Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Identity Hub
  • Access management
  • Pricing policy
  • Terraform reference
    • Authentication
      • Overview
        • Overview
          • Overview
          • SetReplicationToken
          • ResetReplicationToken
          • GetReplicationToken
          • CreateSynchronizationSettings
          • UpdateSynchronizationSettings
          • DeleteSynchronizationSettings
          • GetSynchronizationSettings
          • ListSupportedAttributes
  • Audit Trails events
  • Release notes
  • Yandex Identity Hub Sync Agent release notes

In this article:

  • gRPC request
  • GetSynchronizationSettingsRequest
  • SynchronizationSettings
  • SynchronizationFilter
  • UserAttributeMapping
  • GroupAttributeMapping
  • LdapSettings
  1. API reference
  2. gRPC
  3. Identity Provider API
  4. Synchronization
  5. GetSynchronizationSettings

Identity Provider API, gRPC: SynchronizationService.GetSynchronizationSettings

Written by
Yandex Cloud
Updated at August 5, 2026
View in Markdown
  • gRPC request
  • GetSynchronizationSettingsRequest
  • SynchronizationSettings
  • SynchronizationFilter
  • UserAttributeMapping
  • GroupAttributeMapping
  • LdapSettings

Returns synchronization settings for a subject container.

gRPC requestgRPC request

rpc GetSynchronizationSettings (GetSynchronizationSettingsRequest) returns (SynchronizationSettings)

GetSynchronizationSettingsRequestGetSynchronizationSettingsRequest

{
  "subject_container_id": "string"
}

Request to get synchronization settings.

Field

Description

subject_container_id

string

Required field. ID of the subject container.

The maximum string length in characters is 50.

SynchronizationSettingsSynchronizationSettings

{
  "subject_container_id": "string",
  "filter": {
    "domain": "string",
    "groups": [
      "string"
    ],
    "organization_units": [
      "string"
    ]
  },
  "remove_user_behavior": "RemoveUserBehavior",
  "synchronization_interval": "google.protobuf.Duration",
  "allow_to_capture_users": "bool",
  "allow_to_capture_groups": "bool",
  "user_attribute_mappings": [
    {
      "source": "string",
      "target": "UserTargetAttribute",
      "type": "MappingType"
    }
  ],
  "group_attribute_mappings": [
    {
      "source": "string",
      "target": "GroupTargetAttribute",
      "type": "MappingType"
    }
  ],
  "created_at": "google.protobuf.Timestamp",
  "replacement_domain": "string",
  "enable_password_writeback": "bool",
  "ldap_settings": {
    "external_id_attribute": "string",
    "dn_attribute": "string",
    "user_object_class": "string",
    "group_object_class": "string",
    "account_disabled_attribute": "string",
    "account_disabled_value": "string",
    "account_enabled_value": "string",
    "password_attribute": "string",
    "delta_sync_mode": "LdapDeltaSyncMode",
    "use_recursive_membership_filter": "bool"
  }
}

Synchronization settings for a subject container.

Field

Description

subject_container_id

string

ID of the subject container.

filter

SynchronizationFilter

Filter configuration for synchronization.

remove_user_behavior

enum RemoveUserBehavior

Behavior when removing users.

  • REMOVE: Remove the user.
  • BLOCK: Block the user.

synchronization_interval

google.protobuf.Duration

Interval between synchronization runs.

allow_to_capture_users

bool

Whether users can be captured during synchronization.

allow_to_capture_groups

bool

Whether groups can be captured during synchronization.

user_attribute_mappings[]

UserAttributeMapping

User attribute mappings.

group_attribute_mappings[]

GroupAttributeMapping

Group attribute mappings.

created_at

google.protobuf.Timestamp

Timestamp when the settings were created.

replacement_domain

string

Domain replacement configuration.

enable_password_writeback

bool

Enables password writeback feature.

ldap_settings

LdapSettings

Settings for generic LDAP synchronization source.

Empty for Active Directory source. Required and fully populated for
generic LDAP source.

SynchronizationFilterSynchronizationFilter

Filter configuration for synchronization.

Field

Description

domain

string

Required field. Domain to synchronize.

The string length in characters must be 1-253.

groups[]

string

List of groups to synchronize.

The string length in characters for each value must be 1-253. The maximum number of elements is 10.

organization_units[]

string

List of organizational units to synchronize.

The string length in characters for each value must be 1-253. The maximum number of elements is 10.

UserAttributeMappingUserAttributeMapping

User attribute mapping configuration.

Field

Description

source

string

Source attribute name.

The string length in characters must be 0-253.

target

enum UserTargetAttribute

Required field. Target attribute to map to.

  • FULL_NAME: Full name attribute.
  • GIVEN_NAME: Given name attribute.
  • FAMILY_NAME: Family name attribute.
  • EMAIL: Email attribute.
  • PHONE_NUMBER: Phone number attribute.
  • USERNAME: Username attribute.
  • COMPANY_NAME: Company name attribute.
  • JOB_TITLE: Job title attribute.
  • DEPARTMENT: Department attribute.
  • EMPLOYEE_ID: Employee ID attribute.

type

enum MappingType

Required field. Type of mapping.

  • DIRECT: Direct mapping from source to target.
  • EMPTY: Empty mapping (no source attribute).
  • DIRECT_ARBITRARY_ATTRIBUTE: Direct mapping from an arbitrary source attribute

GroupAttributeMappingGroupAttributeMapping

Group attribute mapping configuration.

Field

Description

source

string

Source attribute name.

The string length in characters must be 0-253.

target

enum GroupTargetAttribute

Required field. Target attribute to map to.

  • NAME: Name attribute.
  • DESCRIPTION: Description attribute.

type

enum MappingType

Required field. Type of mapping.

  • DIRECT: Direct mapping from source to target.
  • EMPTY: Empty mapping (no source attribute).
  • DIRECT_ARBITRARY_ATTRIBUTE: Direct mapping from an arbitrary source attribute

LdapSettingsLdapSettings

Settings for generic LDAP synchronization source.

Field

Description

external_id_attribute

string

Name of the LDAP attribute that holds the unique entry identifier.

dn_attribute

string

Name of the LDAP attribute that holds the DN of the entry.

user_object_class

string

ObjectClass of users.

group_object_class

string

ObjectClass of groups.

account_disabled_attribute

string

Name of the LDAP attribute that stores the account status.

account_disabled_value

string

Value of account_disabled_attribute meaning the account is disabled.

account_enabled_value

string

Value of account_disabled_attribute meaning the account is enabled.

password_attribute

string

Name of the LDAP attribute the agent writes the new password to during
password writeback.

delta_sync_mode

enum LdapDeltaSyncMode

Delta synchronization mode.

  • LDAP_DELTA_SYNC_MODE_FULL_SYNC: Every run is a full sync; no replication token is used.

use_recursive_membership_filter

bool

Enables the AD-extension matching rule
1.2.840.113556.1.4.1941 for the group-DN membership filter.

Was the article helpful?

Previous
DeleteSynchronizationSettings
Next
ListSupportedAttributes
© 2026 Direct Cursus Technology L.L.C.