Directory sync: Active Directory: Which user synchronization field to use?


Username / Groupname

It is the most trivial solution but, according to the company policy, a username (or a groupname) may change in time.
When a username is renamed, the corresponding user with the previous username in WorkflowGen will be deleted or archived and a new user will be created with the new username.

System identifier

The “System identifier” provides a unique identifier which doesn’t change in time.
It seems to be the perfect synchronization key but sometimes directory administrators have to delete and recreate a user account with the same username. In this case, the system identifier value is changed.
When a user is deleted and then recreated in Active Directory, the user in WorkflowGen is deleted or archived and a new user is created.

So both solutions have advantages and disadvantages that you have to evaluate to define your synchronization keys.