_PAYLOAD: example: 1${user.customproperty1}0${Organization_Reference_ID}${entitlementID}01${user.customproperty1}0 type: string INCLUDE_REFERENCE_DESCRIPTORS: type: string REFRESH_TOKEN: type: string MODIFYUSERDATAJSON: type: string isTimeoutConfigValidated: example: true type: boolean USE_X509AUTH_FOR_SOAP: example: 'FALSE' type: string REPORT_OWNER: type: string X509_KEY: type: string CUSTOM_CONFIG: type: string USERATTRIBUTEJSON: type: string X509_CERT: type: string PASSWORD: example: password123 type: string USER_IMPORT_PAYLOAD: type: string PAM_CONFIG: type: string ACCESS_LAST_IMPORT_TIME: example: '{"Organization":{"From":"2024-01-22T21:49:02.674-08:00"},"Security Group":{"Created_Moment":"2024-01-22T21:49:02.674-08:00","Last_Updated":"2024-01-22T21:49:02.674-08:00"},"Domain Security Policy":{"From":"2024-01-22T21:49:02.674-08:00"},"Tasks And Reports":{"Created_Moment":"2024-01-22T21:49:02.674-08:00","Last_Updated":"2024-01-22T21:49:02.674-08:00"},"Business Process Security Policy":{"From":"2024-01-22T21:49:02.674-08:00"},"Organizational Role":{"Created_Moment":"2024-01-22T21:49:02.674-08:00","Last_Updated":"2024-01-22T21:49:02.674-08:00"}}' type: string USERS_LAST_IMPORT_TIME: example: 2025-01-13 03:14:28.530000-08:00 type: string UPDATE_USER_PAYLOAD: type: string PAGE_SIZE: example: '1000' type: string TENANT_NAME: example: tenant type: string USE_ENHANCED_ORGROLE: example: 'FALSE' type: string CREATE_ACCOUNT_PAYLOAD: example: ${accountName}${password} type: string BASE_URL: example: www.example.workday.com type: string SAPConnector: allOf: - $ref: '#/components/schemas/BaseConnector' - properties: MESSAGESERVER: description: set it to TRUE if the Message Server is going to be used for connecting to SAP example: 'FALSE' type: string JCO_ASHOST: description: HostName for connection for Import example: '@TMP_JCO_ASHOST@' type: string JCO_SYSNR: description: System Number for the SAP Instance for Import example: '@TMP_JCO_SYSNR@' type: string JCO_CLIENT: description: Client Number for the SAP Instance for Import example: '@TMP_JCO_CLIENT@' type: string JCO_USER: description: Username to connect to SAP using JCO for Import example: '@TMP_JCO_USER@' type: string PASSWORD: description: Password for connection for Import example: password type: string JCO_LANG: description: LANGUAGE for the SAP Instance for Import example: en type: string JCO_R3NAME: description: Message Server SystemID for connection for Import type: string JCO_MSHOST: description: Message Server Hostname for connection for Import type: string JCO_MSSERV: description: Message Server Port Number for connection for Import type: string JCO_GROUP: description: Message Server logon Group connection for Import type: string SNC: description: TRUE/FALSE, set it to TRUE if Secure Network Connection (SNC) is setup between ABAP and ASHOST example: 'FALSE' type: string JCO_SNC_MODE: description: Enable/Disable Secure Network Connection (SNC) Mode. 0 - Disabled, 1 - Enabled example: '0' type: string JCO_SNC_PARTNERNAME: description: String used to generate secured certificate in SAP server to be used by Saviynt example: p:CN=EC6,OU=eccu1237zx,OU=SAPAS,O=SAP,C=DE type: string JCO_SNC_MYNAME: description: String used to generate the secured certificate on the server where Saviynt is deployed example: p:CN=SAVIYNT,OU=IT,O=CSW,C=DE type: string JCO_SNC_LIBRARY: description: Location of SNC library on the Saviynt server type: string JCO_SNC_QOP: description: The Quality of Protection Level example: '1' type: string TABLES: description: Tables to be Imported example: USR02, USR04, USER_ADDR, USRACL, USR06, TSTC, TSTCT, AGR_AGRS, AGR_TEXTS, AGR_DEFINE, AGR_USERS, USORG, AGR_1252, AGR_1251 type: string SYSTEMNAME: type: string TERMINATEDUSERGROUP: description: User group for all terminated users type: string TERMINATED_USER_ROLE_ACTION: description: Action to take for the user roles when the user gets terminated or roles are removed example: DELETEACCOUNT type: string CREATEACCOUNTJSON: description: JSON to specify the Field Value which will be used to Create the New Account,Objects example: '{''ADDRESS'': {''LASTNAME'': ''${user.lastname}'', ''FIRSTNAME'': ''${user.firstname}'', ''E_MAIL'': ''${user.email}''}, ''DEFAULTS'': {''DCPFM'': ''X'', ''DATFM'': ''2'', ''SPDA'': ''D''}, ''SNC'': {''GUIFLAG'': ''U'', ''PNAME'': ''p:${accountName}@CORP.INT''}, ''LOGONDATA'': {''USTYP'': ''A'', ''GLTGB'': ''99991231''}, ''PASSWORD'': {''BAPIPWD'': ''${randomPassword}''}} ' type: string PROV_JCO_ASHOST: description: HostName for connection for Provisioning example: '@TMP_JCO_ASHOST@' type: string PROV_JCO_SYSNR: description: System Number for the SAP Instance for Provisioning example: '@TMP_JCO_SYSNR@' type: string PROV_JCO_CLIENT: description: Client Number for the SAP Instance for Provisioning example: '@TMP_JCO_CLIENT@' type: string PROV_JCO_USER: description: Username to connect to to SAP using JCO for Provisioning example: '@TMP_JCO_USER@' type: string PROV_PASSWORD: description: Password for connection for Provisioning example: password type: string PROV_JCO_LANG: description: LANGUAGE for the SAP Instance for Provisioning example: '@TMP_JCO_LANG@' type: string PROV_JCO_R3NAME: description: Message Server SystemID for connection for Provisioning type: string PROV_JCO_MSHOST: description: Message Server Hostname for connection for Provisioning type: string PROV_JCO_MSSERV: description: Message Server Port Number for connection for Provisioning type: string PROV_JCO_GROUP: description: Message Server logon Group connection for Provisioning type: string PROV_CUA_ENABLED: description: Is CUA Enabled example: 'FALSE' type: string PROV_CUA_SNC: description: Property for PROV_CUA_SNC type: string RESET_PWD_FOR_NEWACCOUNT: description: For CUA enabled if the user already exists should the Password be reset for accounts for other systems example: 'FALSE' type: string ENFORCEPASSWORDCHANGE: description: Set it to FALSE if while changing the password the productive password should be set example: 'TRUE' type: string PASSWORD_MIN_LENGTH: description: Specify the Min length for the random password example: '8' type: string PASSWORD_MAX_LENGTH: description: Specify the Max length for the random password example: '16' type: string PASSWORD_NOOFCAPSALPHA: description: Specify the Number of Upper case alphabets required for the random password example: '1' type: string PASSWORD_NOOFDIGITS: description: "Specify the Number of digits required for the random password\t" example: '1' type: string PASSWORD_NOOFSPLCHARS: description: Specify the Number of special chars required for the random password example: '1' type: string HANAREFTABLEJSON: description: JSON to specify the mapping for Reference table example: '{OBJMAPPING:[{OBJNAME:*,FIELDNAME:ABC},{OBJNAME:XYS,FIELDNAME:*}{OBJNAME:*,FIELDNAME:*}],HANACONNECTIONNAME:HANAC1,HANAREFTABLENAME:REFTABLE1} ' type: string ENABLEACCOUNTJSON: description: JSON Similar to Create Account to mention the changes that needs to be made at the user level after enabling the account example: '{''LOGONDATA'': {''GLTGV'': "${new java.text.SimpleDateFormat(''yyyyMMdd'').format(user.startdate)}", ''GLTGB'': "${user.enddate==null?''99991231'': new java.text.SimpleDateFormat(''yyyyMMdd'').format(user.enddate)}"}} ' type: string UPDATEACCOUNTJSON: description: JSON Similar to Create Account to mention the changes that needs to be made at the user level after updating the account example: '{''ADDRESS'': {''FIRSTNAME'': ''${user.firstname}'', ''LASTNAME'': ''${user.lastname}''}, ''LOGONDATA'': {''CLASS'': ''TEST''}, ''DEFAULTS'': {''LANGU'': ''EN'', ''TIMEFM'': ''0'', ''DATFM'': ''1'', ''SPLD'': ''LOCL''}} ' type: string USERIMPORTJSON: description: Property for USERIMPORTJSON type: string STATUS_THRESHOLD_CONFIG: description: The attributes of statusAndThresholdConfig json example: '{''statusAndThresholdConfig'': {''statusColumn'': ''userlock'', ''activeStatus'': [''0'', ''128''], ''deleteLinks'': True, ''accountThresholdValue'': 1000, ''correlateInactiveAccounts'': True, ''inactivateAccountsNotInFile'': False, ''deleteAccEntForActiveAccounts'': False, ''lockedStatusColumn'': ''userlock'', ''lockedStatusMapping'': {''Locked'': [''32'', ''64''], ''Unlocked'': [''0'', ''128'']}}} ' type: string SETCUASYSTEM: description: set it to FALSE if using an older CUA System to not support setting sub-systems example: 'FALSE' type: string FIREFIGHTERID_GRANT_ACCESS_JSON: description: "JSON similar to Update Account to mention SNC and other related changes that needs to be done\t" example: '{''SNC'': {''PNAME'': ''p:CN=${user?.systemUserName?.toUpperCase()}@CORP.DEMB.COM''}} ' type: string FIREFIGHTERID_REVOKE_ACCESS_JSON: description: JSON similar to Update Account to reset SNC and other related changes that were done during GRANT example: '{''SNC'': {''PNAME'': ''''}} ' type: string MODIFYUSERDATAJSON: description: Property for MODIFYUSERDATAJSON type: string EXTERNAL_SOD_EVAL_JSON: description: JSON to populate values for External SOD Evaluation example: '{''GRAC_IDM_RISK_WOUT_NO_SERVICES'': {''ROLE_TYPE'': '''', ''USER_GROUP'': '''', ''OBJECT_TYPE'': ''USR'', ''ORG_LEVEL'': '''', ''BUSINESS_PROC'': '''', ''REPORT_TYPE'': ''2'', ''RULE_ID'': '''', ''RISK_LEVEL'': '''', ''RULE_SET_ID'': ''GLOBAL'', ''REPORT_FORMAT'': ''4'', ''USER_TYPE'': '''', ''SIMULATION_RISK_ONLY'': '''', ''APPLICATION_TYPE'': ''SAP'', ''HIT_COUNT'': ''30000'', ''LANGUAGE'': ''EN'', ''ADDL_ATTRIB'': [''03'']}} ' type: string EXTERNAL_SOD_EVAL_JSON_DETAIL: description: Property for EXTERNAL_SOD_EVAL_JSON_DETAIL type: string LOGS_TABLE_FILTER: description: Property for LOGS_TABLE_FILTER type: string PAM_CONFIG: description: "JSON for PAM Bootstrap Configuration\t" example: '{''Connection'': ''SAP'', ''encryptionMechanism'': ''ENCRYPTED'', ''CONSOLE'': {''maxCredSessionRequestTime'': ''36000'', ''maxCredlessSessionRequestTime'': ''36000'', ''maxIDRequestableTime'': ''2592000'', ''shareableAccounts'': {''IDQueryCredentials'': "acc.name in (''cpamuser1'')", ''IDQueryCredentialless'': "acc.name in (''cpamuser2'', ''cpamuser3'')"}, ''endpointAttributeMappings'': [{''column'': ''accessquery'', ''value'': ''where users.USERNAME is not null'', ''feature'': ''endpointAccessQuery''}, {''column'': ''customproperty43'', ''value'': ''PAMDefaultUserAccountAccessControl'', ''feature'': ''accountVisibilityControl''}], ''endpointPamConfig'': {''maxConcurrentSession'': ''50''}, ''accountVisibilityConfig'': {''accountCustomProperty'': ''customproperty55'', ''accountMappingConfig'': [{''accountPattern'': ''cpamuser*'', ''mappingData'': ''roletest1'', ''override'': ''false''}, {''accountPattern'': ''cpamuser1,cpamuser2'', ''mappingData'': ''roletest2'', ''override'': ''false''}]}}} ' type: string SAPTABLE_FILTER_LANG: description: Property for SAPTABLE_FILTER_LANG type: string ALTERNATE_OUTPUT_PARAMETER_ET_DATA: description: Based on the flag ''USE_ET_DATA_4_RETURN'' in SAP, set this value to make use of export parameter ET_DATA example: 'FALSE' type: string AUDIT_LOG_JSON: description: Property for AUDIT_LOG_JSON type: string ECC_OR_S4HANA: description: Property for ECC_OR_S4HANA type: string DATA_IMPORT_FILTER: description: Property for DATA_IMPORT_FILTER type: string ConfigJSON: description: Property for ConfigJSON type: string ROLE_DEFAULT_DATE: description: 'Default end date for SAP roles. Format: yyyyMMdd (e.g., 20251231). If not configured, defaults to 99991231.' type: string UNIXConnector: allOf: - $ref: '#/components/schemas/BaseConnector' - properties: HOST_NAME: description: Property for HOST_NAME type: string PORT_NUMBER: description: Property for PORT_NUMBER type: string USERNAME: description: Property for USERNAME type: string PASSWORD: description: Property for PASSWORD type: string GROUPS_FILE: description: Property for GROUPS_FILE type: string ACCOUNTS_FILE: description: Property for ACCOUNTS_FILE type: string SHADOW_FILE: description: Property for SHADOW_FILE type: string PROVISION_ACCOUNT_COMMAND: description: Property for PROVISION_ACCOUNT_COMMAND type: string DEPROVISION_ACCOUNT_COMMAND: description: Property for DEPROVISION_ACCOUNT_COMMAND type: string ADD_ACCESS_COMMAND: description: Property for ADD_ACCESS_COMMAND type: string REMOVE_ACCESS_COMMAND: description: Property for REMOVE_ACCESS_COMMAND type: string CHANGE_PASSWRD_JSON: description: Property for CHANGE_PASSWRD_JSON type: string PEM_KEY_FILE: description: Property for PEM_KEY_FILE type: string ENABLE_ACCOUNT_COMMAND: description: Property for ENABLE_ACCOUNT_COMMAND type: string DISABLE_ACCOUNT_COMMAND: description: Property for DISABLE_ACCOUNT_COMMAND type: string ACCOUNT_ENTITLEMENT_MAPPING_COMMAND: description: Property for ACCOUNT_ENTITLEMENT_MAPPING_COMMAND type: string PASSPHRASE: description: Property for PASSPHRASE type: string UPDATE_ACCOUNT_COMMAND: description: Property for UPDATE_ACCOUNT_COMMAND type: string CREATE_GROUP_COMMAND: description: Property for CREATE_GROUP_COMMAND type: string DELETE_GROUP_COMMAND: description: Property for DELETE_GROUP_COMMAND type: string ADD_GROUP_OWNER_COMMAND: description: Property for ADD_GROUP_OWNER_COMMAND type: string ADD_PRIMARY_GROUP_COMMAND: description: Property for ADD_PRIMARY_GROUP_COMMAND type: string FIREFIGHTERID_GRANT_ACCESS_COMMAND: description: Property for FIREFIGHTERID_GRANT_ACCESS_COMMAND type: string FIREFIGHTERID_REVOKE_ACCESS_COMMAND: description: Property for FIREFIGHTERID_REVOKE_ACCESS_COMMAND type: string INACTIVE_LOCK_ACCOUNT: description: Property for INACTIVE_LOCK_ACCOUNT type: string STATUS_THRESHOLD_CONFIG: description: Property for STATUS_THRESHOLD_CONFIG type: string CUSTOM_CONFIG_JSON: description: Property for CUSTOM_CONFIG_JSON type: string SSH_KEY: description: Property for SSH_KEY type: string LOCK_ACCOUNT_COMMAND: description: Property for LOCK_ACCOUNT_COMMAND type: string UNLOCK_ACCOUNT_COMMAND: description: Property for UNLOCK_ACCOUNT_COMMAND type: string PassThroughConnectionDetails: description: Property for PassThroughConnectionDetails type: string SSHPassThroughPassword: description: Property for SSHPassThroughPassword type: string SSHPassThroughSSHKEY: description: Property for SSHPassThroughSSHKEY type: string SSHPassThroughPassphrase: description: Property for SSHPassThroughPassphrase type: string SERVER_TYPE: type: string required: - HOST_NAME - PORT_NUMBER - USERNAME BaseConnector: discriminator: mapping: AD: '#/components/schemas/ADConnector' ADSI: '#/components/schemas/ADSIConnector' propertyName: connectiontype properties: connectionName: description: Name of the connection example: Active Directory_Doc type: string connectiontype: description: Connection type (e.g., 'AD' for Active Directory). example: AD type: string connectionDescription: description: Description for the connection. example: ORG_AD type: string defaultSavRole: description: Default SAV roles for managing the connection. example: ROLE_ORG type: string emailTemplate: description: Email template for notifications. example: New Account Task Creation type: string sslCertificate: description: SSL certificates to secure the connection. example: '-----BEGIN CERTIFICATE----- ... -----END CERTIFICATE-----' type: string vaultConnection: description: Specifies the type of vault connection being used (e.g., Hashicorp, AWS Secrets Manager). example: Hashicorp type: string vaultConfiguration: description: JSON string specifying vault configuration example: '{"path":"/secrets/data/kv-dev-intgn1/-AD_Credential","keyMapping":{"PASSWORD":"AD_PASSWORD~#~None"}}' type: string saveinvault: description: Flag indicating whether the encrypted attribute should be saved in the configured vault. example: false type: string required: - connectionName - connectiontype ADConnector: allOf: - $ref: '#/components/schemas/BaseConnector' - properties: URL: description: LDAP or target system URL. example: ldap://uscentral.com:8972/ type: string USERNAME: description: LDAP or system admin username. type: string example: null PASSWORD: description: Set the Password type: string example: null LDAP_OR_AD: description: Type of Endpoint - LDAP or AD, default value is AD example: AD type: string ENTITLEMENT_ATTRIBUTE: description: Attribute used for entitlements. example: memberOf type: string CHECKFORUNIQUE: description: Attribute uniqueness validation rule. example: '{"sAMAccountName":"${task.accountName}"}' type: string groupSearchBaseDN: description: Base DN for group search in LDAP. example: CN=Users,DC=Saviynt,DC=ABC,DC=Com type: string createUpdateMappings: description: Mapping used during group creation and updation. example: '{"cn":"${role?.customproperty27}","objectCategory":"CN=Group,CN=Schema,CN=Configuration,@DOMCONTRDN@","displayName":"${role?.displayname}","SamAccountName":"${role?.customproperty27}","description":"${role?.description}","objectClass":"group","name":"${role?.customproperty27}"}' type: string INCREMENTAL_CONFIG: description: Configuration for Incremental Import if the Incremental import is based on ChangeNumber. type: string MAX_CHANGENUMBER: description: Maximum value of the changeNumber. example: '4' type: string READ_OPERATIONAL_ATTRIBUTES: description: Read operational attributes from LDAP. example: 'FALSE' type: string BASE: description: LDAP base DN. example: CN=Users,DC=Saviynt,DC=ABC,DC=Com type: string DC_LOCATOR: description: Windows connector connection name to connect and get domain controller data. type: string STATUS_THRESHOLD_CONFIG: description: JSON configuration for account status thresholds. example: '{"statusAndThresholdConfig":{"statusColumn":"CUSTOMPROPERTY4","activeStatus":["n"],"deleteLinks":false,"accountThresholdValue":1000,"correlateInactiveAccounts":true,"inactivateAccountsNotInFile":false}}' type: string REMOVEACCOUNTACTION: description: Action performed on account removal. example: '{"removeAction":"DELETE"}' type: string ACCOUNT_ATTRIBUTE: description: Map LDAP user attribute to EIC account attribute for import example: '["ACCOUNTID::objectGUID#Binary","NAME::sAMAccountName#String","ACCOUNTCLASS::objectClass#String","DISPLAYNAME::name#String","DESCRIPTION::description#String","LASTLOGONDATE::lastLogon#millisec","VALIDTHROUGH::accountExpires#millisec","COMMENTS::distinguishedName#String","UPDATEDATE::whenChanged#date","LASTPASSWORDCHANGE::pwdLastSet#millisec","CREATED_ON::whenCreated#date","CUSTOMPROPERTY1::cn#String","CUSTOMPROPERTY2::userPrincipalName#String","CUSTOMPROPERTY3::sn#String","CUSTOMPROPERTY4::homeDirectory#String","CUSTOMPROPERTY5::co#String","CUSTOMPROPERTY6::employeeNumber#String","CUSTOMPROPERTY7::givenName#String","CUSTOMPROPERTY8::title#String","CUSTOMPROPERTY9::telephoneNumber#String","CUSTOMPROPERTY10::c#String","CUSTOMPROPERTY11::uSNCreated#String","CUSTOMPROPERTY12::logonCount#String","CUSTOMPROPERTY13::physicalDeliveryOfficeName#String","CUSTOMPROPERTY30::userAccountControl#String","CUSTOMPROPERTY28::primaryGroupID#String","CUSTOMPROPERTY25::company#String","CUSTOMPROPERTY16::streetAddress#String","CUSTOMPROPERTY18::department#String","CUSTOMPROPERTY19::countryCode#String","CUSTOMPROPERTY21::manager#String","CUSTOMPROPERTY22::homePhone#String","CUSTOMPROPERTY23::mobile#String","CUSTOMPROPERTY24::userAccountControl#String","CUSTOMPROPERTY27::objectSid#Binary","CUSTOMPROPERTY26::objectGUID#Binary","RECONCILATION_FIELD::CUSTOMPROPERTY26"]' type: string ACCOUNTNAMERULE: description: Rule to generate account name. example: uid=${task.accountName.toString().toLowerCase()},ou=People,dc=racf,dc=com type: string ADVSEARCH: type: string SETDEFAULTPAGESIZE: description: Set default page size for LDAP queries. example: 'FALSE' type: string RESETANDCHANGEPASSWRDJSON: description: JSON actions for password reset/change. example: '{"RESET":{"pwdLastSet":"0","title":"password reset"},"CHANGE":{"pwdLastSet":"-1","title":"password changed"}}' type: string REUSEINACTIVEACCOUNT: description: Reuse inactive accounts setting. example: 'TRUE' type: string IMPORTJSON: description: JSON import configurations. example: '{"envproperties":{"com.sun.jndi.ldap.connect.timeout":"10000","com.sun.jndi.ldap.read.timeout":"50000"}}' type: string SUPPORTEMPTYSTRING: description: Set to TRUE to send an empty value or null string during provisioning. example: 'FALSE' type: string ENABLEACCOUNTJSON: description: JSON configuration to enable account actions. example: '{"USEDNFROMACCOUNT":"NO","DISABLEACCOUNTCHECKRULE":["CN=${user.username},OU=DisabledUsers,OU=TestUsers,dc=test,dc=com"],"ATTRIBUTESTOCHECK":{"sAMAccountName":"${user.username}","sn":"${user.lastname}","givenName":"${user.firstname}"},"MOVEDN":"YES","ENABLEACCOUNTOU":"OU=ActiveUsers,OU=TestUsers,dc=test,dc=com","AFTERMOVEACTIONS":{"userAccountControl":"512"},"REMOVEGROUPS":"YES","RESETPASSWORD":"YES"}' type: string PAGE_SIZE: description: LDAP pagination page size. example: '1000' type: string USER_ATTRIBUTE: description: Map LDAP user attribute to EIC user attribute for import. example: '["USERNAME::sAMAccountName#String","systemUserName::sAMAccountName#String","DISPLAYNAME::displayName#String","LASTNAME::sn#String","FIRSTNAME::givenName#String","statuskey::userAccountControl#String","ENDDATE::accountExpires#millisec","UPDATEDATE::whenChanged#customDate--yyyyMMddHHmmss.''0Z''","CREATEDATE::whenCreated#customDate--yyyyMMddHHmmss.''0Z''","CUSTOMPROPERTY1::cn#String","CUSTOMPROPERTY25::company#String","CUSTOMPROPERTY40::distinguishedName#String","CUSTOMPROPERTY5::co#String","CUSTOMPROPERTY8::title#String","CUSTOMPROPERTY9::telephoneNumber#String","CUSTOMPROPERTY10::c#String","CUSTOMPROPERTY12::logonCount#String","CUSTOMPROPERTY13::physicalDeliveryOfficeName#String","CUSTOMPROPERTY16::streetAddress#String","CUSTOMPROPERTY17::mailNickname#String","CUSTOMPROPERTY18::department#String","CUSTOMPROPERTY19::countryCode#String","CUSTOMPROPERTY20::userPrincipalName#String","CUSTOMPROPERTY21::manager#String","CUSTOMPROPERTY22::homePhone#String","CUSTOMPROPERTY23::mobile#String","CUSTOMPROPERTY26::objectGUID#Binary","RECONCILATION_FIELD::CUSTOMPROPERTY26"]' type: string DEFAULT_USER_ROLE: description: Default SAV Role to be assigned to all the new users that gets imported via User Import example: ROLE_TASK_ADMIN type: string SEARCHFILTER: description: LDAP search filter. example: OU=Users,DC=domainname,DC=com type: string ENDPOINTS_FILTER: description: Provide the configuration to create Child Endpoints and import associated accounts and entitlements type: string CREATEACCOUNTJSON: description: To create an account, specify the value of the CREATEACCOUNTJSON parameter. example: '{"cn":"${cn}","displayname":"${user.displayname}","givenname":"${user.firstname}","mail":"${user.email}","name":"${user.displayname}","objectClass":["top","person","organizationalPerson","user"],"userAccountControl":"544","sAMAccountName":"${task.accountName}","sn":"${user.lastname}","title":"${user.title}"}' type: string UPDATEACCOUNTJSON: description: To update an existing account, specify the value of the UPDATEACCOUNTJSON parameter. example: '{"uid":"${task.accountName.toString().toLowerCase()}","cn":"${task.accountName.toString().toLowerCase()}","sn":"${user.lastname}","givenName":"${user.firstname}","objectClass":["inetOrgPerson"],"description":"AS 400 Integration with Saviynt"}' type: string REUSEACCOUNTJSON: description: To retain the suspended user accounts, specify the value of the REUSEACCOUNTJSON parameter. This is a mandatory attribute. example: '{"ATTRIBUTESTOCHECK":{"userAccountControl":"514","sn":"${user.lastname}","cn":"${user.fistname}"},"REUSEACCOUNTOU":"OU=ActiveUsers,DC=domainname,DC=com"}' type: string ENFORCE_TREE_DELETION: description: Enforce tree deletion in LDAP. example: 'TRUE' type: string ADVANCE_FILTER_JSON: type: string FILTER: description: Filters the objects that will be returned. type: string OBJECTFILTER: description: LDAP object filter. example: (objectClass=inetorgperson) type: string UPDATEUSERJSON: description: To update an existing user, specify the value of the UPDATEUSERJSON parameter. example: '{"mail":"${user.email}","sn":"${user.lastname}","givenName":"${user.firstname}"}' type: string saveconnection: description: Flag to save connection permanently. example: N type: string systemname: description: Associated system name. example: Dummyapplication type: string SETRANDOMPASSWORD: description: Set random password option. type: string example: null PASSWORD_MIN_LENGTH: description: Minimum password length. example: '8' type: string PASSWORD_MAX_LENGTH: description: Maximum password length. example: '12' type: string PASSWORD_NOOFCAPSALPHA: description: Specify the number of special characters required for the random password. example: '2' type: string PASSWORD_NOOFSPLCHARS: description: Number of special characters in password. example: '1' type: string PASSWORD_NOOFDIGITS: description: Specify the Number of digits required for the random password. example: '5' type: string groupImportMapping: description: Map LDAP group attribute to EIC entitlement attribute for import example: '{"entitlementTypeName":"memberOf","performGroupAccountLinking":"true","importnestedmembershipoutofscope":"true","incrementalTimeField":"whenChanged","groupObjectClass":"(objectclass=group)","mapping":"memberHash:member_char,customproperty1:sAMAccountType_char,customproperty16:memberOf_char,customproperty2:instanceType_char,customproperty3:uSNCreated_char,customproperty4:groupType_char,customproperty5:dSCorePropagationData_char,customproperty12:dn_char,customproperty13:cn_char,lastscandate:whenCreated_date,customproperty15:managedBy_char,entitlement_glossary:description_char,customproperty9:name_char,customproperty10:objectCategory_char,customproperty11:sAMAccountName_char,customproperty14:objectClass_char,status:isCriticalSystemObject_char,entitlement_value:distinguishedName_char,entitlement_id:distinguishedName_char,customproperty17:distinguishedName_char,updatedate:whenChanged_date,RECONCILATION_FIELD:customproperty17"}' type: string UNLOCKACCOUNTJSON: description: JSON configuration to unlock accounts. example: '{"lockoutTime":"0"}' type: string STATUSKEYJSON: description: JSON configuration for account statuses. example: '{"STATUS_ACTIVE":["512","544"],"STATUS_INACTIVE":["514","546"]}' type: string ENABLEGROUPMANAGEMENT: description: Specify TRUE to enable Group Management for AD. example: 'TRUE' type: string DISABLEACCOUNTJSON: description: JSON to specify the different attributes to be checked and action to be performed for disabling an active account. example: '{"userAccountControl":"546","deleteAllGroups":"No"}' type: string MODIFYUSERDATAJSON: description: Specify this parameter to use the inline processor for transforming the data during user import. type: string ORG_BASE: description: Organization BASE for provision job. type: string ORGANIZATION_ATTRIBUTE: description: Organization Attributes. type: string ORGIMPORTJSON: type: string CREATEORGJSON: description: JSON to specify different attributes for Organization Create Provisioning Job. type: string UPDATEORGJSON: description: JSON to specify different attributes for Organization Update Provisioning Job. type: string ConfigJSON: description: We can use this attribute to define the connectionTimeoutConfig. example: '{"connectionTimeoutConfig":{"connectionTimeout":10,"readTimeout":50,"retryWait":2,"retryCount":3}}' type: string LAST_IMPORT_TIME: type: string PAM_CONFIG: description: JSON to specify Bootstrap Config. example: '{"Connection":"AD","encryptionMechanism":"ENCRYPTED","CONSOLE":{"maxCredSessionRequestTime":"36000","maxCredlessSessionRequestTime":"36000","shareableAccounts":{"IDQueryCredentials":"acc.name in (''cpamuser1'')","IDQueryCredentialless":"acc.name in (''cpamuser2'', ''cpamuser3'')","IDQueryCredentiallessViewPwd":"acc.name in (''cpamuser2'')"},"endpointAttributeMappings":[{"column":"accessquery","value":"where users.USERNAME is not null","feature":"endpointAccessQuery"},{"column":"customproperty43","value":"PAMDefaultUserAccountAccessControl","feature":"accountVisibilityControl"}],"endpointPamConfig":{"maxConcurrentSession":"50"},"accountVisibilityConfig":{"accountCustomProperty":"customproperty55","accountMappingConfig":[{"accountPattern":"cpamuser*","mappingData":"roletest1","override":"false"},{"accountPattern":"cpamuser1,cpamuser2","mappingData":"roletest2","override":"false"}]}}}' type: string required: - PASSWORD SAPConnectionAttributes: properties: CREATEACCOUNTJSON: type: string AUDIT_LOG_JSON: type: string connectionType: example: MS_BASED_CONNECTOR type: string SAPTABLE_FILTER_LANG: type: string PASSWORD_NOOFSPLCHARS: type: string TERMINATEDUSERGROUP: type: string LOGS_TABLE_FILTER: type: string ECC_OR_S4HANA: type: string FIREFIGHTERID_REVOKE_ACCESS_JSON: type: string ConfigJSON: type: string FIREFIGHTERID_GRANT_ACCESS_JSON: type: string PROV_PASSWORD: type: string JCO_SNC_LIBRARY: type: string isTimeoutSupported: example: true type: boolean JCO_R3NAME: type: string EXTERNAL_SOD_EVAL_JSON: type: string JCO_ASHOST: example: sap.example.com type: string PASSWORD_NOOFDIGITS: type: string PROV_JCO_MSHOST: type: string PASSWORD: example: pass123 type: string PAM_CONFIG: type: string JCO_SNC_MYNAME: type: string ENFORCEPASSWORDCHANGE: type: string JCO_USER: type: string JCO_SNC_MODE: type: string PROV_JCO_MSSERV: type: string HANAREFTABLEJSON: type: string PASSWORD_MIN_LENGTH: type: string JCO_CLIENT: example: '10' type: string TERMINATED_USER_ROLE_ACTION: type: string RESET_PWD_FOR_NEWACCOUNT: type: string PROV_JCO_CLIENT: type: string SNC: type: string JCO_MSSERV: type: string PROV_CUA_SNC: type: string connectionTimeoutConfig: $ref: '#/components/schemas/ConnectionTimeoutConfig' PROV_JCO_USER: type: string JCO_LANG: example: en type: string JCO_SNC_PARTNERNAME: type: string STATUS_THRESHOLD_CONFIG: type: string PROV_JCO_SYSNR: type: string SETCUASYSTEM: type: string MESSAGESERVER: example: 'FALSE' type: string PROV_JCO_ASHOST: type: string PROV_JCO_GROUP: type: string PROV_CUA_ENABLED: type: string JCO_MSHOST: type: string PROV_JCO_R3NAME: type: string PASSWORD_NOOFCAPSALPHA: type: string MODIFYUSERDATAJSON: type: string isTimeoutConfigValidated: example: true type: boolean JCO_SNC_QOP: type: string TABLES: type: string PROV_JCO_LANG: type: string JCO_SYSNR: example: '101' type: string EXTERNAL_SOD_EVAL_JSON_DETAIL: type: string DATA_IMPORT_FILTER: type: string ENABLEACCOUNTJSON: type: string ALTERNATE_OUTPUT_PARAMETER_ET_DATA: type: string JCO_GROUP: type: string PASSWORD_MAX_LENGTH: type: string USERIMPORTJSON: type: string SYSTEMNAME: type: string UPDATEACCOUNTJSON: type: string ROLE_DEFAULT_DATE: description: 'Default end date for SAP roles. Format: yyyyMMdd (e.g., 20251231). If not configured, defaults to 99991231.' type: string EntraIDConnector: allOf: - $ref: '#/components/schemas/BaseConnector' - properties: CLIENT_ID: type: string CLIENT_SECRET: description: Property for CLIENT_SECRET type: string ACCESS_TOKEN: description: Property for ACCESS_TOKEN type: string AAD_TENANT_ID: description: Property for AAD_TENANT_ID type: string AZURE_MGMT_ACCESS_TOKEN: description: Property for AZURE_MGMT_ACCESS_TOKEN type: string AUTHENTICATION_ENDPOINT: description: Property for AUTHENTICATION_ENDPOINT type: string MICROSOFT_GRAPH_ENDPOINT: description: Property for MICROSOFT_GRAPH_ENDPOINT type: string AZURE_MANAGEMENT_ENDPOINT: description: Property for AZURE_MANAGEMENT_ENDPOINT type: string ImportUserJSON: description: Property for ImportUserJSON type: string CREATEUSERS: description: Property for CREATEUSERS type: string WINDOWS_CONNECTOR_JSON: description: Property for WINDOWS_CONNECTOR_JSON type: string CREATE_NEW_ENDPOINTS: description: Property for CREATE_NEW_ENDPOINTS type: string MANAGED_ACCOUNT_TYPE: description: Property for MANAGED_ACCOUNT_TYPE type: string ACCOUNT_ATTRIBUTES: description: Property for ACCOUNT_ATTRIBUTES type: string SERVICE_ACCOUNT_ATTRIBUTES: description: Property for SERVICE_ACCOUNT_ATTRIBUTES type: string DELTATOKENSJSON: description: Property for DELTATOKENSJSON type: string ACCOUNT_IMPORT_FIELDS: description: Property for ACCOUNT_IMPORT_FIELDS type: string IMPORT_DEPTH: description: Property for IMPORT_DEPTH type: string ENTITLEMENT_ATTRIBUTE: description: Property for ENTITLEMENT_ATTRIBUTE type: string CreateAccountJSON: description: Property for CreateAccountJSON type: string UpdateAccountJSON: description: Property for UpdateAccountJSON type: string EnableAccountJSON: description: Property for EnableAccountJSON type: string DisableAccountJSON: description: Property for DisableAccountJSON type: string AddAccessJSON: description: Property for AddAccessJSON type: string RemoveAccessJSON: description: Property for RemoveAccessJSON type: string UpdateUserJSON: description: Property for UpdateUserJSON type: string ChangePassJSON: description: Property for ChangePassJSON type: string RemoveAccountJSON: description: Property for RemoveAccountJSON type: string ConnectionJSON: description: Property for ConnectionJSON type: string CreateGroupJSON: description: Property for CreateGroupJSON type: string UpdateGroupJSON: description: Property for UpdateGroupJSON type: string AddAccessToEntitlementJSON: description: Property for AddAccessToEntitlementJSON type: string RemoveAccessFromEntitlementJSON: description: Property for RemoveAccessFromEntitlementJSON type: string DeleteGroupJSON: description: Property for DeleteGroupJSON type: string CreateServicePrincipalJSON: description: Property for CreateServicePrincipalJSON type: string UpdateServicePrincipalJSON: description: Property for UpdateServicePrincipalJSON type: string RemoveServicePrincipalJSON: description: Property for RemoveServicePrincipalJSON type: string ENTITLEMENT_FILTER_JSON: description: Property for ENTITLEMENT_FILTER_JSON type: string CreateTeamJSON: description: Property for CreateTeamJSON type: string CreateChannelJSON: description: Property for CreateChannelJSON type: string STATUS_THRESHOLD_CONFIG: description: Property for STATUS_THRESHOLD_CONFIG type: string ACCOUNTS_FILTER: description: Property for ACCOUNTS_FILTER type: string PAM_CONFIG: description: Property for PAM_CONFIG type: string ENDPOINTS_FILTER: description: Property for ENDPOINTS_FILTER type: string ConfigJSON: description: Property for ConfigJSON type: string MODIFYUSERDATAJSON: description: Property for MODIFYUSERDATAJSON type: string ENHANCEDDIRECTORYROLES: description: Property for ENHANCEDDIRECTORYROLES type: string required: - AAD_TENANT_ID - CLIENT_ID - CLIENT_SECRET WorkdaySOAPConnectionAttributes: properties: ACCOUNTS_IMPORT_JSON: type: string CHANGEPASSJSON: type: string COMBINEDCREATEREQUEST: type: string CONNECTIONJSON: type: string CREATEACCOUNTJSON: type: string CUSTOM_CONFIG: type: string DATA_TO_IMPORT: type: string DATEFORMAT: type: string DELETEACCOUNTJSON: type: string DISABLEACCOUNTJSON: type: string ENABLEACCOUNTJSON: type: string GRANTACCESSJSON: type: string HR_IMPORT_JSON: type: string MODIFYUSERDATAJSON: type: string PAGE_SIZE: type: string PAM_CONFIG: type: string PASSWORD: type: string PASSWORD_MAX_LENGTH: type: string PASSWORD_MIN_LENGTH: type: string PASSWORD_NOOFCAPSALPHA: type: string PASSWORD_NOOFDIGITS: type: string PASSWORD_NOOFSPLCHARS: type: string PASSWORD_TYPE: type: string RESPONSEPATH_PAGERESULTS: type: string RESPONSEPATH_TOTALRESULTS: type: string RESPONSEPATH_USERLIST: type: string REVOKEACCESSJSON: type: string SOAP_ENDPOINT: type: string UPDATEACCOUNTJSON: type: string UPDATEUSERJSON: type: string USERNAME: type: string connectionTimeoutConfig: $ref: '#/components/schemas/ConnectionTimeoutConfig' connectionType: type: string isTimeoutConfigValidated: type: boolean isTimeoutSupported: type: boolean getConnectionDetailsResponse: discriminator: mapping: AD: '#/components/schemas/ADConnectionResponse' REST: '#/components/schemas/RESTConnectionResponse' DB: '#/components/schemas/DBConnectionResponse' ADSI: '#/components/schemas/ADSIConnectionResponse' Workday: '#/components/schemas/WorkdayConnectionResponse' EntraID: '#/components/schemas/EntraIDConnectionResponse' SAP: '#/components/schemas/SAPConnectionResponse' Salesforce: '#/components/schemas/SalesforceConnectionResponse' UNIX: '#/components/schemas/UNIXConnectionResponse' GithubREST: '#/components/schemas/GithubRESTResponse' Okta: '#/components/schemas/OktaConnectionResponse' WorkdaySOAP: '#/components/schemas/WorkdaySOAPConnectionResponse' SFTP: '#/components/schemas/SFTPConnectionResponse' propertyName: connectiontype oneOf: - $ref: '#/components/schemas/ADConnectionResponse' - $ref: '#/components/schemas/RESTConnectionResponse' - $ref: '#/components/schemas/DBConnectionResponse' - $ref: '#/components/schemas/ADSIConnectionResponse' - $ref: '#/components/schemas/WorkdayConnectionResponse' - $ref: '#/components/schemas/EntraIDConnectionResponse' - $ref: '#/components/schemas/SAPConnectionResponse' - $ref: '#/components/schemas/SalesforceConnectionResponse' - $ref: '#/components/schemas/UNIXConnectionResponse' - $ref: '#/components/schemas/GithubRESTConnectionResponse' - $ref: '#/components/schemas/OktaConnectionResponse' - $ref: '#/components/schemas/WorkdaySOAPConnectionResponse' - $ref: '#/components/schemas/SFTPConnectionResponse' SalesforceConnectionResponse: allOf: - $ref: '#/components/schemas/getConnectionDetails' - properties: connectionattributes: $ref: '#/components/schemas/SalesforceConnectionAttributes' WorkdaySOAPConnector: allOf: - $ref: '#/components/schemas/BaseConnector' - properties: ACCOUNTS_IMPORT_JSON: description: JSON configuration for accounts import type: string CHANGEPASSJSON: description: JSON for password changes type: string COMBINEDCREATEREQUEST: description: Combined create request configuration type: string CONNECTIONJSON: type: string CREATEACCOUNTJSON: description: JSON for account creation type: string CUSTOM_CONFIG: description: Custom configuration JSON type: string DATA_TO_IMPORT: description: Specification of data types to import type: string DATEFORMAT: description: Date format for data processing type: string DELETEACCOUNTJSON: description: JSON for account deletion type: string DISABLEACCOUNTJSON: description: JSON for account disabling type: string ENABLEACCOUNTJSON: description: JSON for account enabling type: string GRANTACCESSJSON: description: JSON for granting access type: string HR_IMPORT_JSON: description: JSON configuration for HR data import type: string MODIFYUSERDATAJSON: description: JSON for modifying user data type: string PAGE_SIZE: description: Number of records per page type: string PAM_CONFIG: description: PAM configuration JSON type: string PASSWORD: description: Password for SOAP authentication type: string PASSWORD_MAX_LENGTH: description: Maximum password length type: string PASSWORD_MIN_LENGTH: description: Minimum password length type: string PASSWORD_NOOFCAPSALPHA: description: Number of capital letters required type: string PASSWORD_NOOFDIGITS: description: Number of digits required type: string PASSWORD_NOOFSPLCHARS: description: Number of special characters required type: string PASSWORD_TYPE: description: Type of password authentication type: string RESPONSEPATH_PAGERESULTS: description: Response path for page results type: string RESPONSEPATH_TOTALRESULTS: description: Response path for total results count type: string RESPONSEPATH_USERLIST: description: Response path for user list type: string REVOKEACCESSJSON: description: JSON for revoking access type: string SOAP_ENDPOINT: description: SOAP endpoint URL for Workday type: string UPDATEACCOUNTJSON: description: JSON for account updates type: string UPDATEUSERJSON: description: JSON for user updates type: string USERNAME: description: Username for SOAP authentication type: string ADSIConnectionAttributes: properties: importNestedMembership: example: 'true' type: string PASSWDPOLICYJSON: type: string CREATEACCOUNTJSON: example: "{\n \"objects\": [\n {\n \"objectClasses\": [\n \"user\",\n \"top\",\n \"Person\",\n \"OrganizationalPerson\"\n ],\n \"baseDn\": \"CN=Users,DC=saviyntlabs,DC=org\",\n \"password\": \"Password@123\",\n \"attributes\": {\n \"sn\": \"${user.lastname}\",\n \"sAMAccountName\": \"${task.accountName}\",\n \"cn\": \"${task.accountName}\",\n \"userAccountControl\": 512,\n \"co\": \"\",\n \"department\": \"${user.departmentname}\",\n \"displayName\": \"${user.displayname}\",\n \"employeeID\": \"${user.employeeid}\",\n \"employeeNumber\": \"1\",\n \"employeeType\": \"${user.employeeType}\",\n \"givenName\": \"${user.firstname}\",\n \"l\": \"${user.city}\",\n \"mail\": \"${user.email}\",\n \"proxyAddresses\": [\n \"SMTP:test@test.org\",\n \"SIP:Test@test1.org\"\n ]\n }\n }\n ]\n }" type: string ENDPOINTS_FILTER: type: string DISABLEACCOUNTJSON: example: '{"objects":[{"objectClasses":["user"],"distinguishedName":"${account.accountID}","deleteAllGroups":false,"attributes":{"userAccountControl":514}}]}' type: string REMOVEACCESSENTITLEMENTJSON: example: '{\n "objects":[\n {\n "objectClasses":[\n "group"\n ],\n "distinguishedName":"${ent1Value.entitlement_value?.replace(''\\'', ''\\\\\\'')?.replace(''/'', ''\\/'')}",\n "removeGroup":"${ent2Value.entitlement_value?.replace(''\\'', ''\\\\\\'')?.replace(''/'', ''\\/'')}"\n }\n ],\n "requestConfiguration":{\n "grpMemExistenceChk":{\n "enable":true\n }\n }\n}' type: string groupSearchBaseDN: example: DC=saviyntlabs,DC=org type: string connectionType: example: MS_BASED_CONNECTOR type: string STATUSKEYJSON: example: "{\n \"STATUS_ACTIVE\": [\n \"512\",\n \"544\",\n \"66048\"\n ],\n \"STATUS_INACTIVE\": [\n \"546\",\n \"514\"\n ]\n}" type: string DEFAULT_USER_ROLE: type: string FOREST_DETAILS: example: '{"forestDetails":{"example.org":[{"saviyntlabs.org":["example.org"]}]}}' type: string USERNAME: example: username type: string UPDATESERVICEACCOUNTJSON: example: '{\n "objects": [\n {\n "objectClasses": [\n "user",\n "top",\n "Person",\n "OrganizationalPerson"\n ],\n "distinguishedName": "${account.accountID?.replace(''\\'', ''\\\\\\'')?.replace(''/'', ''\\/'')}",\n "attributes": {\n "pwdLastSet": 0,\n "displayName": "testDPUpdated"\n }\n }\n ]\n}' type: string ADDACCESSJSON: example: '{\n "objects": [\n {\n "objectClasses": [\n "user"\n ],\n "distinguishedName": "${accountID}",\n "addGroup": "${entitlement_values}"\n }\n ],\n "requestConfiguration": {\n "grpMemExistenceChk": {\n "enable": true\n }\n }\n}' type: string CREATESERVICEACCOUNTJSON: example: '{\n "objects": [\n {\n "objectClasses": [\n "user",\n "top",\n "Person",\n "OrganizationalPerson"\n ],\n "baseDn": "${baseDN}",\n "password": "${password}",\n "attributes": {\n "sAMAccountName": "${task.accountName}",\n "cn": "${task.accountName}",\n "displayname": "testDP",\n "userAccountControl": 512\n }\n }\n ]\n}' type: string ACCOUNTNAMERULE: example: '{"AccountNameRule":{"Attributes":[{"cn":"ACCOUNTID","baseDN":"${baseDN}","RuleCheck":"${user.lastname}, ${user.firstname}###${user.lastname}, ${user.firstname}1###${user.lastname}, ${user.firstname}2###${user.lastname}, ${user.firstname}3###${user.lastname}, ${user.firstname}4"}]}}' type: string CONNECTION_URL: example: http://sample.com type: string isTimeoutSupported: example: true type: boolean createUpdateMappings: type: string ACCOUNT_ATTRIBUTE: example: '[CUSTOMPROPERTY1::samaccountname#String,CUSTOMPROPERTY2::userprincipalname#String,LASTLOGONDATE::lastLogon#millisec,DISPLAYNAME::cn#String,CUSTOMPROPERTY25::company#String,CUSTOMPROPERTY3::sn#String,COMMENTS::distinguishedname#String,CUSTOMPROPERTY4::homedirectory#String,LASTPASSWORDCHANGE::pwdlastset#millisec,CUSTOMPROPERTY5::co#String,CUSTOMPROPERTY6::cn#String,CUSTOMPROPERTY7::givenname#String,CUSTOMPROPERTY8::title#String,CUSTOMPROPERTY9::telephonenumber#String,CUSTOMPROPERTY10::c#String,DESCRIPTION::description#String,CUSTOMPROPERTY11::usncreated#String,VALIDTHROUGH::accountexpires#millisec,CUSTOMPROPERTY12::logoncount#String,CUSTOMPROPERTY13::physicaldeliveryofficename#String,UPDATEDATE::whenchanged#date,CUSTOMPROPERTY14::extensionattribute1#String,CUSTOMPROPERTY15::extensionattribute2#String,CUSTOMPROPERTY16::streetaddress#String,CUSTOMPROPERTY17::mailnickname#String,CUSTOMPROPERTY18::department#String,CUSTOMPROPERTY19::countrycode#String,NAME::distinguishedname#String,CUSTOMPROPERTY21::manager#String,CUSTOMPROPERTY22::homephone#String,CUSTOMPROPERTY23::mobile#String,ACCOUNTCLASS::objectclass#String,ACCOUNTID::distinguishedname#String,CUSTOMPROPERTY24::useraccountcontrol#String,status::useraccountcontrol#Number,CUSTOMPROPERTY26::objectguid#String,CUSTOMPROPERTY28::forest#String,CUSTOMPROPERTY29::domain#string,CUSTOMPROPERTY30::objectclass#String]' type: string PASSWORD: example: pass123# type: string PAM_CONFIG: type: string PAGE_SIZE: example: '1000' type: string SEARCHFILTER: example: DC=example,DC=org type: string UPDATEGROUPJSON: example: '{"objects":[{"attributes":{"description":"${role.description}","proxyAddresses":"${role.customproperty20}"},"distinguishedName":"${role.role_name}","objectClasses":["group"]}]}' type: string CREATEGROUPJSON: example: '"objects":[{"attributes":{"cn":"${role.displayname}","description":"${role.description}","displayName":"${role.displayname}","groupType":"${role?.customproperty21 == ''Security'' role?.customproperty22 == ''Global''?''-2147483646'' : role?.customproperty21==''Security''role?.customproperty22==''Universal''?''-2147483640'' : role?.customproperty21== ''Security''role?.customproperty22==''Domain Local'' ? ''-2147483644'':role?.customproperty21==''Distribution''role?.customproperty22==''Global'' ? ''2'':role?.customproperty21== ''Distribution''role?.customproperty22==''Universal''?''8'':role?.customproperty21==''Distribution''role?.customproperty22==''Domain Local''?''4'':''''}","name":"${role.displayname}"},"baseDn":"${role.customproperty24}","objectClasses":["group"]}]}' type: string ENTITLEMENT_ATTRIBUTE: example: memberOf type: string CHECKFORUNIQUE: example: '"CheckForUnique":{"Attributes":[{"samaccountname":"customproperty1","RuleCheck":"${user.lastname}###${user.lastname}1###${user.lastname}2###${user.lastname}3###${user.lastname}4###${user.lastname}5###${user.lastname}6###${user.lastname}7###${user.lastname}8"},{"userprincipalname":"customproperty2","RuleCheck":"${user.lastname}@domainame.com###${user.lastname}1@domainname.com###${user.lastname}2@domainname.com###${user.lastname}3@domainname.com###${user.lastname}4@domainname.com"},{"displayname":"customproperty31","RuleCheck":"${user.lastname}, ${user.firstname}###${user.lastname}, ${user.firstname}1###${user.lastname}, ${user.firstname}2###${user.lastname}, ${user.firstname}3###${user.lastname}, ${user.firstname}4"}]}}' type: string REMOVESERVICEACCOUNTJSON: example: '{\n "objects": [\n {\n "distinguishedName": "${account.accountID?.replace(''\\'', ''\\\\'')?.replace(''/'', ''\\/'')}",\n "removeAction": "DELETE",\n "deleteChildObjects": false\n }\n ]\n}' type: string connectionTimeoutConfig: $ref: '#/components/schemas/ConnectionTimeoutConfig' UPDATEUSERJSON: type: string URL: example: www.example.com type: string MOVEACCOUNTJSON: type: string CUSTOMCONFIGJSON: type: string STATUS_THRESHOLD_CONFIG: example: "{\n \"importGroupHierarchy\": \"true\",\n \"entitlementTypeName\": \"memberOf\",\n \"performGroupAccountLinking\": \"true\",\n \"groupObjectClass\": \"(objectclass=group)\",\n \"entitlementOwnerAttribute\": \"managedby\",\n \"tableFieldAttribute\": \"accountID\",\n \"mapping\": \"memberHash:memberof_char,customProperty1:samaccounttype_char,customProperty2:instancetype_char,customProperty3:usncreated_char,customProperty4:grouptype_char,customProperty5:dscorepropagationdata_char,customProperty12:dn_char,customProperty13:cn_char,lastscandate:whencreated_date,customProperty15:managedBy_char,entitlement_glossary:description_char,description:description_char,displayname:name_char,customProperty9:name_char,customProperty10:objectcategory_char,customProperty11:samaccounttype_char,entitlement_value:distinguishedname_char,entitlementid:distinguishedname_char,customProperty14:objectclass_char,updatedate:whenchanged_date,customProperty17:distinguishedname_char,RECONCILATION_FIELD:customProperty18,customProperty18:objectguid_char\"\n}" type: string groupImportMapping: example: '{ "importGroupHierarchy": "true", "entitlementTypeName": "memberOf", "performGroupAccountLinking": "true", "groupObjectClass": "(objectclass=group)", "entitlementOwnerAttribute": "managedby", "tableFieldAttribute": "accountID", "mapping": "memberHash:memberof_char,customProperty1:samaccounttype_char,customProperty2:instancetype_char,customProperty3:usncreated_char,customProperty4:grouptype_char,customProperty5:dscorepropagationdata_char,customProperty12:dn_char,customProperty13:cn_char,lastscandate:whencreated_date,customProperty15:managedBy_char,entitlement_glossary:description_char,description:description_char,displayname:name_char,customProperty9:name_char,customProperty10:objectcategory_char,customProperty11:samaccounttype_char,entitlement_value:distinguishedname_char,entitlementid:distinguishedname_char,customProperty14:objectclass_char,updatedate:whenchanged_date,customProperty17:distinguishedname_char,RECONCILATION_FIELD:customProperty18,customProperty18:objectguid_char" }' type: string PROVISIONING_URL: example: http://example.com type: string REMOVEGROUPJSON: example: "{\n \"objects\": [\n {\n \"distinguishedName\": \"${role.role_name}\",\n \"removeAction\": \"DELETE\",\n \"deleteChildObjects\": false\n }\n ]\n}" type: string REMOVEACCESSJSON: example: '{"objects": [{"distinguishedName": "${account.accountID}","removeAction": "DELETE","deleteChildObjects": false}]}' type: string IMPORTDATACOOKIES: type: string RESETANDCHANGEPASSWRDJSON: example: '{ "objects":[ { "objectClasses":[ "user" ], "password":"${password}", "distinguishedName":"", "attributes":{ "pwdLastSet":"${pwdLastSet}" } } ]}' type: string USER_ATTRIBUTE: example: '[FIRSTNAME::givenname#String,LASTNAME::sn#String,CUSTOMPROPERTY1::samaccountname#String,USERNAME::distinguishedname#String,DISPLAYNAME::cn#String,CUSTOMPROPERTY25::description#String,CUSTOMPROPERTY3::sn#String,COMMENTS::distinguishedname#String,CUSTOMPROPERTY4::homedirectory#String,CUSTOMPROPERTY5::co#String,CUSTOMPROPERTY6::cn#String,CUSTOMPROPERTY7::givenname#String,CUSTOMPROPERTY8::title#String,CUSTOMPROPERTY9::telephonenumber#String,CUSTOMPROPERTY10::c#String,CUSTOMPROPERTY11::uSNCreated#String,ENDDATE::accountExpires#millisec,CUSTOMPROPERTY12::logonCount#String,CUSTOMPROPERTY13::physicaldeliveryofficename#String,UPDATEDATE::whenchanged#date,CUSTOMPROPERTY14::extensionattribute1#String,CUSTOMPROPERTY15::extensionattribute2#String,CUSTOMPROPERTY16::streetaddress#String,CUSTOMPROPERTY17::mailnickname#String,CUSTOMPROPERTY18::department#String,CUSTOMPROPERTY19::countrycode#String,CUSTOMPROPERTY2::samaccountname#String,CUSTOMPROPERTY20::userprincipalname#String,CUSTOMPROPERTY21::manager#String,CUSTOMPROPERTY22::homephone#String,CUSTOMPROPERTY23::mobile#String,CREATEDATE::whencreated#date,customproperty24::useraccountcontrol#String,CUSTOMPROPERTY26::distinguishedname#String,statuskey::useraccountcontrol#String,CUSTOMPROPERTY27::objectguid#String,RECONCILATION_FIELD::CUSTOMPROPERTY27,CUSTOMPROPERTY28::forest#String,CUSTOMPROPERTY29::domain#string]' type: string ADDACCESSENTITLEMENTJSON: example: '{\n "objects":[\n {\n "objectClasses":[\n "group"\n ],\n "distinguishedName":"${ent1Value.entitlement_value?.replace(''\\'', ''\\\\'')?.replace(''/'', ''\\/'')}",\n "addGroup":"${ent2Value.entitlement_value?.replace(''\\'', ''\\\\'')?.replace(''/'', ''\\/'')}"\n }\n ],\n "requestConfiguration":{\n "grpMemExistenceChk":{\n "enable":true\n }\n }\n}' type: string MODIFYUSERDATAJSON: type: string isTimeoutConfigValidated: example: true type: boolean ENABLEGROUPMANAGEMENT: type: string ENABLEACCOUNTJSON: example: '{"objects":[{"objectClasses":["user"],"distinguishedName":"${account.accountID}","deleteAllGroups":false,"attributes":{"userAccountControl":512}}]}' type: string FORESTLIST: example: example.org type: string OBJECTFILTER: example: (&(objectCategory=person)(objectClass=user)) type: string UPDATEACCOUNTJSON: example: '{\"objects\":[{\"attributes\":{\"additionalAttributes\":{\"companyName\":\"Saviynt\",\"departmentName\":\"PM\"},\"displayName\":\"${user.displayname}\",\"streetAddress\":\"${user.street}\"},\"distinguishedName\":\"${account.accountID?.replace(''\\'', ''\\\\'')?.replace(''/'', ''\\/'')}\",\"objectClasses\":[\"user\"]}]}' type: string REMOVEACCOUNTJSON: example: '{\n "objects": [\n {\n "objectClasses": [\n "group"\n ],\n "distinguishedName": "${accountID}",\n "removeGroup": "${entitlement_values}"\n }\n ],\n "requestConfiguration": {\n "grpMemExistenceChk": {\n "enable": true\n }\n }\n}' type: string