Accounts and passwords
An account is an identity's access to a target system, for example an SAP user or an Active Directory account. This page describes how Nova names and links accounts, where the account status it shows comes from and how Nova handles passwords. How Nova creates accounts during provisioning is described under Provisioning runs.
One account, one identity
Every account belongs to exactly one identity. If an account is already linked to an identity, Nova refuses to link the same account to another identity.
Account IDs
Nova builds the ID of a new account from the target system's naming rule – see Target systems – Overview.
- ID already exists: if an account with the computed ID already exists in the target system, Nova never takes it over silently. Nova stops and reports a conflict. An administrator decides: link the existing account after checking it, or assign a different ID.
- Creation uncertain: if it is unclear whether a create request reached the target system – for example after a timeout – Nova keeps the chosen ID. On the next attempt, Nova looks for exactly this account and links it instead of creating a second one.
Account status
Nova shows an account's status, such as active or locked, as it last read it in the target system – together with the time of that read. A newly linked account shows “unknown” until Nova has read it.
- Locking and unlocking count as done only once Nova has read the new state back from the target system.
- Missing accounts: Nova concludes that an account does not exist only when the search in the target system succeeded and was unambiguous. A failed or ambiguous search does not count as “not found”.
Passwords
- Generated passwords are random and follow the target system's password rules.
- Passwords set by administrators must be changed by the identity at the next sign-in – in every target system that supports this: SAP, Active Directory, Microsoft Entra ID and Keycloak.
- Encrypted only: to directories such as Active Directory, Nova transmits passwords only over LDAPS or StartTLS.
- Not stored: Nova does not store the passwords of accounts in target systems. They never appear in the logs or in the change journal.
Leavers
When an identity leaves, Nova locks all its accounts. If a lock fails, Nova retries it until it is confirmed.
Nova permanently deletes an identity only once all its accounts are confirmed as locked or deleted – see Identities and their status.
Orphaned accounts
For each target system, Nova shows the accounts that exist there but belong to no identity.