Microsoft Entra ID
Provisioning

Tutorial - Customize Microsoft Entra attribute mappings in Application Provisioning

In brief

The article now directs administrators to Manage > Attribute Mapping, with mappings organized by Users and Groups. It documents row-level edit and delete controls, group sync via Scoping filters, and the Advanced Options menu for custom attributes.

What Entra admins need to know

Update administrative procedures to use the new navigation and controls. The documented minimum role remains Application Administrator.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Editing user attribute-mappings

Follow these steps to access the MappingsAttribute Mapping feature of user provisioning:

  1. Sign in to the Microsoft Entra admin center as at least an Application Administrator.

  2. Browse to Entra ID > Enterprise apps.

  3. A list of all configured apps is shown, including apps that were added from the gallery.

  4. Select any app to load its app management pane, where you can view reports and manage app settings.

  5. Select Provisioning to manage user account provisioning settings for the selected app.

  6. ExpandUnder MappingsManage, select Attribute Mapping. The attribute mapping page displays a table of current mappings organized by object type (Users and Groups). The table shows the Source Attribute, Target Attribute, Mapping Type, and Matching Precedence for each mapping.

  7. To edit an existing mapping, select the pencil icon to view and editthe right of the mapping row. The Edit Attribute screen opens, where you can modify the user attributes that flow between Microsoft Entra ID and the target application. If the target application supports it, this section lets you optionally configure provisioning of groups and user accounts.

    Use Mappings to view and edit user attributes

  8. SelectTo delete a Mappings configurationmapping, select the trash can icon to open the related Attribute Mapping screen. SaaS applications require certain attribute-mappings to function correctly.right of the mapping row. For required attributes, the Delete featureoption is unavailable.

Understanding attribute-mapping types

Use Attribute Mapping to configure attribute mappings for appsExample shows ServiceNow with provisioned Group and User objects

In this screenshot,Group provisioning can be optionally enabled or disabled by selecting the group mapping under Attribute Mapping, and setting Enabled to the option you can seewant. For apps that support group sync, enable or disable group sync by navigating to the UsernameScoping filters attributepage.

The attributes provisioned as part of Group objects can be customized in the same manner as User objects, described previously.

The user attributes supported for a managed object in Salesforce is populated withgiven application are preconfigured. Most application's user management APIs don't support schema discovery. So, the Microsoft Entra provisioning service isn't able to dynamically generate the list of supported attributes by making calls to the application.

However, some applications support custom attributes, and the Microsoft Entra provisioning service can read and write to custom attributes. To enter their definitions into the Microsoft Entra admin center, select the userPrincipalNameAdvanced Options valuedropdown menu at the top of the linked Microsoft Entra Object.Attribute Mapping page, and then select Edit target User attributes.

  1. Select an existing Attribute Mapping to open the Edit Attribute screen. Here you can edit the user attributes that flow between Microsoft Entra ID and the target application.

    Use Edit Attribute to edit user attributes

Understanding attribute-mapping types

Example shows ServiceNow with provisioned Group and User objects

Group provisioning can be optionally enabled or disabled by selecting the group mapping under Mappings, and setting Enabled to the option you want in the Attribute Mapping screen.

The attributes provisioned as part of Group objects can be customized in the same manner as User objects, described previously.

The user attributes supported for a given application are preconfigured. Most application's user management APIs don't support schema discovery. So, the Microsoft Entra provisioning service isn't able to dynamically generate the list of supported attributes by making calls to the application.

However, some applications support custom attributes, and the Microsoft Entra provisioning service can read and write to custom attributes. To enter their definitions into the Microsoft Entra admin center, select the Show advanced options check box at the bottom of the Attribute Mapping screen, and then select Edit attribute list for your app.

Applications and systems that support customization of the attribute list include:

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…