LDAP attributes to ClearID attribute mappings
2026-05-06Last updated
The mapping of Active Directory (AD) Lightweight Directory Access Protocol (LDAP) attributes to Genetec ClearID™ identity attributes ensures data consistency and supports automated role-based access control.
LDAP attributes to ClearID attribute mappings
| LDAP attributes | ClearID identity attributes |
|---|---|
| whenChanged Important: The whenChanged attribute indicates
the last time a synchronization with the ClearID LDAP Synchronization Agent
occurred. This attribute is then used to query Active
Directory users that have changed since the last synchronization so that only
changed users are updated when the next synchronization occurs. |
Not applicable |
| userAccountControl | Status Note: The
ClearID Status attribute is set to inactive if the Active Directory
attribute userAccountControl is set to disabled. |
| givenName | FirstName |
| sn | LastName |
| displayName | DisplayName |
| jpegPhoto |
Note:
jpegPhoto Is used to upload a picture into the ClearID identity. |
| thumbnailPhoto (fallback if jpegPhoto is empty) |
Note:
thumbnailPhoto is used as a fallback ( if jpegPhoto is empty) to upload
a picture into the ClearID identity. |
| countryCode | CountryCode |
| employeeID | EmployeeNumber |
| employeeNumber (fallback if employeeID is empty) | EmployeeNumber |
| hrStatus | Worker type description |
| title | JobTitle |
| telephoneNumber | PhoneNumberPrimary |
| phone | PhoneNumberSecondary |
| preferredLanguageCode | Culture |
| Mobile (fallback if phone is empty) | PhoneNumberSecondary |
| department | DepartmentName |
| company | CompanyName |
| userPrincipalName Note: The userPrincipalName attribute is used as the link
between the AD user and the ClearID identity. |
Email, ExternalId |
| manager | SupervisorName |