Skip to content

Connected Systems

The Connected Systems cmdlets manage the full lifecycle of Connected Systems in JIM: creating and configuring systems, importing schemas and hierarchy, selecting object types and attributes, browsing connector space objects, and reviewing Pending Exports. Most cmdlets support pipeline input for scripting and automation workflows.


Get-JIMConnectedSystem

Retrieves one or more Connected Systems, their object types, or a deletion impact preview.

Syntax

# List (default)
Get-JIMConnectedSystem [-Name <string>]

# ById
Get-JIMConnectedSystem -Id <int>

# ObjectTypes
Get-JIMConnectedSystem -Id <int> -ObjectTypes

# DeletionPreview
Get-JIMConnectedSystem -Id <int> -DeletionPreview

Parameters

Name Type Required Default Description
Id int Yes (ById, ObjectTypes, DeletionPreview) Connected System identifier. Accepts pipeline input by property name.
Name string No (List only) Filter by name; supports wildcard characters (*, ?)
ObjectTypes switch No $false Returns the object types configured on the Connected System
DeletionPreview switch No $false Returns a deletion impact preview for the Connected System

Output

  • List: Connected System headers with properties such as Id, Name, Description, Status, ObjectCount, ConnectorName, and ConnectorId.
  • ById: the full Connected System, including its nested Connector (use $cs.Connector.Id for the connector definition ID), configuration state, and a nested ConfigurationDrift object (see below).
  • ObjectTypes: Object type definitions for the specified Connected System.
  • DeletionPreview: Deletion impact preview with counts and warnings.

Examples

List all Connected Systems
Get-JIMConnectedSystem
Filter by name using wildcards
Get-JIMConnectedSystem -Name "HR*"
Get a specific Connected System by ID
Get-JIMConnectedSystem -Id 3
Retrieve object types for a Connected System
Get-JIMConnectedSystem -Id 3 -ObjectTypes
Find Connected Systems needing a Full Synchronisation
Get-JIMConnectedSystem |
    ForEach-Object { Get-JIMConnectedSystem -Id $_.Id } |
    Where-Object { $_.ConfigurationDrift.HasPendingChanges } |
    Select-Object Name, @{n='Changes';e={$_.ConfigurationDrift.ChangeCount}},
                        @{n='Highest';e={$_.ConfigurationDrift.HighestChangeClass}}

ConfigurationDrift (ById only)

Whether the configuration has changed in a way that needs a Full Synchronisation to take effect. Only Sync-affecting and Destructive changes count, so a rename never registers here.

Property Type Description
HasPendingChanges bool Qualifying changes have been recorded since the last completed Full Synchronisation
IsDeterminable bool The question has a meaningful answer; see the caution below
NeverFullySynchronised bool No Full Synchronisation has ever completed, so there is no reference point
TrackingDisabled bool Configuration change tracking is off, so JIM holds no record of what changed
LastFullSynchronisation datetime? When the last completed Full Synchronisation started, or $null
MostRecentChange datetime? When the most recent qualifying change was recorded, or $null
ChangeCount int How many qualifying changes there are
HighestChangeClass string Cosmetic, SyncAffecting or Destructive; NotClassified when there are no changes

Get-JIMConnectedSystemPasswordPolicy

Reports what the Connected System itself said it will accept, read during a previous connection. Nothing here opens a new connection or changes anything.

Get-JIMConnectedSystemPasswordPolicy -Id 3
Get-JIMConnectedSystem -Id 3 | Get-JIMConnectedSystemPasswordPolicy
Property Type Description
discovered datetime? When JIM last read this from the system
minimumLength int? The shortest password the system will accept
complexityRequired bool? Whether the system enforces a complexity rule
requiredCharacterClassCount int? How many character categories a password must draw on
recognisedCharacterClasses string[] The categories this system counts towards that rule
passwordHistoryLength int? How many previous passwords it remembers and refuses
maximumPasswordAgeDays int? How long a password may live
minimumPasswordAgeDays int? How soon it may be changed again
policyOverrideSignal string Absent, Present or CouldNotDetermine: whether some accounts may be governed by a policy other than this one
furtherChecksApply bool Whether the directory applies checks JIM cannot see, such as a dictionary check, so a password satisfying every figure can still be refused
discoveryOutcome string? Read, NotPublished, ConfigurationNotReadable or NoPolicyConfigured; $null when nothing has been read yet
hasAnyDiscoveredConstraint bool Whether JIM discovered anything at all

A null means JIM could not read that rule, not that no such rule exists

A directory withholds what a caller may not see by omitting it rather than refusing, so a null minimum length does not mean any length is acceptable. Check hasAnyDiscoveredConstraint before treating the figures as a description of what the system will accept. Where policyOverrideSignal is Present or CouldNotDetermine, the figures are a floor rather than a guarantee, because some accounts may be governed by a stricter policy (Active Directory's Fine-Grained Password Policies, OpenLDAP's per-entry policy subentries, 389 Directory Server's subtree policies). Where nothing was discovered, discoveryOutcome says why, and whether there is anything to do about it: NotPublished means the directory has nothing to read, ConfigurationNotReadable means the account JIM connects as needs read access to the server configuration.

Get-JIMConnectedSystemPasswordSynchronisation

Reports whether a Connected System receives synchronised passwords, and the settings governing how hard JIM tries to deliver them. A system that has never been configured is reported with configured set to $false and JIM's defaults in the remaining fields, so a script comparing systems does not have to special-case the untouched ones.

Get-JIMConnectedSystemPasswordSynchronisation -Id 3
Get-JIMConnectedSystem -Id 3 | Get-JIMConnectedSystemPasswordSynchronisation
Property Type Description
configured bool Whether Password Synchronisation has been configured here at all
connectorSupportsPasswordSet bool Whether this Connector can set passwords; $false means it cannot be configured
enabled bool Whether queued password changes are delivered
targetObjectTypeId int The Connected System Object Type that receives passwords
targetObjectTypeName string Its name
maxRetries int Attempts before a change is parked; 0 means use JIM's default
effectiveMaxRetries int The retry count actually applied
retryBackoffBase timespan The first retry interval; 0 means use JIM's default
effectiveRetryBackoffBase timespan The backoff base actually applied
requireSecureTransport bool Whether an unconfirmed-encryption connection is refused. Reported here, set on the Connected System with Set-JIMConnectedSystem
effectiveTimeToLive timespan How long a queued change waits before JIM expires it

Auditing which systems are switched on:

Get-JIMConnectedSystem -All | ForEach-Object {
    $p = Get-JIMConnectedSystemPasswordSynchronisation -Id $_.Id
    [PSCustomObject]@{ System = $_.Name; Configured = $p.configured; Enabled = $p.enabled }
}

Set-JIMConnectedSystemPasswordSynchronisation

Creates or updates the configuration. Omitted parameters leave the stored value unchanged; -TargetObjectType is required when creating one.

# Stage the configuration without switching it on
Set-JIMConnectedSystemPasswordSynchronisation -Id 3 -TargetObjectType 7 -Enabled $false

# Switch it on during the change window, delivering everything queued while it was off
Set-JIMConnectedSystemPasswordSynchronisation -Id 3 -Enabled $true -ChangeReason 'CHG0041288'

# Allow ten attempts before a change is parked
Set-JIMConnectedSystemPasswordSynchronisation -Id 3 -MaxRetries 10 -PassThru
Parameter Type Description
-Id int The Connected System (required; also accepts a Connected System from the pipeline as -InputObject)
-Enabled bool Whether to deliver queued password changes. Enabling delivers what accumulated while it was off
-TargetObjectType int The Object Type that receives passwords; must be selected for synchronisation. Alias: -TargetObjectTypeId
-MaxRetries int Attempts before parking a change; 0 uses JIM's default
-RetryBackoffBase timespan The first retry interval; 0 uses JIM's default
-ChangeReason string Recorded against the Connected System's configuration change history
-PassThru switch Return the updated configuration

Require Secure Transport is set on the Connected System

It governs every password JIM sends to the system, not only synchronised ones, so it is set with Set-JIMConnectedSystem -Id 3 -RequireSecureTransport and turned off with -RequireSecureTransport:$false. It is reported here as well, because it governs this feature too.

There is no Remove cmdlet, and that is deliberate

Removing a configuration would discard every password change queued against it. Disabling it keeps them, and is reversible, so -Enabled $false is the supported way to stop delivery.

Stranded-value sweep (ById only)

Whether a stranded-value sweep is armed following a Connector Space clear, and what it is waiting for. See Clearing the connector space.

Property Type Description
StrandedValueSweepArmedAt datetime? When the Connector Space was last cleared, or $null if no sweep is armed
LastSuccessfulFullImportCompletedAt datetime? When the most recent Full Import of this Connected System completed successfully, or $null if none ever has

The sweep runs at the first Full Synchronisation after LastSuccessfulFullImportCompletedAt is later than StrandedValueSweepArmedAt. A Full Synchronisation run before that leaves the arming in place and states so on its Activity.

Find systems with a stranded-value sweep waiting on a Full Import
Get-JIMConnectedSystem |
    ForEach-Object { Get-JIMConnectedSystem -Id $_.Id } |
    Where-Object {
        $_.StrandedValueSweepArmedAt -and
        (-not $_.LastSuccessfulFullImportCompletedAt -or $_.LastSuccessfulFullImportCompletedAt -le $_.StrandedValueSweepArmedAt)
    } |
    Select-Object Name, StrandedValueSweepArmedAt, LastSuccessfulFullImportCompletedAt

Check IsDeterminable before treating HasPendingChanges as false

HasPendingChanges is also $false when JIM cannot tell: when the Connected System has never completed a Full Synchronisation, and when configuration change tracking is switched off. Scripts that gate a run on -not $_.ConfigurationDrift.HasPendingChanges will skip those systems silently. Test IsDeterminable first.

Preview the impact of deleting a Connected System
Get-JIMConnectedSystem -Id 3 -DeletionPreview

New-JIMConnectedSystem

Creates a new Connected System.

Syntax

New-JIMConnectedSystem [-Name] <string> -ConnectorDefinitionId <int>
    [-Description <string>] [-ChangeReason <string>] [-PassThru]

Parameters

Name Type Required Default Description
Name string Yes (Position 0) Display name for the Connected System
ConnectorDefinitionId int Yes Identifier of the connector definition to use
Description string No Optional description
ChangeReason string No Optional reason ("commit message") recorded with this change and shown in the configuration change history. Maximum 2000 characters.
PassThru switch No $false Returns the created Connected System Object

Output

When -PassThru is specified, returns the newly created Connected System Object. Otherwise, no output.

Examples

Create a Connected System
New-JIMConnectedSystem -Name "Active Directory" -ConnectorDefinitionId 1
Create and capture the result
$cs = New-JIMConnectedSystem "HR Database" -ConnectorDefinitionId 2 -Description "Primary HR source" -PassThru

Notes

  • Supports ShouldProcess (Medium impact). Use -WhatIf or -Confirm to preview or prompt before creation.

Set-JIMConnectedSystem

Updates the configuration of an existing Connected System.

Syntax

# ById (default)
Set-JIMConnectedSystem -Id <int> [-Name <string>] [-Description <string>]
    [-SettingValues <hashtable>] [-MaxExportParallelism <int>]
    [-RequireSecureTransport] [-InitialPasswordTimeToLive <timespan>]
    [-UnresolvedReferenceHandling <string>] [-PassThru]

# ByInputObject
Set-JIMConnectedSystem -InputObject <PSCustomObject> [-Name <string>]
    [-Description <string>] [-SettingValues <hashtable>]
    [-MaxExportParallelism <int>] [-RequireSecureTransport]
    [-InitialPasswordTimeToLive <timespan>] [-UnresolvedReferenceHandling <string>]
    [-ChangeReason <string>] [-PassThru]

Parameters

Name Type Required Default Description
Id int Yes (ById) Connected System identifier
InputObject PSCustomObject Yes (ByInputObject) Connected System Object from the pipeline
Name string No New display name
Description string No New description
SettingValues hashtable No Connector-specific settings. Keys are setting IDs; values are hashtables with stringValue, intValue, or checkboxValue.
MaxExportParallelism int No Maximum number of parallel export threads (1 to 16). Leave unset to let the connector recommend a conservative value (the LDAP Connector recommends 2 for capable directories, those tuned to a high Export Concurrency); JIM stays sequential (1) if the connector offers no recommendation. An explicitly set value always takes precedence.
RequireSecureTransport switch No $false Refuse to send a password to this Connected System over a connection JIM cannot confirm is encrypted. Governs every password JIM sends here: the first password on a Connected System Object it provisions, one set by hand, and a synchronised password change. Nothing is discarded when JIM refuses; queued changes wait and Connected System Objects stay owed their first password. Turn it off with -RequireSecureTransport:$false. See Passwords.
InitialPasswordTimeToLive timespan No 7 days How long a Connected System Object provisioned into this Connected System stays owed an initial password before JIM records an expiry and stops trying. Raise it ahead of a planned outage longer than the current window; Connected System Objects provisioned meanwhile otherwise expire without a password. See Passwords.
UnresolvedReferenceHandling string No Error How import-time reference values that cannot be resolved to a Connected System Object are treated: Error, Warn, or Ignore. See Unresolved reference handling.
ChangeReason string No Optional reason ("commit message") recorded with this change and shown in the configuration change history. Maximum 2000 characters.
PassThru switch No $false Returns the updated Connected System Object

Output

When -PassThru is specified, returns the updated Connected System Object. Otherwise, no output.

Examples

Rename a Connected System
Set-JIMConnectedSystem -Id 3 -Name "AD Production"
Update connector settings
Set-JIMConnectedSystem -Id 3 -SettingValues @{
    1 = @{ stringValue = "ldaps://dc01.example.com" }
    2 = @{ intValue = 636 }
    3 = @{ checkboxValue = $true }
}
Pipeline input from Get-JIMConnectedSystem
Get-JIMConnectedSystem -Id 3 | Set-JIMConnectedSystem -MaxExportParallelism 8 -PassThru
Update a setting and record why (shown in the change history)
Set-JIMConnectedSystem -Id 3 -Description "Point at DR domain controller" -ChangeReason "Failover for DC maintenance (CHG0101)"

Notes

  • Supports ShouldProcess (Medium impact). Use -WhatIf or -Confirm to preview or prompt before changes.

Remove-JIMConnectedSystem

Deletes a Connected System and all its associated data.

Syntax

# ById (default)
Remove-JIMConnectedSystem -Id <int> [-DeleteImmediately] [-ChangeReason <string>]
    [-PreviewActivityId <guid>] [-PassThru] [-Force]

# ByInputObject
Remove-JIMConnectedSystem -InputObject <PSCustomObject> [-DeleteImmediately] [-ChangeReason <string>]
    [-PreviewActivityId <guid>] [-PassThru] [-Force]

Parameters

Name Type Required Default Description
Id int Yes (ById) Connected System identifier. Accepts pipeline input by property name.
InputObject PSCustomObject Yes (ByInputObject) Connected System object from the pipeline
DeleteImmediately switch No $false Deletes immediately and keeps the attribute values the system contributed, instead of deprovisioning through synchronisation. The kept values lose their provenance, so nothing can ever recall them, and downstream systems are not corrected.
ChangeReason string No Reason for the deletion, recorded on its Activity and on the configuration change history tombstone
PreviewActivityId guid No The deletion preview this deletion was made after reading, as returned by New-JIMConfigurationChangePreview -ConnectedSystemId <id> -Deletion. Recorded on the deletion's Activity. JIM refuses the deletion, deleting nothing, when the id is not a deletion preview of this same Connected System.
PassThru switch No $false Returns the deletion result for a deletion that completes immediately
Force switch No $false Suppresses the confirmation prompt, and the lookup of headline counts the prompt uses

By default the deletion deprovisions the system through synchronisation: the system is fenced and a background run takes every Connected System Object through the same obsoletion a synchronisation disconnect would, so other systems take over the values they also contribute, values nothing else contributes are cleared, Deletion Rules are evaluated, and corrections are staged for the other Connected Systems, before the system itself is deleted. To see all of that before it happens, run New-JIMConfigurationChangePreview -Deletion first and pass its ActivityId to -PreviewActivityId.

If a deprovisioning run fails partway, the system stays fenced (its Status remains Deleting). Running the cmdlet again retries the run from its checkpoint; running it with -DeleteImmediately finishes the deletion immediately, abandoning the remaining deprovisioning work.

Output

When the deletion queues (always the case by default), returns a tracking object:

Property Description
ActivityId The deletion Activity's id; monitor it with Get-JIMActivity
WorkerTaskId The queued Worker Task's id
Outcome QueuedAsBackgroundJob, or QueuedAfterSync when a running synchronisation delays it
ConnectedSystemObjectCount, ContributedValueCount, ContributedValueObjectCount Headline counts from the deletion's impact summary, or $null when -Force skipped the lookup

When an immediate deletion completes synchronously, nothing is returned unless -PassThru is specified, in which case the deletion result (Outcome, ActivityId) is returned.

Examples

Deprovision a Connected System with confirmation
Remove-JIMConnectedSystem -Id 3
Preview the deletion, then delete and record the preview
$preview = New-JIMConfigurationChangePreview -ConnectedSystemId 3 -Deletion -Wait
$preview.ImpactCounts | Format-Table TransitionType, ObjectCount
Remove-JIMConnectedSystem -Id 3 -PreviewActivityId $preview.ActivityId -ChangeReason "Decommissioned (CHG0123)"
Deprovision without confirmation and follow the run
$tracking = Remove-JIMConnectedSystem -Id 3 -Force
Get-JIMActivity -Id $tracking.ActivityId
Delete immediately, keeping the values the system contributed
Remove-JIMConnectedSystem -Id 3 -DeleteImmediately -Force
Delete every Connected System matching a name pattern, immediately
# -Name supports wildcards, so this deletes ALL matching Connected Systems and
# their connector spaces. Run it without -Force first to confirm the matches.
Get-JIMConnectedSystem -Name "Decommissioned*" | Remove-JIMConnectedSystem -DeleteImmediately -Force

Notes

  • Supports ShouldProcess (High impact). Without -Force, you will be prompted for confirmation, and the prompt states the headline impact of the chosen mode.
  • Deprovisioning always runs as a background job. An immediate deletion of a small Connected System (fewer than 1,000 objects) completes straight away; a larger one is queued as a background job.

Import-JIMConnectedSystemSchema

Imports (or re-imports) the schema from the connected data source. This discovers available object types and attributes.

Syntax

# ById (default)
Import-JIMConnectedSystemSchema -Id <int> [-Preview] [-DisableDependents] [-RemoveDependents] [-PassThru]

# ByInputObject
Import-JIMConnectedSystemSchema -InputObject <PSCustomObject> [-Preview] [-DisableDependents] [-RemoveDependents] [-PassThru]

Parameters

Name Type Required Default Description
Id int Yes (ById) Connected System identifier
InputObject PSCustomObject Yes (ByInputObject) Connected System Object from the pipeline
Preview switch No $false Retrieves the schema and returns what a refresh would change, without persisting anything
DisableDependents switch No $false Applies the refresh and disables everything it invalidated: Synchronisation Rules bound to a removed object type and mappings reading a removed or redefined attribute, each with a recorded reason. Preview first; the preview's Dependents property names what this disables. Cannot be combined with RemoveDependents
RemoveDependents switch No $false Applies the refresh and removes everything it invalidated. This deletes configuration and identity data: the named Synchronisation Rules and mappings are deleted, and a background worker task marks every Connected System Object of a removed object type Obsolete (deprovisioning through the standard pipeline) and deletes every stored value of a removed attribute. Always preview first; the preview's Dependents and RemovalImpact properties show exactly what this takes. Cannot be combined with DisableDependents
PassThru switch No $false Returns the Connected System Object after schema import (not needed with -Preview, which always returns its result)

Output

With -Preview, returns the preview result: Success, HasChanges, HasRemovalsOrDefinitionChanges, Dependents (what the destructive changes invalidate: InvalidatedSyncRules, InvalidatedMappings and ReferencedObjectMatchingRules, each entry carrying its Reason, plus DependentDerivedFlows, the Attribute Flows deriving Metaverse attributes that disabling or removing them would leave with a missing input), RemovalImpact (what committing with RemoveDependents would take: RemovedObjectTypes with a ConnectedSystemObjectCount each, and RemovedAttributes with a StoredValueCount each), AddedObjectTypes, RemovedObjectTypes, UpdatedObjectTypes, AddedAttributes, RemovedAttributes, ChangedAttributes (attribute definition changes: name, aspect, old and new value), AttributesInUse, BlockedCredentialAttributes, DiscoveryWarnings and PasswordPolicyDiscovered. Otherwise, when -PassThru is specified, returns the Connected System Object; without it, no output. Its DependentDerivedFlows is empty unless -DisableDependents or -RemoveDependents left an Attribute Flow deriving a Metaverse attribute with a missing input. Those flows are written with Write-Warning either way, worded as a prediction for -Preview; see Derived Attribute Flow warnings.

Examples

Import schema for a Connected System
Import-JIMConnectedSystemSchema -Id 3
Preview a refresh, then apply only when nothing was removed or redefined
$preview = Import-JIMConnectedSystemSchema -Id 3 -Preview
if (-not $preview.HasRemovalsOrDefinitionChanges) {
    Import-JIMConnectedSystemSchema -Id 3 -Confirm:$false
}
Apply a destructive refresh with its dependents disabled
$preview = Import-JIMConnectedSystemSchema -Id 3 -Preview
$preview.Dependents.InvalidatedSyncRules | Select-Object SyncRuleName, Reason
Import-JIMConnectedSystemSchema -Id 3 -DisableDependents -Confirm:$false
Apply a destructive refresh with its dependents removed, deleting the previewed configuration and data
# Inspect what the removal would delete before committing: every named rule and mapping is deleted,
# every counted object is obsoleted and deprovisioned, and every counted stored value is deleted.
$preview = Import-JIMConnectedSystemSchema -Id 3 -Preview
$preview.Dependents.InvalidatedSyncRules | Select-Object SyncRuleName, Reason
$preview.RemovalImpact.RemovedObjectTypes | Select-Object ObjectTypeName, ConnectedSystemObjectCount
$preview.RemovalImpact.RemovedAttributes | Select-Object AttributeName, StoredValueCount

Import-JIMConnectedSystemSchema -Id 3 -RemoveDependents
Get-JIMWorkerTask   # the data removal runs as a background worker task
Pipeline: create a system, then import its schema
New-JIMConnectedSystem "LDAP Directory" -ConnectorDefinitionId 1 -PassThru |
    Import-JIMConnectedSystemSchema -PassThru

Notes

  • A refresh never deletes on its own: additions and attribute definition updates are applied, while object types and attributes the Connected System no longer reports are retained in JIM and flagged in the result. Deletion only happens when you explicitly choose -RemoveDependents, and only across what the preview listed. See Refreshing the schema.
  • Check the preview's DiscoveryWarnings before applying: a partial schema read (for example, missing permissions) can make entries appear removed when they are not.
  • Schema import is required before creating Synchronisation Rules for a Connected System.
  • Supports ShouldProcess (Medium impact). -Preview bypasses it; a preview changes nothing, so there is nothing to confirm.

Import-JIMConnectedSystemHierarchy

Imports (or re-imports) the partition and container hierarchy from the connected data source.

Syntax

# ById (default)
Import-JIMConnectedSystemHierarchy -Id <int> [-PassThru]

# ByInputObject
Import-JIMConnectedSystemHierarchy -InputObject <PSCustomObject> [-PassThru]

Parameters

Name Type Required Default Description
Id int Yes (ById) Connected System identifier
InputObject PSCustomObject Yes (ByInputObject) Connected System Object from the pipeline
PassThru switch No $false Returns the Connected System Object after hierarchy import

Output

When -PassThru is specified, returns the Connected System Object. Otherwise, no output.

Examples

Import hierarchy
Import-JIMConnectedSystemHierarchy -Id 3
Pipeline: import schema, then hierarchy
Get-JIMConnectedSystem -Id 3 |
    Import-JIMConnectedSystemSchema |
    Import-JIMConnectedSystemHierarchy -PassThru

Notes

  • This operation is destructive: it replaces the existing partition and container configuration.
  • Supports ShouldProcess (Medium impact).

Get-JIMConnectedSystemServerCertificate

Reads the certificate the Connected System's server is presenting, without storing anything.

JIM connects to the endpoint the Connected System is configured for, purely to look at the certificate the server offers, and refuses the connection. The endpoint is always worked out by the Connected System's own connector from that system's settings; it is never named directly, so this cannot be used to make JIM connect to an address of your choosing.

Syntax

Get-JIMConnectedSystemServerCertificate -ConnectedSystemId <int> [-SettingValues <hashtable>]

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier. Accepts a Connected System from the pipeline.
SettingValues hashtable No Connectivity settings entered but not yet saved, keyed by Connector Definition Setting identifier.

Output

An object with a certificate property and a readAt timestamp. The certificate carries host, port, subject, issuer, subjectAlternativeNames, validFrom, validTo, thumbprint, signatureAlgorithm, isSelfSigned, issuerThumbprint, isIssuerCertificateAvailable, chain, isChainComplete, missingIssuer, rootThumbprint, rootSubject, failureReason and remediation.

chain lists the certificate chain JIM found, the server's own certificate first and the root (where JIM reached one) last. Each entry carries subject, issuer, thumbprint, validFrom, validTo, isCertificateAuthority, isSelfSigned, source and downloadedFrom. source is SentByServer, Downloaded (from the address in the certificate below it, given in downloadedFrom), JimCertificateStore or OperatingSystem. When JIM could not reach a root, isChainComplete is $false and missingIssuer names the certificate it could not find.

failureReason is one of None, UntrustedIssuer, NameMismatch, Expired, NotYetValid, NoCertificatePresented, InvalidChain or Unknown. Only UntrustedIssuer is fixed by trusting a certificate. InvalidChain means a certificate authority in the chain has expired, is not marked as one, or has a signature that does not verify, which has to be fixed on the server.

Examples

Read the certificate the configured server presents
Get-JIMConnectedSystemServerCertificate -ConnectedSystemId 42
Show the identifying details and which check it fails
Get-JIMConnectedSystemServerCertificate -ConnectedSystemId 42 |
    Select-Object -ExpandProperty certificate |
    Select-Object host, subject, thumbprint, failureReason
List the certificate chain and where each certificate came from
(Get-JIMConnectedSystemServerCertificate -ConnectedSystemId 42).certificate.chain |
    Format-Table subject, source, downloadedFrom
Read an endpoint that has been entered but not saved
Get-JIMConnectedSystemServerCertificate -ConnectedSystemId 42 -SettingValues @{ 40 = 'https://hr.corp.local/scim/v2' }

Notes

  • Why -SettingValues exists. JIM does not save settings that fail validation, and a certificate JIM does not trust is a validation failure. A Connected System being configured for the first time therefore has the address you typed and nothing in the database, so without these JIM would look at the endpoint last saved, or report that the system is not configured for an encrypted connection. Setting identifiers come from Get-JIMConnectorDefinition. The values are never persisted, and values for encrypted settings are ignored.
  • Reading stores nothing. Trusting the certificate is a separate call to Approve-JIMConnectedSystemServerCertificate.

Approve-JIMConnectedSystemServerCertificate

Trusts the certificate the Connected System's server is presenting, adding it to the Trusted Certificates store.

JIM reads the certificate from the server again, checks it against the thumbprint you supply, and adds it through the audited path, so the addition carries an Activity naming who trusted it and why.

Syntax

Approve-JIMConnectedSystemServerCertificate -ConnectedSystemId <int> -Thumbprint <string>
    [-ChangeReason <string>] [-SettingValues <hashtable>] [-PassThru]

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier. Accepts a Connected System from the pipeline.
Thumbprint string Yes The thumbprint being trusted, as read from the server: the server's own certificate, or any certificate in its chain. Spaces and colons between the pairs are ignored.
ChangeReason string No Reason recorded on the audit Activity. JIM records a sentence naming the Connected System when none is given.
SettingValues hashtable No Connectivity settings entered but not yet saved, keyed by Connector Definition Setting identifier.
PassThru switch No $false Returns the outcome, including the certificate as it now sits in the store.

Output

When -PassThru is specified, returns an object with outcome (Trusted, AlreadyTrusted, ThumbprintMismatch or InvalidChain), message, certificate, storedIntermediates, expectedThumbprint and presentedThumbprint. storedIntermediates lists any certificate authorities JIM downloaded and stored alongside the one you trusted, because the server does not send them. Otherwise, no output.

Examples

Trust the certificate you have checked
Approve-JIMConnectedSystemServerCertificate -ConnectedSystemId 42 -Thumbprint '7B44E1902CF6A83D5518BE7719A0C4D62F8E3B01'
Trust the root of the chain, rather than the server's own certificate
$reading = Get-JIMConnectedSystemServerCertificate -ConnectedSystemId 42
$reading.certificate.chain | Format-Table subject, source, downloadedFrom

Approve-JIMConnectedSystemServerCertificate -ConnectedSystemId 42 `
    -Thumbprint $reading.certificate.rootThumbprint `
    -ChangeReason 'Unblocking the HR Cloud connection test.'
Trust an endpoint that has been entered but not saved
Approve-JIMConnectedSystemServerCertificate -ConnectedSystemId 42 `
    -Thumbprint '7B44E1902CF6A83D5518BE7719A0C4D62F8E3B01' `
    -SettingValues @{ 40 = 'https://hr.corp.local/scim/v2' } -PassThru

Notes

  • Check the thumbprint against the server's administrator before running this. It is the only thing standing between an unattended script and trusting whatever is presented.
  • Any certificate in the chain works; the root lasts longest. JIM accepts the server when any certificate in its chain is in the Trusted Certificates store. rootThumbprint is populated when JIM reached the root, and trusting it survives the renewal of every certificate beneath it; trusting the server's own certificate has to be repeated at every renewal. Where isChainComplete is $false, trust the highest certificate JIM found, or add missingIssuer under Admin > Certificates. A self-signed certificate is its own root.
  • A changed certificate stops the action. If the server is presenting anything other than the thumbprint you named, nothing is trusted and the outcome is ThumbprintMismatch, with both values returned so you can compare them. Expected after a renewal; worth investigating otherwise.
  • Only an untrusted issuer is fixed by trusting a certificate. An expired certificate has to be renewed on the server, and a name mismatch means connecting by a name the certificate carries. A chain through a broken certificate authority is refused with InvalidChain and nothing is trusted.
  • Supports ShouldProcess.
  • Remove a certificate later with Remove-JIMCertificate.

Get-JIMConnectorDefinition

Retrieves available connector definitions, including their settings and capabilities.

Syntax

# List all (default)
Get-JIMConnectorDefinition

# By ID
Get-JIMConnectorDefinition -Id <int>

# By name (exact match)
Get-JIMConnectorDefinition -Name <string>

Parameters

Name Type Required Default Description
Id int Yes (ById) Connector definition identifier. Accepts pipeline input.
Name string Yes (ByName) Connector definition name. Must be an exact match.

Output

Connector definition objects including name, description, available settings, and supported capabilities (e.g. full import, delta import, export, hierarchy).

Examples

List all connector definitions
Get-JIMConnectorDefinition
Get a connector definition by name
Get-JIMConnectorDefinition -Name "CSV File"
Get a specific connector definition by ID
Get-JIMConnectorDefinition -Id 1
Find connectors that support delta import
# The list form returns headers, which carry no capability flags; fetch each
# definition by ID to see what it supports.
Get-JIMConnectorDefinition |
    ForEach-Object { Get-JIMConnectorDefinition -Id $_.Id } |
    Where-Object { $_.SupportsDeltaImport }

Get-JIMConnectedSystemObjectType

Retrieves the object types and their attributes for a Connected System.

Object Types the Connected System classified as internal (a directory's own configuration and operational classes) are omitted by default, matching what the portal's Schema tab shows. Pass -IncludeInternal to return them as well. An Object Type that is already selected is always returned, whatever its classification.

Syntax

Get-JIMConnectedSystemObjectType -ConnectedSystemId <int> [-IncludeInternal]

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier. Alias: Id. Accepts pipeline input by property name.
IncludeInternal switch No Off Also return Object Types the Connected System classified as internal.

Output

Object type definitions with their attributes, selection state, and external ID configuration.

Each Object Type also carries Tags, the classification key/value pairs the Connected System reported (for example class-kind = structural, visibility = internal), and IsInternal, derived from them.

Each attribute carries writability, one of Writable, ReadOnly or WritableOnCreate. See Attribute writability for what each one means for Attribute Flow.

Each attribute also carries required: whether the Connected System's schema demands it for the attribute's class (an RFC 4512 MUST). JIM refuses an export that would add a class whose required attributes have no value, so this is what to check when deciding which of a merged auxiliary class's attributes to flow. Read-only: discovered from the schema, never settable.

A Reference attribute additionally carries referencedObjectTypeId and referencedObjectTypeName when the Connected System's schema declares which Object Type the reference points at (the SQL Connector's referencesObjectType); import reference resolution then resolves the reference within that Object Type alone. Both are null when the schema does not say. Read-only: discovered from the schema, never settable.

Examples

Get object types for a Connected System
Get-JIMConnectedSystemObjectType -ConnectedSystemId 3
List the attributes JIM may only set when it creates the object
Get-JIMConnectedSystemObjectType -ConnectedSystemId 3 |
    ForEach-Object { $_.attributes } |
    Where-Object { $_.writability -eq 'WritableOnCreate' } |
    Select-Object name, type
Include the directory's own internal object types
Get-JIMConnectedSystemObjectType -ConnectedSystemId 3 -IncludeInternal
Pipeline from Get-JIMConnectedSystem
Get-JIMConnectedSystem -Id 3 | Get-JIMConnectedSystemObjectType
List selected object types only
Get-JIMConnectedSystem -Id 3 |
    Get-JIMConnectedSystemObjectType |
    Where-Object { $_.Selected }

Set-JIMConnectedSystemObjectType

Updates the configuration of an object type on a Connected System.

Syntax

Set-JIMConnectedSystemObjectType -ConnectedSystemId <int> -ObjectTypeId <int>
    [-Selected <bool>] [-RemoveContributedAttributesOnObsoletion <bool>] [-PassThru]

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier
ObjectTypeId int Yes Object type identifier. Alias: Id. Accepts pipeline input by property name.
Selected bool No Whether this object type is selected for synchronisation
RemoveContributedAttributesOnObsoletion bool No Whether to remove attributes contributed by this system when an object becomes obsolete
PassThru switch No $false Returns the updated object type

Output

When -PassThru is specified, returns the updated object type. Otherwise, no output.

Examples

Select an object type for synchronisation
Set-JIMConnectedSystemObjectType -ConnectedSystemId 3 -ObjectTypeId 1 -Selected $true
Take an object type out of management (obsoletes every object of that type on the next Full Import)
# Deselecting is refused while an enabled Synchronisation Rule is bound to the type, so disable those first.
# Run the first line without the final Set-JIMSyncRule stage to see which rules it would disable.
Get-JIMSyncRule -ConnectedSystemId 3 | Where-Object { $_.connectedSystemObjectTypeId -eq 2 } | Set-JIMSyncRule -Disable
Set-JIMConnectedSystemObjectType -ConnectedSystemId 3 -ObjectTypeId 2 -Selected $false

Deselecting an Object Type takes it out of management: the next Full Import marks every Connected System Object of that type obsolete, and the following synchronisation disconnects them from their Metaverse Objects, which may leave those eligible for deletion. Preview it first with New-JIMConfigurationChangePreview -ConnectedSystemId 3 -SchemaObjectType @(@{ objectTypeId = 2; selected = $false }) -Wait, and see What deselecting means.

Notes

  • Supports ShouldProcess (Medium impact).
  • Selecting an Object Type is refused, with the Connector's own message, when the Connected System's settings cannot serve it: for the JIM SQL Connector, selecting an Object Type that lacks a watermarkColumn or a changeLog while the matching Delta Import Mode is set.
  • Deselecting an Object Type is refused while an enabled Synchronisation Rule is bound to it; the error names the rules to disable. The same check refuses any update to an Object Type left deselected with an enabled rule still bound to it (possible in configurations saved before this check existed).

Set-JIMConnectedSystemAttribute

Updates the selection, external ID configuration and data type of attributes on a Connected System Object Type. Supports updating a single attribute or multiple attributes in bulk.

Syntax

# Single (default)
Set-JIMConnectedSystemAttribute -ConnectedSystemId <int> -ObjectTypeId <int>
    -AttributeId <int> [-Selected <bool>] [-IsExternalId <bool>]
    [-IsSecondaryExternalId <bool>] [-Type <string>] [-PassThru]

# Bulk
Set-JIMConnectedSystemAttribute -ConnectedSystemId <int> -ObjectTypeId <int>
    -AttributeUpdates <hashtable> [-PassThru]

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier
ObjectTypeId int Yes Object type identifier
AttributeId int Yes (Single) Attribute identifier. Alias: Id. Accepts pipeline input by property name.
Selected bool No (Single) Whether this attribute is selected for synchronisation
IsExternalId bool No (Single) Whether this attribute is the primary external identifier
IsSecondaryExternalId bool No (Single) Whether this attribute is a secondary external identifier
Type string No (Single) Overrides the data type schema discovery inferred. One of Text, Integer, LongNumber, Decimal, DateTime, Boolean, Reference, Guid, Binary. Integer is the friendly name for the Number type.
AttributeUpdates hashtable Yes (Bulk) Hashtable of updates. Keys are attribute IDs; values are hashtables with selected, isExternalId, and/or isSecondaryExternalId. A data type cannot be set in bulk.
PassThru switch No $false Returns the updated attribute(s)

-Type is accepted only where the Connector's schema cannot state a type definitively, which today means the JIM File Connector and the JIM SQL Connector. It is refused once the attribute is referenced by a Synchronisation Rule or holds values. See Attribute data types for when an override is needed and why.

Output

When -PassThru is specified, returns the updated attribute object(s). Otherwise, no output.

Examples

Select a single attribute
Set-JIMConnectedSystemAttribute -ConnectedSystemId 3 -ObjectTypeId 1 -AttributeId 5 -Selected $true
Mark an attribute as the primary external ID
Set-JIMConnectedSystemAttribute -ConnectedSystemId 3 -ObjectTypeId 1 -AttributeId 10 -IsExternalId $true
Correct the data type of an Oracle NUMBER column
# Oracle has one numeric type, so a NUMBER(10) employee identifier is read as a Long Number by default.
# Recording it as a whole number lets it flow into the built-in Employee Number Metaverse Attribute.
Set-JIMConnectedSystemAttribute -ConnectedSystemId 3 -ObjectTypeId 1 -AttributeId 5 -Type Integer
Bulk-update multiple attributes
Set-JIMConnectedSystemAttribute -ConnectedSystemId 3 -ObjectTypeId 1 -AttributeUpdates @{
    5  = @{ selected = $true }
    10 = @{ selected = $true; isExternalId = $true }
    12 = @{ selected = $true; isSecondaryExternalId = $true }
}

Notes

  • Supports ShouldProcess (Medium impact).
  • Only one attribute per object type can be the primary external ID. Setting IsExternalId on an attribute automatically clears it from the previous primary.

Get-JIMConnectedSystemPartition

Retrieves the partitions and their containers for a Connected System.

Syntax

Get-JIMConnectedSystemPartition -ConnectedSystemId <int>

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier. Alias: Id. Accepts pipeline input by property name.

Output

Partition objects with their container hierarchy and selection state.

Examples

Get partitions for a Connected System
Get-JIMConnectedSystemPartition -ConnectedSystemId 3
Pipeline from Get-JIMConnectedSystem
Get-JIMConnectedSystem -Id 3 | Get-JIMConnectedSystemPartition

Get-JIMConnectedSystemDirectoryServer

Discovers the domain controllers in a Connected System's directory, with the Active Directory Site each belongs to. Only Connected Systems using the LDAP connector against an Active Directory or Samba AD directory support this; other connectors, and non-AD-family LDAP directories (OpenLDAP, Generic), return an error naming why. Purely informational: it never writes anything. Aliased as Get-JIMConnectedSystemDomainController.

Syntax

Get-JIMConnectedSystemDirectoryServer -ConnectedSystemId <int>

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier. Alias: Id. Accepts pipeline input by property name.

Output

One object per discovered domain controller: hostName (its FQDN) and site (the Active Directory Site it belongs to, or $null for directories without Sites).

Examples

Discover domain controllers for a Connected System
Get-JIMConnectedSystemDirectoryServer -ConnectedSystemId 3
Filter to a specific Active Directory Site
Get-JIMConnectedSystemDirectoryServer -ConnectedSystemId 3 | Where-Object { $_.site -eq 'London' }
Pipeline from Get-JIMConnectedSystem
Get-JIMConnectedSystem -Name "Corp AD" | Get-JIMConnectedSystemDirectoryServer

Notes

  • This is a discovery aid, not a configuration write: use Set-JIMConnectedSystem to set the Preferred Domain Controller setting once you have chosen one.

Set-JIMConnectedSystemPartition

Updates the selection state of a partition on a Connected System.

Syntax

Set-JIMConnectedSystemPartition -ConnectedSystemId <int> -PartitionId <int>
    [-Selected <bool>] [-PassThru]

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier
PartitionId int Yes Partition identifier. Alias: Id. Accepts pipeline input by property name.
Selected bool No Whether this partition is selected for synchronisation
PassThru switch No $false Returns the updated partition

Output

When -PassThru is specified, returns the updated partition. Otherwise, no output.

Examples

Select a partition
Set-JIMConnectedSystemPartition -ConnectedSystemId 3 -PartitionId 1 -Selected $true
Deselect a partition
Set-JIMConnectedSystemPartition -ConnectedSystemId 3 -PartitionId 1 -Selected $false -PassThru

Notes

  • Supports ShouldProcess (Medium impact).

Set-JIMConnectedSystemContainer

Updates the selection state, exclusion and scope of a container within a partition.

Syntax

Set-JIMConnectedSystemContainer -ConnectedSystemId <int> -ContainerId <int>
    [-Selected <bool>] [-Excluded <bool>] [-Scope <string>] [-PassThru]

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier
ContainerId int Yes Container identifier. Alias: Id. Accepts pipeline input by property name.
Selected bool No Whether this container is selected for synchronisation
Excluded bool No Whether this container is carved out of a selection an ancestor made, leaving the objects within it deliberately unimported. Omit to leave the stored exclusion unchanged.
Scope string No How far beneath the container objects are imported from: Subtree or OneLevel. Omit to leave the stored scope unchanged.
PassThru switch No $false Returns the updated container

Output

When -PassThru is specified, returns the updated container. Otherwise, no output.

Examples

Select a container
Set-JIMConnectedSystemContainer -ConnectedSystemId 3 -ContainerId 7 -Selected $true
Select a container without its child containers
Set-JIMConnectedSystemContainer -ConnectedSystemId 3 -ContainerId 7 -Selected $true -Scope OneLevel
Widen an already selected container back to its whole subtree
Set-JIMConnectedSystemContainer -ConnectedSystemId 3 -ContainerId 7 -Scope Subtree
Exclude a container from the selection above it
Set-JIMConnectedSystemContainer -ConnectedSystemId 3 -ContainerId 12 -Excluded $true
Replace a selection with an exclusion
Set-JIMConnectedSystemContainer -ConnectedSystemId 3 -ContainerId 12 -Selected $false -Excluded $true
Hand an excluded container back into scope
Set-JIMConnectedSystemContainer -ConnectedSystemId 3 -ContainerId 12 -Excluded $false
Select multiple containers via pipeline
@(7, 8, 9) | ForEach-Object {
    Set-JIMConnectedSystemContainer -ConnectedSystemId 3 -ContainerId $_ -Selected $true
}

Notes

  • The parent partition must also be selected for container selection to take effect during import operations.
  • Scope defaults to Subtree on containers that have never had it set, which is how container selection behaved before the option existed.
  • Narrowing a container to OneLevel takes the objects beneath it out of scope, exactly as deselecting those containers would. The Connected System Objects already imported from them become obsolete on the next import.
  • Selected and Excluded are mutually exclusive: a container states one thing about itself. A request that would leave both set is rejected with a 400, whether it names both or names one against a stored other, so moving a container from a selection to an exclusion means setting both in the same call.
  • Excluding a container takes the objects within it, and within every container beneath it, out of scope. A container beneath an exclusion can be selected in its own right to bring that branch back, because whichever statement is nearest to an object decides its fate. See Excluding a Container.
  • Supports ShouldProcess (Medium impact).

Get-JIMConnectedSystemContainerScopeText

Reads a Connected System's Container Scope as text, one statement per line.

Syntax

Get-JIMConnectedSystemContainerScopeText -ConnectedSystemId <int>

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier. Accepts pipeline input by property name.

Output

A string: the Container Scope in canonical form, one statement per line, in hierarchy order. Empty where nothing is selected.

Text read here can be passed straight back to Set-JIMConnectedSystemContainerScopeText, which leaves the scope exactly as it was.

Examples

Read the Container Scope
Get-JIMConnectedSystemContainerScopeText -ConnectedSystemId 3
include OU=Corp,DC=example,DC=com
exclude OU=Service Accounts,OU=Corp,DC=example,DC=com
include OU=App1,OU=Service Accounts,OU=Corp,DC=example,DC=com
Save the Container Scope to a file
Get-JIMConnectedSystemContainerScopeText -ConnectedSystemId 3 | Set-Content ./scope.txt
Copy the Container Scope to another Connected System
Get-JIMConnectedSystemContainerScopeText -ConnectedSystemId 3 |
    Set-JIMConnectedSystemContainerScopeText -ConnectedSystemId 4

Notes

  • Every path is the Container's identifier in the Connected System's own terms, which for a directory is its Distinguished Name.
  • Copying a scope between Connected Systems requires the target to have discovered the same Containers; a path naming one it has not is refused.

Set-JIMConnectedSystemContainerScopeText

States a Connected System's whole Container Scope as text.

Syntax

Set-JIMConnectedSystemContainerScopeText -ConnectedSystemId <int> -Text <string> [-PassThru]

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier
Text string Yes The Container Scope to apply. Accepts pipeline input. Empty text clears every selection and exclusion.
PassThru switch No $false Returns the canonical text for the scope now in force

Each line is a directive, an optional one-level, then the Container's path:

Statement Means
include <path> Manage this Container and everything beneath it. + is accepted as shorthand.
include one-level <path> Manage the objects held directly in this Container, and no Container beneath it.
exclude <path> Carve this Container out of the selection an ancestor made. - is accepted as shorthand.
exclude one-level <path> Carve out the objects held directly in this Container only.

Blank lines and whole lines beginning with # are ignored.

Output

When -PassThru is specified, returns the canonical Container Scope text as a string. Otherwise, no output.

Examples

State a Container Scope with a carve-out and a re-inclusion
Set-JIMConnectedSystemContainerScopeText -ConnectedSystemId 3 -Text @"
include OU=Corp,DC=example,DC=com
exclude OU=Service Accounts,OU=Corp,DC=example,DC=com
include OU=App1,OU=Service Accounts,OU=Corp,DC=example,DC=com
"@
Apply a Container Scope held in a file
Get-Content ./scope.txt -Raw | Set-JIMConnectedSystemContainerScopeText -ConnectedSystemId 3
Manage only the objects held directly in a container
Set-JIMConnectedSystemContainerScopeText -ConnectedSystemId 3 -Text 'include one-level OU=Corp,DC=example,DC=com' -PassThru

Notes

  • The text states the whole of Container Scope rather than a change to it. A Container it does not name states nothing, so omitting a line is how a Container is deselected, and empty text clears the scope entirely.
  • Partition selection is left alone, except that naming a Container selects the partition holding it.
  • It is applied all-or-nothing. A path naming no Container, a Container named twice, and a statement an ancestor already makes are each refused with the line that caused them, and nothing is changed.
  • This is a synchronisation-affecting change: taking a Container out of scope obsoletes the objects imported through it on the next Full Import, and the synchronisation after that disconnects them. Preview it first with New-JIMConfigurationChangePreview.
  • Supports ShouldProcess (High impact), so it prompts before applying unless you pass -Confirm:$false.

Get-JIMConnectedSystemObject

Retrieves connector space objects (CSOs) from a Connected System, with support for paging and attribute value drill-down.

Syntax

# List (default)
Get-JIMConnectedSystemObject -ConnectedSystemId <int> [-Search <string>] [-Status <string>]
    [-ObjectTypeId <int>] [-JoinType <string>] [-SortBy <string>] [-Ascending]
    [-Page <int>] [-PageSize <int>]

# ListAll
Get-JIMConnectedSystemObject -ConnectedSystemId <int> -All [-Force] [-Search <string>] [-Status <string>]
    [-ObjectTypeId <int>] [-JoinType <string>] [-SortBy <string>] [-Ascending] [-PageSize <int>]

# ById
Get-JIMConnectedSystemObject -ConnectedSystemId <int> -Id <guid>

# AttributeValues
Get-JIMConnectedSystemObject -ConnectedSystemId <int> -Id <guid>
    -AttributeName <string> [-Search <string>] [-Page <int>] [-PageSize <int>]

# AttributeValuesAll
Get-JIMConnectedSystemObject -ConnectedSystemId <int> -Id <guid>
    -AttributeName <string> [-Search <string>] -All [-Force]

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier
Id guid Yes (ById/AttributeValues sets) Connector space object identifier
AttributeName string No Name of a multi-valued attribute to page through
Search string No Filter attribute values, or filter the object list by display name/external ID
Status string No Filter the object list by status: Normal, Obsolete, PendingProvisioning
ObjectTypeId int No Filter the object list by Connected System Object Type
JoinType string No Filter the object list by join type: NotJoined, Projected, Provisioned, Joined
SortBy string No Property name to sort the object list by
Ascending switch No $false Sort the object list ascending instead of the default descending
Page int No 1 Page number for paginated results
PageSize int No 50 Number of results per page (maximum 100)
All switch No $false Returns all objects, or all attribute values, auto-paginating. Fetches at most 1000 pages (~100,000 items at the default page size) and then stops with a warning; a warning is also emitted up front when the result set is large
Force switch No $false Override the -All 1000-page ceiling and fetch every page regardless of size. Only valid with -All

Output

  • List / ListAll: Lightweight headers for each Connected System Object matching the filters. Each row carries State, the derived connection state the portal's Connector Space list and a Metaverse Object's Connections tab both show: InSync, UpdatePending, ProvisioningExportPending, ProvisioningAwaitingConfirmation, ExportNotConfirmed, ExportFailed, DeletePending or Obsolete. It combines the object's own Status with any queued Pending Export, so Where-Object { $_.State -eq "ExportFailed" } finds the accounts a run could not write without reading the Pending Exports separately.
  • ById: A connector space object with its attributes and current values.
  • AttributeValues / AttributeValuesAll: Paged or complete list of values for the specified multi-valued attribute.

Examples

List objects in a Connected System
Get-JIMConnectedSystemObject -ConnectedSystemId 3
Find the objects whose export failed
Get-JIMConnectedSystemObject -ConnectedSystemId 3 -All |
    Where-Object { $_.State -eq "ExportFailed" }
Find Obsolete objects matching a search term
Get-JIMConnectedSystemObject -ConnectedSystemId 3 -Search "smith" -Status Obsolete
Get every object in a Connected System
Get-JIMConnectedSystemObject -ConnectedSystemId 3 -All
Get every object in a very large connector space, overriding the -All safety cap
# -All stops after 1000 pages (~100,000 objects) by default; -Force fetches everything up to the
# API's maximum retrieval depth of 1,000,000 rows.
Get-JIMConnectedSystemObject -ConnectedSystemId 3 -All -Force
Get a specific connector space object
Get-JIMConnectedSystemObject -ConnectedSystemId 3 -Id "a1b2c3d4-e5f6-7890-abcd-ef1234567890"
Page through a multi-valued attribute
Get-JIMConnectedSystemObject -ConnectedSystemId 3 -Id "a1b2c3d4-..." -AttributeName "member" -Page 2 -PageSize 25
Get all values of a multi-valued attribute
Get-JIMConnectedSystemObject -ConnectedSystemId 3 -Id "a1b2c3d4-..." -AttributeName "member" -All

Notes

  • Multi-valued attributes are capped at 10 values in the default detail response. Use the -AttributeName parameter to page through all values of a large multi-valued attribute.

Get-JIMConnectedSystemObjectChangeHistory

Retrieves the change history for a Connected System Object. Each record carries the initiator and Run Profile context, plus the per-attribute value changes, ordered by change time descending (most recent first).

Syntax

# Page (default)
Get-JIMConnectedSystemObjectChangeHistory -ConnectedSystemId <int> -Id <guid>
    [-Page <int>] [-PageSize <int>]

# All
Get-JIMConnectedSystemObjectChangeHistory -ConnectedSystemId <int> -Id <guid> -All [-Force] [-PageSize <int>]

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier. Accepts pipeline input by property name.
Id guid Yes Connector space object identifier. Accepts pipeline input by property name.
All switch No $false Automatically paginates through all results. Cannot be used with -Page. Fetches at most 1000 pages (~50,000 records at the default page size) and then stops with a warning; use -Force to fetch beyond the cap, up to the API's maximum retrieval depth of 1,000,000 rows.
Force switch No $false Override the -All 1000-page ceiling and fetch every page regardless of size. Only valid with -All.
Page int No 1 Page number for paginated results. Cannot be used with -All.
PageSize int No 50 Number of items per page. Maximum: 100.

Output

Returns one PSCustomObject per change record, including the initiator, Run Profile context, and per-attribute value changes. Each value change produced by an export carries SyncRuleId and SyncRuleName, naming the export Synchronisation Rule whose mapping produced that value; both are $null for import-side changes, or when the contributing rule has since been deleted.

Examples

Get the most recent page of changes
Get-JIMConnectedSystemObjectChangeHistory -ConnectedSystemId 3 -Id "a1b2c3d4-e5f6-7890-abcd-ef1234567890"
Page through all changes for a CSO
Get-JIMConnectedSystemObjectChangeHistory -ConnectedSystemId 3 -Id "a1b2c3d4-..." -All
Use a larger page size
Get-JIMConnectedSystemObjectChangeHistory -ConnectedSystemId 3 -Id "a1b2c3d4-..." -PageSize 100

Get-JIMConnectedSystemObjectAttributeValue

Pages through the values of a multi-valued attribute on a connector space object. This is the dedicated cmdlet for browsing large multi-valued attributes.

Syntax

# Page (default)
Get-JIMConnectedSystemObjectAttributeValue -ConnectedSystemId <int> -CsoId <guid>
    -AttributeName <string> [-Search <string>] [-Page <int>] [-PageSize <int>]

# All
Get-JIMConnectedSystemObjectAttributeValue -ConnectedSystemId <int> -CsoId <guid>
    -AttributeName <string> [-Search <string>] -All [-Force]

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier
CsoId guid Yes Connector space object identifier
AttributeName string Yes Name of the multi-valued attribute
Search string No Filter values by search term
Page int No 1 Page number
PageSize int No 50 Number of values per page (maximum 100)
All switch No $false Returns all values, auto-paginating. Fetches at most 1000 pages (~50,000 values at the default page size) and then stops with a warning; use -Force to fetch beyond the cap, up to the API's maximum retrieval depth of 1,000,000 rows.
Force switch No $false Override the -All 1000-page ceiling and fetch every page regardless of size. Only valid with -All.

Output

Attribute values for the specified multi-valued attribute, with paging metadata when not using -All.

Examples

Page through group members
Get-JIMConnectedSystemObjectAttributeValue -ConnectedSystemId 3 `
    -CsoId "a1b2c3d4-e5f6-7890-abcd-ef1234567890" `
    -AttributeName "member" -Page 1 -PageSize 100
Search within attribute values
Get-JIMConnectedSystemObjectAttributeValue -ConnectedSystemId 3 `
    -CsoId "a1b2c3d4-..." -AttributeName "member" -Search "admin"
Get all values at once
Get-JIMConnectedSystemObjectAttributeValue -ConnectedSystemId 3 `
    -CsoId "a1b2c3d4-..." -AttributeName "proxyAddresses" -All

Get-JIMConnectedSystemUnresolvedReferenceCount

Returns the count of unresolved references in a Connected System's connector space.

Syntax

Get-JIMConnectedSystemUnresolvedReferenceCount -ConnectedSystemId <int>

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier. Alias: Id. Accepts pipeline input by property name.

Output

An integer representing the number of unresolved references.

Examples

Check for unresolved references
Get-JIMConnectedSystemUnresolvedReferenceCount -ConnectedSystemId 3
Pipeline check across all systems
Get-JIMConnectedSystem | ForEach-Object {
    [PSCustomObject]@{
        Name  = $_.Name
        Unresolved = Get-JIMConnectedSystemUnresolvedReferenceCount -ConnectedSystemId $_.Id
    }
} | Where-Object { $_.Unresolved -gt 0 }

Notes

  • A non-zero count indicates data integrity issues in the connector space. This commonly occurs after a partial import. Running a full import typically resolves outstanding references.

Get-JIMConnectedSystemCapability

Retrieves the Connector-detected capabilities for a Connected System, e.g. an LDAP directory's type, vendor, DNS host name, and paging support. These are facts read from the target system during a previous connection and persisted by JIM; calling this cmdlet does not open a new connection.

Syntax

Get-JIMConnectedSystemCapability -ConnectedSystemId <int>

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier. Alias: Id. Accepts pipeline input by property name.

Output

Zero or more PSCustomObject instances, one per detected capability, each with Name and Value properties. Empty when the Connector does not detect any capabilities, or when nothing has been detected yet (for example, before the first successful connection).

Examples

Get the detected capabilities for a Connected System
Get-JIMConnectedSystemCapability -ConnectedSystemId 1
Get capabilities for a named Connected System via pipeline
Get-JIMConnectedSystem -Name "Active Directory" | Get-JIMConnectedSystemCapability

Notes

  • These facts mirror the Detected strip on the Connected System's Details tab in the portal; see the JIM LDAP Connector documentation for what each fact means.

Clear-JIMConnectedSystem

Removes all connector space objects (CSOs) and associated data from a Connected System without deleting the system itself. The Connected System configuration, schema, and Synchronisation Rules are preserved.

The clear runs as a queued background task, tracked by an Activity, exactly like the portal: the cmdlet returns as soon as the task is queued rather than running the deletion inline, so the operation is audited and trackable regardless of which surface started it. Use -Wait to block until it has finished.

Syntax

# ById (default)
Clear-JIMConnectedSystem -Id <int> [-KeepChangeHistory] [-Wait] [-Timeout <int>] [-Force]

# ByInputObject
Clear-JIMConnectedSystem -InputObject <PSCustomObject> [-KeepChangeHistory] [-Wait] [-Timeout <int>] [-Force]

Parameters

Name Type Required Default Description
Id int Yes (ById) Connected System identifier
InputObject PSCustomObject Yes (ByInputObject) Connected System Object from the pipeline
KeepChangeHistory switch No $false Preserves change history records; by default, change history is also deleted
Wait switch No $false Waits for the queued clear to finish before returning
Timeout int No Maximum seconds to wait when -Wait is supplied. Omit to wait indefinitely
Force switch No $false Suppresses the confirmation prompt

Output

A tracking object for the queued clear:

Property Type Description
ActivityId guid The clear Activity's id; monitor it with Get-JIMActivity
TaskId guid The queued Worker Task's id
Message string A human-readable confirmation naming the Connected System

Examples

Clear a Connected System with confirmation
Clear-JIMConnectedSystem -Id 3
Clear without confirmation, keeping history
Clear-JIMConnectedSystem -Id 3 -KeepChangeHistory -Force
Clear and wait for it to finish
Clear-JIMConnectedSystem -Id 3 -Force -Wait
Pipeline: clear a system by name
Get-JIMConnectedSystem -Name "Staging AD" | Clear-JIMConnectedSystem -Force

Notes

  • Supports ShouldProcess (High impact). Without -Force, you will be prompted for confirmation.
  • Removes all CSOs, attribute values, Pending Exports, and deferred references from the Connected System.
  • Metaverse Objects are not deleted by the clear itself; their links to this Connected System are severed.
  • By default, change history is also deleted. Use -KeepChangeHistory to retain it for auditing purposes.
  • Without -Wait, the cmdlet returns as soon as the clear is queued; a script that immediately re-imports, or reads the Connector Space back, races the clear task.
  • The clear records which Metaverse Objects were joined and arms the stranded-value sweep, which runs automatically at this Connected System's next Full Synchronisation once a Full Import has completed successfully: it recalls any Metaverse attribute value the system contributed whose object never returned, and applies that object type's Deletion Rule to objects that never returned. Run a Full Import before that synchronisation so objects that do return can reclaim their values and avoid the Deletion Rule firing on them. If far fewer objects return than were cleared, the sweep refuses rather than deleting most of the population; see Sync.PostClearReconciliation.MaxMissingPercent in Get-JIMServiceSetting. See Clearing the connector space.

Get-JIMPendingExport

Retrieves Pending Export operations queued for a Connected System.

Syntax

# List (default)
Get-JIMPendingExport -ConnectedSystemId <int> [-Search <string>]
    [-Page <int>] [-PageSize <int>]

# ListAll
Get-JIMPendingExport -ConnectedSystemId <int> [-Search <string>] -All [-Force]

# ById
Get-JIMPendingExport -Id <guid>

# AttributeChanges
Get-JIMPendingExport -Id <guid> -AttributeName <string>
    [-Search <string>] [-Page <int>] [-PageSize <int>]

# AttributeChangesAll
Get-JIMPendingExport -Id <guid> -AttributeName <string> [-Search <string>] -All [-Force]

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes (List, ListAll) Connected System identifier
Id guid Yes (ById, AttributeChanges, AttributeChangesAll) Pending Export operation identifier
AttributeName string No Name of a multi-valued attribute to page through its changes
Search string No Filter results by search term
Page int No 1 Page number
PageSize int No 50 Number of results per page (maximum 100)
All switch No $false Returns all results, auto-paginating. Fetches at most 1000 pages and then stops with a warning; use -Force to fetch beyond the cap, up to the API's maximum retrieval depth of 1,000,000 rows.
Force switch No $false Override the -All 1000-page ceiling and fetch every page regardless of size. Only valid with -All.

Output

  • List / ListAll: Pending Export operations with export type (Add, Update, Delete) and summary of changes.
  • ById: Detailed view of a single Pending Export, including all attribute changes. Each attribute change carries SyncRuleId and SyncRuleName, naming the export Synchronisation Rule whose mapping produced it; both are $null if the contributing rule has since been deleted. UnresolvedReferences lists each reference change not yet written (AttributeName, ReferencedMetaverseObjectId, ReferencedMetaverseObjectDisplayName) with its Reason: Resolvable (written on the next export run), AwaitingAnchor (the referenced object exists in this Connected System but has no anchor yet) or NotInTargetSystem (the referenced object has no Connected System Object in this Connected System). See Unresolved reference handling on export. ValueSources names where each attribute's queued value came from: ConnectedSystemAttributeId identifies the attribute, IsComputed is $true for an expression, chained mapping or generated value (Expression describes an expression or chained mapping; for a generated value IsGeneratedValue is $true and Expression is $null), and otherwise SourceMetaverseAttributeId/SourceMetaverseAttributeName name the single Metaverse attribute it was read from, with Origin (the same shape Get-JIMMetaverseObjectProvenance returns) giving that attribute's current source and HasSeveralOrigins flagging a multi-valued attribute whose values came from more than one source. There is no entry for an attribute whose export mapping cannot be resolved (its staging rule has since been deleted).
  • AttributeChanges / AttributeChangesAll: Paged or complete list of changes for a specific multi-valued attribute.

Examples

List Pending Exports for a Connected System
Get-JIMPendingExport -ConnectedSystemId 3
Search Pending Exports
Get-JIMPendingExport -ConnectedSystemId 3 -Search "jsmith" -PageSize 25
Get all Pending Exports
Get-JIMPendingExport -ConnectedSystemId 3 -All
View details of a specific Pending Export
Get-JIMPendingExport -Id "a1b2c3d4-e5f6-7890-abcd-ef1234567890"
Page through member additions on a group export
Get-JIMPendingExport -Id "a1b2c3d4-..." -AttributeName "member" -Page 1 -PageSize 100

Notes

  • For large multi-valued attribute changes (e.g. adding hundreds of members to a group), use the -AttributeName parameter to page through the individual changes rather than loading them all at once.

Get-JIMConnectedSystemDeletionPreview

Retrieves a preview of the impact of deleting a Connected System, including counts of affected objects and warnings.

Syntax

Get-JIMConnectedSystemDeletionPreview -ConnectedSystemId <int>

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier. Alias: Id. Accepts pipeline input by property name.

Output

A deletion impact preview object with counts of connector space objects, Pending Exports, Synchronisation Rules, and other dependent data that would be removed.

Examples

Preview deletion impact
Get-JIMConnectedSystemDeletionPreview -ConnectedSystemId 3
Pipeline: preview before deleting
Get-JIMConnectedSystem -Id 3 | Get-JIMConnectedSystemDeletionPreview
Check all systems for deletion impact
Get-JIMConnectedSystem | ForEach-Object {
    $preview = $_ | Get-JIMConnectedSystemDeletionPreview
    [PSCustomObject]@{
        Name = $_.Name
        CSOCount = $preview.ConnectedSystemObjectCount
        SyncRules = $preview.SyncRuleCount
    }
}

Set-JIMConnectedSystemObjectPassword

Sets the password on one Connected System Object.

The Connected System Object-scoped form of Set Password: the same operation as Set-JIMMetaverseObjectPassword with this one Connected System Object named, for scripts that hold the Connected System Object rather than the Metaverse Object. The change is queued, encrypted, and the Password Delivery Service writes it within about a second, whatever the synchronisation engine is doing; by default the command waits up to ten seconds and tells you what the Connected System Object did with the password. JIM holds the password only until the object has it; a password the system refused is kept, still encrypted, so JIM can finish the job once the cause is dealt with. Every attempt is recorded as an Activity, carrying the outcome and, where the system refused, its verbatim reason.

This is the automation counterpart of the Set Password action on a Connected System Object in the administration portal. The object must be joined to a Metaverse Object: a password belongs to a Metaverse Object, and that is where its history is kept. Supply the password with -Password, or have JIM generate one that follows the Connected System's discovered policy with -Generate. A generated password is returned to you, once, on GeneratedPassword.

Syntax

Set-JIMConnectedSystemObjectPassword -ConnectedSystemId <int> -Id <guid> -Password <securestring>
    [-ExpiryBehaviour <string>] [-EnableAccount] [-Wait <int>] [-Force]

Set-JIMConnectedSystemObjectPassword -ConnectedSystemId <int> -Id <guid> -Generate
    [-ExpiryBehaviour <string>] [-EnableAccount] [-Wait <int>] [-Force]

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier. Accepts a Connected System Object from the pipeline.
Id guid Yes Connected System Object identifier. Accepts a Connected System Object from the pipeline.
Password securestring Yes (unless -Generate) The password to set. Encrypted before JIM stores it and held only until delivered.
Generate switch Yes (unless -Password) Have JIM generate a password satisfying the policy it discovered on the Connected System.
ExpiryBehaviour string No RequireChangeAtNextSignIn RequireChangeAtNextSignIn, ExpiresAccordingToTargetPolicy or NeverExpires.
EnableAccount switch No $false Enables the account as part of setting the password. Omitting it leaves the account's enabled state untouched.
Wait int No 10 Seconds, 0 to 30, to wait for the account to answer. Pass 0 to return as soon as the change is recorded.
Force switch No $false Skips the confirmation prompt.

Output

One PSCustomObject in the same shape Set-JIMMetaverseObjectPassword returns, with one entry under Targets. No property carries the password you supplied.

Property Description
ActivityId The Activity recording the change. Its child Activity holds the account's outcome once delivery has been attempted.
Origin Always Explicit: the account was named.
Settled Whether the account had reached an outcome you need not wait on by the time the command returned.
Targets One entry, for this account's Connected System.
GeneratedPassword The password JIM produced, as a SecureString. Present only with -Generate.

The entry under Targets:

Property Description
ConnectedSystemId, ConnectedSystemName The Connected System.
ConnectedSystemObjectId The account.
Enabled Whether the system is currently taking propagated passwords. This account is delivered to either way.
State Queued, Delivering, Set, Retrying, Parked, Expired or Cancelled.
NextAttemptAt When the next attempt falls due, for a target that is Retrying; $null otherwise.
Message The system's own words on its most recent outcome, or $null before anything has been said.
AttemptCount How many delivery attempts this account has had.

A Parked target is also reported as a non-terminating error carrying the result as its TargetObject, so a script that stops on errors stops on a refusal. A target still in flight when the wait ran out is reported as a warning.

Examples

Set a password, requiring a change at the next sign-in
$password = Read-Host -AsSecureString "New password"
Set-JIMConnectedSystemObjectPassword -ConnectedSystemId 1 -Id 3f2a91c4-5b6d-4e7f-8a90-1b2c3d4e5f60 -Password $password
Set a password and enable the account, and see whether the directory took it
$password = Read-Host -AsSecureString "New password"
$result = Set-JIMConnectedSystemObjectPassword -ConnectedSystemId 1 -Id 3f2a91c4-5b6d-4e7f-8a90-1b2c3d4e5f60 -Password $password -EnableAccount -Force
$result.Targets[0] | Select-Object State, Message
Pipeline: set the password on a retrieved Connected System Object
$password = Read-Host -AsSecureString "New password"
Get-JIMConnectedSystemObject -ConnectedSystemId 1 -Id 3f2a91c4-5b6d-4e7f-8a90-1b2c3d4e5f60 |
    Set-JIMConnectedSystemObjectPassword -Password $password -ExpiryBehaviour NeverExpires

Notes

  • This resets the password on whichever account you point it at. Anyone who can call it can reset the password of any account in this connector space, subject only to what the Connected System's own service account is permitted to do.
  • The password is taken as a SecureString so it does not sit in your session's command history in clear text. It is unwrapped only to be sent over TLS.
  • A Connected System that cannot honour the requested expiry behaviour applies what it can and says so in the target's Message; the password is still set.
  • A system that refused the password parks it, with its own reason in Message. A system that could not be reached is Retrying, because nothing was established about the password itself; JIM tries again on its own clock, and nothing is lost while the system is down.
  • The account must be joined to a Metaverse Object. An unjoined object is reported as not found, with the remedy: join it first.
  • Routine initial passwords belong on the Synchronisation Rule that provisions the account; see Set-JIMSyncRuleInitialPassword.
  • Pass -Generate instead of -Password to have JIM produce a password satisfying the policy it discovered on the Connected System. Prefer this to inventing one in your own script: JIM knows what the target demands, and a hand-rolled generator rediscovers the passphrase trap, where three words offer two character categories against a directory that wants three. The generated password comes back on the result's GeneratedPassword property as a SecureString, and that is the only chance to capture it.
Set a compliant password without choosing one
$result = Set-JIMConnectedSystemObjectPassword -ConnectedSystemId 3 -Id $csoId -Generate -EnableAccount -Force
ConvertFrom-SecureString -SecureString $result.GeneratedPassword -AsPlainText

Get-JIMConnectedSystemAuxiliaryClass

Lists the auxiliary classes that can be merged into a Connected System Object Type, and which of them are merged already.

Merging an auxiliary class brings its attributes into the Object Type, so JIM can import and export them. See Auxiliary Object Classes for what this means on a directory.

Nothing is returned for an Object Type whose Connected System does not let JIM compose class membership (Active Directory resolves its own auxiliary classes into each structural class), or for an Object Type that is itself an auxiliary class.

Syntax

Get-JIMConnectedSystemAuxiliaryClass -ConnectedSystemId <int> -ObjectTypeId <int> [-MergedOnly] [-SuggestedOnly]

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier
ObjectTypeId int Yes Object Type identifier. Accepts pipeline input by property name
MergedOnly switch No $false Return only the classes currently merged into the Object Type
SuggestedOnly switch No $false Return only the classes something suggests

Output

One object per auxiliary class, ordered merged first, then suggested, then the rest by name.

Property Type Description
ObjectTypeId int The auxiliary class's own Object Type identifier, which is what merging is set by
Name string The class as the directory spells it
Merged bool Whether it is merged into this Object Type
ContributedAttributeCount int How many attributes merging it would contribute
ContributedAttributes object[] The attributes merging it would contribute, ordered by name. Each carries Name, Type, AttributePlurality, Required (the class's schema demands it) and IsCredential (JIM will never select it; passwords travel by the password channel)
PermittedByTheConnectedSystem bool A DIT Content Rule says it may attach here
EntriesObservedOn int? How many of the entries the last discovery run read carried it. $null when no run has observed it, which is different from 0
IsSuggested bool Whether either reason above applies

Examples

List every auxiliary class on offer
Get-JIMConnectedSystemAuxiliaryClass -ConnectedSystemId 1 -ObjectTypeId 5
Show only the classes JIM has a reason to suggest
Get-JIMConnectedSystemAuxiliaryClass -ConnectedSystemId 1 -ObjectTypeId 5 -SuggestedOnly |
    Format-Table Name, ContributedAttributeCount, EntriesObservedOn
See what merging a class would bring
(Get-JIMConnectedSystemAuxiliaryClass -ConnectedSystemId 1 -ObjectTypeId 5 |
    Where-Object Name -eq 'posixAccount').ContributedAttributes |
    Format-Table Name, Type, Required, IsCredential
Name what the Object Type carries today
Get-JIMConnectedSystemAuxiliaryClass -ConnectedSystemId 1 -ObjectTypeId 5 -MergedOnly |
    Select-Object -ExpandProperty Name

Set-JIMConnectedSystemAuxiliaryClass

Sets which auxiliary classes a Connected System Object Type carries.

Syntax

# Set (default)
Set-JIMConnectedSystemAuxiliaryClass -ConnectedSystemId <int> -ObjectTypeId <int> -AuxiliaryClassObjectTypeId <int[]> [-PassThru]

# Clear
Set-JIMConnectedSystemAuxiliaryClass -ConnectedSystemId <int> -ObjectTypeId <int> -Clear [-PassThru]

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier
ObjectTypeId int Yes Object Type the classes are merged into. Accepts pipeline input by property name
AuxiliaryClassObjectTypeId int[] Yes (Set) The auxiliary classes it should carry, by their own Object Type identifiers
Clear switch Yes (Clear) Withdraw every auxiliary class selection
PassThru switch No $false Returns the updated Object Type

Output

When -PassThru is specified, returns the updated Object Type. Its MergedAuxiliaryClassObjectTypeIds property lists what it now carries. Otherwise, no output.

Examples

Merge one auxiliary class
Set-JIMConnectedSystemAuxiliaryClass -ConnectedSystemId 1 -ObjectTypeId 5 -AuxiliaryClassObjectTypeId 12
Add a class to whatever is already merged
$merged = (Get-JIMConnectedSystemAuxiliaryClass -ConnectedSystemId 1 -ObjectTypeId 5 -MergedOnly).ObjectTypeId
Set-JIMConnectedSystemAuxiliaryClass -ConnectedSystemId 1 -ObjectTypeId 5 -AuxiliaryClassObjectTypeId ($merged + 12)
Withdraw every auxiliary class from an Object Type
Set-JIMConnectedSystemAuxiliaryClass -ConnectedSystemId 1 -ObjectTypeId 5 -Clear

Notes

  • This replaces the whole set, it does not add to it. A class that is merged and not named here is withdrawn. Read the current set first, as the second example does, when you mean to add one.
  • Withdrawing a class removes its attributes from the Object Type at the next schema import, which removes any Attribute Flow using them. Run Get-JIMConnectedSystemAuxiliaryClass -ConnectedSystemId <id> -ObjectTypeId <id> -MergedOnly and check what flows those attributes before clearing.
  • Merged attributes appear after the next Import-JIMConnectedSystemSchema.
  • Supports ShouldProcess (Medium impact).

Set-JIMConnectedSystemStructuralCarrierClass

Sets the Structural Carrier Class of an auxiliary Connected System Object Type: the structural class JIM writes alongside the auxiliary one when creating an entry.

Every entry in a directory carries exactly one structural class, so until a carrier is named JIM can import objects of the type but cannot create them.

Syntax

# Set (default)
Set-JIMConnectedSystemStructuralCarrierClass -ConnectedSystemId <int> -ObjectTypeId <int> -StructuralCarrierObjectTypeId <int> [-PassThru]

# Clear
Set-JIMConnectedSystemStructuralCarrierClass -ConnectedSystemId <int> -ObjectTypeId <int> -Clear [-PassThru]

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier
ObjectTypeId int Yes The auxiliary Object Type. Accepts pipeline input by property name
StructuralCarrierObjectTypeId int Yes (Set) The structural Object Type to write alongside it
Clear switch Yes (Clear) Clear the carrier, leaving the Object Type importable but not creatable
PassThru switch No $false Returns the updated Object Type

Output

When -PassThru is specified, returns the updated Object Type. Its StructuralCarrierObjectTypeId property names its carrier. Otherwise, no output.

Examples

Name the structural class to create objects as
Set-JIMConnectedSystemStructuralCarrierClass -ConnectedSystemId 1 -ObjectTypeId 12 -StructuralCarrierObjectTypeId 3
Find selected auxiliary Object Types JIM cannot yet create objects for
Get-JIMConnectedSystemObjectType -ConnectedSystemId 1 |
    Where-Object { $_.isAuxiliary -and $_.selected -and -not $_.structuralCarrierObjectTypeId } |
    Select-Object -Property id, name

Notes

  • Only an auxiliary Object Type takes a carrier, and only a structural Object Type in the same Connected System can be one. Anything else is refused with a message naming the problem.
  • Supports ShouldProcess (Medium impact).

Start-JIMConnectedSystemAuxiliaryClassDiscovery

Starts a run that reads a Connected System's entries to find which auxiliary classes they carry.

It changes no configuration: what an Object Type carries stays whatever an administrator has merged. The counts become suggestions on Get-JIMConnectedSystemAuxiliaryClass.

Syntax

Start-JIMConnectedSystemAuxiliaryClassDiscovery -ConnectedSystemId <int> -Scope <string> [-SampleSizePerObjectType <int>]

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier. Accepts pipeline input by property name
Scope string Yes QuickSample or FullScan
SampleSizePerObjectType int No 5000 Entries of each Object Type a quick sample reads. Ignored for a full scan

Output

Property Type Description
WorkerTaskId Guid The queued task, for cancelling the run
ActivityId Guid The Activity carrying the run's progress and outcome

Examples

Sample each Object Type
Start-JIMConnectedSystemAuxiliaryClassDiscovery -ConnectedSystemId 1 -Scope QuickSample
Read every entry in scope
Start-JIMConnectedSystemAuxiliaryClassDiscovery -ConnectedSystemId 1 -Scope FullScan
Start a larger sample and watch its Activity
$run = Start-JIMConnectedSystemAuxiliaryClassDiscovery -ConnectedSystemId 1 -Scope QuickSample -SampleSizePerObjectType 20000
Get-JIMActivity -Id $run.ActivityId

Notes

  • A quick sample cannot prove a class unused: a directory returns entries in its own order, so a rarely used class can be missed. Only a full scan's "not in use" means anything.
  • A full scan reads every entry in scope and can take a long time on a large directory. It requests class membership and nothing else.
  • One run at a time per Connected System. Starting a second while one is in progress is refused with a message saying so.
  • Supports ShouldProcess (Medium impact).

Get-JIMConnectedSystemAuxiliaryClassDiscovery

Gets the last auxiliary class discovery run for a Connected System, whatever its outcome. Returns nothing when none has been started.

Syntax

Get-JIMConnectedSystemAuxiliaryClassDiscovery -ConnectedSystemId <int>

Parameters

Name Type Required Default Description
ConnectedSystemId int Yes Connected System identifier. Accepts pipeline input by property name

Output

Property Type Description
Id int Run identifier
Scope string QuickSample or FullScan
SampleSizePerObjectType int? Entries per Object Type a quick sample read. $null for a full scan
Status string InProgress, Complete, Cancelled or Failed
Started DateTime When the run began
Completed DateTime? When it stopped, however it stopped. $null while it is still going
EntriesRead int How many entries were read
ActivityId Guid? The Activity carrying its progress and errors
InitiatedByName string Who asked for the run
ErrorMessage string Why it failed, when Status is Failed
Results object[] One per class observed, each with StructuralObjectTypeId, AuxiliaryClassName and EntryCount

Examples

Read the last run
Get-JIMConnectedSystemAuxiliaryClassDiscovery -ConnectedSystemId 1
Rank the classes the last run observed
(Get-JIMConnectedSystemAuxiliaryClassDiscovery -ConnectedSystemId 1).Results |
    Sort-Object -Property EntryCount -Descending |
    Format-Table AuxiliaryClassName, EntryCount

Notes

  • A cancelled run keeps the results it did gather. Those classes are genuinely in use; the ones it never reached are unknown.

See also

  • Connected Systems: what Connected Systems are, the connector space, partitions and containers, and common workflows
  • LDAP Connector: Auxiliary Object Classes: what merging an auxiliary class does on a directory, and how JIM composes each entry's class membership on export
  • Run Profiles: execute import, sync, and export operations on Connected Systems
  • Synchronisation Rules: define attribute mappings and scoping for Connected System synchronisation, including the initial password set on provisioned accounts
  • Connection: establish a session before using these cmdlets