Tutorial - Customize Microsoft Entra attribute mappings in Application Provisioning
In brief
The article now directs administrators to Manage > Attribute Mapping, with mappings organized by Users and Groups. It documents row-level edit and delete controls, group sync via Scoping filters, and the Advanced Options menu for custom attributes.
What Entra admins need to know
Update administrative procedures to use the new navigation and controls. The documented minimum role remains Application Administrator.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Editing user attribute-mappings
Follow these steps to access the MappingsAttribute Mapping feature of user provisioning:
Sign in to the Microsoft Entra admin center as at least an Application Administrator.
Browse to Entra ID > Enterprise apps.
A list of all configured apps is shown, including apps that were added from the gallery.
Select any app to load its app management pane, where you can view reports and manage app settings.
Select Provisioning to manage user account provisioning settings for the selected app.
ExpandUnderMappingsManage, select Attribute Mapping. The attribute mapping page displays a table of current mappings organized by object type (Users and Groups). The table shows the Source Attribute, Target Attribute, Mapping Type, and Matching Precedence for each mapping.To edit an existing mapping, select the pencil icon to
view and editthe right of the mapping row. The Edit Attribute screen opens, where you can modify the user attributes that flow between Microsoft Entra ID and the target application.If the target application supports it, this section lets you optionally configure provisioning of groups and user accounts.
SelectTo delete aMappingsconfigurationmapping, select the trash can icon toopentherelatedAttribute Mappingscreen. SaaS applications require certain attribute-mappings to function correctly.right of the mapping row. For required attributes, the Deletefeatureoption is unavailable.
Understanding attribute-mapping types

In this screenshot,Group provisioning can be optionally enabled or disabled by selecting the group mapping under Attribute Mapping, and setting Enabled to the option you can seewant. For apps that support group sync, enable or disable group sync by navigating to the UsernameScoping filters attributepage.
The attributes provisioned as part of Group objects can be customized in the same manner as User objects, described previously.
The user attributes supported for a managed object in Salesforce is populated withgiven application are preconfigured. Most application's user management APIs don't support schema discovery. So, the Microsoft Entra provisioning service isn't able to dynamically generate the list of supported attributes by making calls to the application.
However, some applications support custom attributes, and the Microsoft Entra provisioning service can read and write to custom attributes. To enter their definitions into the Microsoft Entra admin center, select the Select an existing Attribute Mapping to open the Edit Attribute screen. Here you can edit the user attributes that flow between Microsoft Entra ID and the target application.
Group provisioning can be optionally enabled or disabled by selecting the group mapping under Mappings, and setting Enabled to the option you want in the Attribute Mapping screen. The attributes provisioned as part of Group objects can be customized in the same manner as User objects, described previously. The user attributes supported for a given application are preconfigured. Most application's user management APIs don't support schema discovery. So, the Microsoft Entra provisioning service isn't able to dynamically generate the list of supported attributes by making calls to the application. However, some applications support custom attributes, and the Microsoft Entra provisioning service can read and write to custom attributes. To enter their definitions into the Microsoft Entra admin center, select the Show advanced options check box at the bottom of the Attribute Mapping screen, and then select Edit attribute list for your app. Applications and systems that support customization of the attribute list include:userPrincipalNameAdvanced Options valuedropdown menu at the top of the linked Microsoft Entra Object.Attribute Mapping page, and then select Edit target User attributes.
Understanding attribute-mapping types

@@ -2,7 +2,7 @@ title: Tutorial - Customize Microsoft Entra attribute mappings in Application Provisioning description: Learn about attribute mappings for Software as a Service (SaaS) apps in Microsoft Entra Application Provisioning. Learn what attributes are and how you can modify them to address your business needs. ms.topic: tutorial-ms.date: 03/04/2025+ms.date: 08/06/2026 ms.reviewer: arvinh ai-usage: ai-assisted ---@@ -25,29 +25,18 @@ You can customize the default attribute-mappings according to your business need ## Editing user attribute-mappings -Follow these steps to access the **Mappings** feature of user provisioning:+Follow these steps to access the **Attribute Mapping** feature of user provisioning: 1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Application Administrator](~/identity/role-based-access-control/permissions-reference.md#application-administrator). 1. Browse to **Entra ID** > **Enterprise apps**. 1. A list of all configured apps is shown, including apps that were added from the gallery. 1. Select any app to load its app management pane, where you can view reports and manage app settings. 1. Select **Provisioning** to manage user account provisioning settings for the selected app.-1. Expand **Mappings** to view and edit the user attributes that flow between Microsoft Entra ID and the target application. If the target application supports it, this section lets you optionally configure provisioning of groups and user accounts.+1. Under **Manage**, select **Attribute Mapping**. The attribute mapping page displays a table of current mappings organized by object type (**Users** and **Groups**). The table shows the **Source Attribute**, **Target Attribute**, **Mapping Type**, and **Matching Precedence** for each mapping. - +1. To edit an existing mapping, select the pencil icon to the right of the mapping row. The **Edit Attribute** screen opens, where you can modify the user attributes that flow between Microsoft Entra ID and the target application. -1. Select a **Mappings** configuration to open the related **Attribute Mapping** screen. SaaS applications require certain attribute-mappings to function correctly. For required attributes, the **Delete** feature is unavailable.-- -- In this screenshot, you can see that the **Username** attribute of a managed object in Salesforce is populated with the **userPrincipalName** value of the linked Microsoft Entra Object.- - > [!NOTE]- > Clearing **Create** doesn't affect existing users. If **Create** isn't selected, you can't create new users. --1. Select an existing **Attribute Mapping** to open the **Edit Attribute** screen. Here you can edit the user attributes that flow between Microsoft Entra ID and the target application.-- +2. To delete a mapping, select the trash can icon to the right of the mapping row. For required attributes, the **Delete** option is unavailable. ### Understanding attribute-mapping types @@ -97,7 +86,7 @@ A selected number of applications, such as ServiceNow, Box, and G Suite, support  -Group provisioning can be optionally enabled or disabled by selecting the group mapping under **Mappings**, and setting **Enabled** to the option you want in the **Attribute Mapping** screen.+Group provisioning can be optionally enabled or disabled by selecting the group mapping under **Attribute Mapping**, and setting **Enabled** to the option you want. For apps that support group sync, enable or disable group sync by navigating to the **Scoping filters** page. The attributes provisioned as part of Group objects can be customized in the same manner as User objects, described previously. @@ -108,7 +97,7 @@ The attributes provisioned as part of Group objects can be customized in the sam The user attributes supported for a given application are preconfigured. Most application's user management APIs don't support schema discovery. So, the Microsoft Entra provisioning service isn't able to dynamically generate the list of supported attributes by making calls to the application. -However, some applications support custom attributes, and the Microsoft Entra provisioning service can read and write to custom attributes. To enter their definitions into the Microsoft Entra admin center, select the **Show advanced options** check box at the bottom of the **Attribute Mapping** screen, and then select **Edit attribute list for** your app.+However, some applications support custom attributes, and the Microsoft Entra provisioning service can read and write to custom attributes. To enter their definitions into the Microsoft Entra admin center, select the **Advanced Options** dropdown menu at the top of the **Attribute Mapping** page, and then select **Edit target User attributes**. Applications and systems that support customization of the attribute list include: @@ -122,7 +111,7 @@ Applications and systems that support customization of the attribute list includ > [!NOTE]-> Editing the list of supported attributes is only recommended for administrators who have customized the schema of their applications and systems, and have first-hand knowledge of how their custom attributes have been defined or if a source attribute isn't automatically displayed in the Microsoft Entra admin center UI. This sometimes requires familiarity with the APIs and developer tools provided by an application or system. The ability to edit the list of supported attributes is locked down by default, but customers can enable the capability by navigating to the following URL: https://portal.azure.com/?Microsoft_AAD_Connect_Provisioning_forceSchemaEditorEnabled=true . You can then navigate to your application to view the [attribute list](#editing-the-list-of-supported-attributes). +> Editing the list of supported attributes is only recommended for administrators who have customized the schema of their applications and systems, and have first-hand knowledge of how their custom attributes have been defined or if a source attribute isn't automatically displayed in the Microsoft Entra admin center UI. This sometimes requires familiarity with the APIs and developer tools provided by an application or system. The ability to edit the list of supported attributes is locked down by default, but customers can enable the capability by navigating to the following URL: https://portal.azure.com/?Microsoft_AAD_Connect_Provisioning_forceSchemaEditorEnabled=true . You can then navigate to your application to view the [attribute list](#editing-the-list-of-supported-attributes). The **Advanced Options** dropdown on the **Attribute Mapping** page provides access to **Edit target User attributes** and **Edit schema**. > [!NOTE] > When a directory extension attribute in Microsoft Entra ID doesn't show up automatically in your attribute mapping drop-down, you can manually add it to the "Microsoft Entra attribute list". When manually adding Microsoft Entra directory extension attributes to your provisioning app, note that directory extension attribute names are case-sensitive. For example: If you have a directory extension attribute named `extension_53c9e2c0exxxxxxxxxxxxxxxx_acmeCostCenter`, make sure you enter it in the same format as defined in the directory. Provisioning multi-valued directory extension attributes is not supported. @@ -147,19 +136,18 @@ When you're editing the list of supported attributes, the following properties a #### Provisioning a custom extension attribute to a SCIM compliant application The SCIM Request for Comments (RFC) defines a core user and group schema, while also allowing for extensions to the schema to meet your application's needs. To add a custom attribute to a SCIM application:- 1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Application Administrator](~/identity/role-based-access-control/permissions-reference.md#application-administrator).+ 1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Application Administrator](~/identity/role-based-access-control/permissions-reference.md#application-administrator). 1. Browse to **Entra ID** > **Enterprise apps**. 1. Select your application, and then select **Provisioning**.- 1. Under **Mappings**, select the object (user or group) for which you'd like to add a custom attribute.- 1. At the bottom of the page, select **Show advanced options**.- 1. Select **Edit attribute list for AppName**.+ 1. Under **Manage**, select **Attribute Mapping**, and then select the object type (**Users** or **Groups**) for which you'd like to add a custom attribute.+ 1. Select the **Advanced Options** dropdown and then select **Edit target User attributes**. > [!NOTE] > If the **Edit attribute list for AppName** option doesn't appear, navigate to your application using the URL `https://portal.azure.com/?Microsoft_AAD_Connect_Provisioning_forceSchemaEditorEnabled=true` to enable the schema editor.-+ 1. At the bottom of the attribute list, enter information about the custom attribute in the fields provided. Then select **Add Attribute**. -For SCIM applications, the attribute name must follow the pattern shown in the example. The "CustomExtensionName" and "CustomAttribute" can be customized per your application's requirements, for example: urn:ietf:params:scim:schemas:extension:CustomExtensionName:2.0:User:CustomAttribute +For SCIM applications, the attribute name must follow the pattern shown in the example. The ```CustomExtensionName``` and ```CustomAttribute``` can be customized per your application's requirements, for example: ```urn:ietf:params:scim:schemas:extension:CustomExtensionName:2.0:User:CustomAttribute```. These instructions are only applicable to SCIM-enabled applications. Applications such as ServiceNow and Salesforce aren't integrated with Microsoft Entra ID using SCIM, and therefore they don't require this specific namespace when adding a custom attribute. @@ -462,7 +450,7 @@ Certain attributes such as phoneNumbers and emails are multi-value attributes wh ## Restoring the default attributes and attribute-mappings -Should you need to start over and reset your existing mappings back to their default state, you can select the **Restore default mappings** check box and save the configuration. Doing so sets all mappings and scoping filters as if the application was added to your Microsoft Entra tenant from the application gallery.+If you need to reset your mapping settings back to their default state, select **Attribute mapping** > **Restore default mappings** to restore and save the configuration. Doing so sets all mappings and scoping filters as if the application was added to your Microsoft Entra tenant from the application gallery. This will also restart synchronization. Selecting this option forces a resynchronization of all users while the provisioning service is running. 