How to query ITIM for users who have not supplied challenge response info

Technote (FAQ)


Many organizations do not know who has or has not answered the ITIM User challenge response questions. In order to find out an ITIM LDAP administrator can query for all system users who have not answered the challenge response questions.


Use a LDAP query in the ITIM LDAP to find all users who have no entries for the following binary data. Query must be done at the ou=systemUsers,ou=ITIM,ou=<tenant>,<suffix> level.

The results will provide you a list when exported of system users who you can then notify to answer the challenge response questions.

Rate this page:

(0 users)Average rating

Document information

More support for:

IBM Security Identity Manager

Software version:

5.0, 5.1, 6.0

Operating system(s):

All Platforms

Software edition:

All Editions

Reference #:


Modified date:


Translate my page

Machine Translation

Content navigation