Choosing Created/Updated by attribute from LDAP connection
D
Darren MOSS
started a topic
almost 2 years ago
We use an LDAP identity provider.
We allow for users to authenticate using either sAMAccountName, UserPrincipalName or email when logging into xDM.
On each login, we retrieve the user's email address for notification purposes regardless of which method they used to authenticate.
I noticed that created/updated by audit information uses whatever the user logged in with at the time they performed the changes to the records. This makes reading audit logs tricky as not all users use the same authentication method and even the same user uses different methods when they login. In those cases, audits are displaying mixes of UPN, SAM and Email, which is untidy and confusing.
Is there a way to configure the audit logging to always use the email address regardless of authentication method?
This way the audit information would be consistent and much easier to read.
Best Answer
A
Alexia SIMOND
said
over 1 year ago
Hello,
As it is very much linked to user preferences, there is no way to block this information.
However, if you want to expose those data for whatever purpose and to have a standardized output, then a lookup table should help that purpose.
The only prerequisite being that you indeed have a way to match those different output formats.
1 Comment
A
Alexia SIMOND
said
over 1 year ago
Answer
Hello,
As it is very much linked to user preferences, there is no way to block this information.
However, if you want to expose those data for whatever purpose and to have a standardized output, then a lookup table should help that purpose.
The only prerequisite being that you indeed have a way to match those different output formats.
Darren MOSS
We use an LDAP identity provider.
We allow for users to authenticate using either sAMAccountName, UserPrincipalName or email when logging into xDM.
On each login, we retrieve the user's email address for notification purposes regardless of which method they used to authenticate.
I noticed that created/updated by audit information uses whatever the user logged in with at the time they performed the changes to the records.
This makes reading audit logs tricky as not all users use the same authentication method and even the same user uses different methods when they login.
In those cases, audits are displaying mixes of UPN, SAM and Email, which is untidy and confusing.
Is there a way to configure the audit logging to always use the email address regardless of authentication method?
This way the audit information would be consistent and much easier to read.
Hello,
As it is very much linked to user preferences, there is no way to block this information.
However, if you want to expose those data for whatever purpose and to have a standardized output, then a lookup table should help that purpose.
The only prerequisite being that you indeed have a way to match those different output formats.
Alexia SIMOND
Hello,
As it is very much linked to user preferences, there is no way to block this information.
However, if you want to expose those data for whatever purpose and to have a standardized output, then a lookup table should help that purpose.
The only prerequisite being that you indeed have a way to match those different output formats.
-
Deployment History Date
-
Username in Tomcat Access Logs
-
Is It Possible to Perform Automatic Authentication with The User's Windows Account?
-
Where is the documentation for Version 5.2.5?
-
On Prem Semarchy Authentication using Azure AD?
-
Delete old models
-
Sync production model version with dev
-
Recreate a dev environment. Any side effect?
-
Indexes on xDM database tables
-
What logging technology is used in the Semarchy xDM platform?
See all 82 topics