User Import from Target Systems
Nova imports existing user accounts straight from your target systems: Active Directory and other LDAP directories, Microsoft Entra ID, SAP, and Keycloak. The rollout thus starts from the accounts that already exist.
What the user import from target systems does
- Import jobs create missing Nova users from the system inventory and link existing users to their accounts.
- Matching against existing Nova users runs on configurable attributes: email address, username (uid), or cn.
- The LDAP import can read group memberships along with users and create groups in Nova that are not yet on record.
- The SAP import creates missing users, updates existing ones, can be narrowed with a username filter, and optionally reads role assignments.
- The Keycloak import distinguishes human users from AI agent identities and can be limited to enabled accounts.
- All imports run as background jobs in the central job system, with a traceable result log for every run.
Technical integration
Imports use the native connectors of each system: LDAP/LDAPS with bind authentication, the Microsoft Graph API with OAuth2 client credentials, the Keycloak Admin REST API with a service account, and SAP via RFC/BAPI. No agent software is installed in the target systems; everything runs over their standard interfaces.
In the identity lifecycle
User import brings your existing account inventory into Nova and is the starting point for recertification, reconciliation, and access requests across connected systems. Ongoing joiner, mover, and leaver processing is then driven by your connected HR source.
All product names, logos and brands mentioned are property of their respective owners. They are referenced solely to describe compatibility and do not imply any partnership or endorsement.