Attributes synchronized by Azure AD Connect - Microsoft Entra (2023)

  • Article

This topic lists the attributes that are synchronized by Azure AD Connect sync.
The attributes are grouped by the related Azure AD app.

Attributes to sync

A common question iswhat is the list of minimum attributes to sync. The default and recommended approach is to keep the default attributes so that a full GAL (Global Address List) can be built in the cloud and get all the features in Microsoft 365 workloads. In some cases, there are some attributes that your organization does not want synced to the cloud, as these attributes contain sensitive personal data, such as in this example:
Attributes synchronized by Azure AD Connect - Microsoft Entra (1)

In this case, start with the list of attributes in this topic and identify those attributes that would contain personal data and cannot be synced. Then deselect those attributes during installation usingAzure AD app and attribute filtering.

Warning

When deselecting attributes, be careful to deselect only those attributes that absolutely cannot be synchronized. Deselecting other attributes can have a negative impact on features.

Microsoft 365 Apps for enterprise

attribute nameUserRemark
accountEnabledXDefines whether an account is enabled.
cnX
Display nameX
objectSIDXmechanical property. AD user ID used to maintain synchronization between Azure AD and AD.
pwdLastSetXmechanical property. Used to know when to invalidate already issued tokens. Used by both password hash synchronization, pass-through authentication, and federation.
sameAccountnameX
almostAnkerXmechanical property. Immutable ID to maintain the relationship between ADDS and Azure AD.
useLocationXmechanical property. The country/region of the user. Used for license assignment.
userPrincipalnaamXUPN is the login ID for the user. Usually the same as [mail] value.

Exchange online

attribute nameUserContactGroupRemark
accountEnabledXDefines whether an account is enabled.
altRecipientXVereist Azure AD Connect build 1.1.552.0 of later.
authorizeXXX
CXX
cnXX
coXX
companyXX
LandcodeXX
departmentXX
descriptionX
Display nameXXX
dLMemRejectPermsXXX
dLMemSubmitPermsXXX
extensionAttribuut1XXX
extensionAttribuut10XXX
extensionAttribuut11XXX
extensionAttribuut12XXX
extensionAttribuut13XXX
extensionAttribuut14XXX
extensionAttribuut15XXX
extensionAttribuut2XXX
extensionAttribuut3XXX
extensionAttribuut4XXX
extensionAttribuut5XXX
extensionAttribuut6XXX
extensionAttribuut7XXX
extensionAttribuut8XXX
extensionAttribuut9XXX
fax phone numberXX
given nameXX
homePhoneXX
informationXXXThis attribute is not currently used for groups.
initialsXX
IXX
legacyExchangeDNXXX
mailNicknameXXX
managed byX
managerXX
lidX
mobileXX
msDS-HABSeniorityIndexXXX
msDS-PhoneticDisplayNameXXX
msExchArchiveGUIDX
msExchArchiveNameX
msExchAssistantNameXX
msExchAuditAdminX
msExchAuditDelegateX
msExchAuditDelegateAdminX
msExchAuditOwnerX
msExchBlockedSendersHashXX
msExchBypassAuditX
msExchBypassModerationLinkXAvailable in Azure AD Connect version 1.1.524.0
msExchCoManagedByLinkX
msExchDelegateListLinkX
msExchELCExpirySuspensionEndX
msExchELCExpirySuspensionStartX
msExchELCMailboxFlagsX
msExchEnableModerationXX
msExchExtensionCustomAttribute1XXXThis attribute is not currently used by Exchange Online.
msExchExtensionCustomAttribute2XXXThis attribute is not currently used by Exchange Online.
msExchExtensionCustomAttribute3XXXThis attribute is not currently used by Exchange Online.
msExchExtensionCustomAttribute4XXXThis attribute is not currently used by Exchange Online.
msExchExtensionCustomAttribute5XXXThis attribute is not currently used by Exchange Online.
msExchHideFromAddressListsXXX
msExchImmutableIDX
msExchLitigationHoldDateXXX
msExchLitigationHoldOwnerXXX
msExchMailboxAuditEnableX
msExchMailboxAuditLogAgeLimitX
msExchMailboxGuidX
msExchModeratedByLinkXXX
msExchModerationFlagsXXX
msExchRecipientDisplayTypeXXX
msExchRecipientTypeDetailsXXX
msExchRemoteRecipientTypeX
msExchRequireAuthToSendToXXX
msExchResourceCapacityX
msExchResourceDisplayX
msExchResourceMetaDataX
msExchResourceSearchPropertiesX
msExchRetentionCommentXXX
msExchRetentie-URLXXX
msExchSafeRecipientsHashXX
msExchSafeSendersHashXX
msExchSenderHintTranslationsXXX
msExchTeamMailboxExpiry dateX
msExchTeamMailboxOwnersX
msExchTeamMailboxSharePointUrlX
msExchUserHoldPoliciesX
msOrg-IsOrganizationalX
objectSIDXXmechanical property. AD user ID used to maintain synchronization between Azure AD and AD.
oOFReplyToOriginatorX
other facsimile phoneXX
andereHomePhoneXX
other phoneXX
semaphoreXX
physicalDeliveryOfficeNameXX
PostcodeXX
proxyAdressenXXX
public delegatesXXX
pwdLastSetXmechanical property. Used to know when to invalidate already issued tokens. Used by both password sync and federation.
reportToOriginatorX
reportToOwnerX
snXX
almostAnkerXXXmechanical property. Immutable ID to maintain the relationship between ADDS and Azure AD.
stXX
AddressXX
destination addressXX
phoneAssistantXX
phone numberXX
thumbnail photoXXPeriodically synced with M365 profile picture. Administrators can set the frequency of synchronization by changing the Azure AD Connect value. Please note that if users change their photo both on-premises and in the cloud within a time span shorter than the Azure AD Connect value, we cannot guarantee that the latest photo will be displayed.
titleXX
unauthorizedOrigXXX
useLocationXmechanical property. The country/region of the user. Used for license assignment.
user certificateXX
userPrincipalnaamXUPN is the login ID for the user. Usually the same as [mail] value.
userSMIMECertificatesXX
wWWStart pageXX
attribute nameUserContactGroupRemark
accountEnabledXDefines whether an account is enabled.
authorizeXXX
CXX
cnXX
coXX
companyXX
LandcodeXX
departmentXX
descriptionXXX
Display nameXXX
dLMemRejectPermsXXX
dLMemSubmitPermsXXX
extensionAttribuut1XXX
extensionAttribuut10XXX
extensionAttribuut11XXX
extensionAttribuut12XXX
extensionAttribuut13XXX
extensionAttribuut14XXX
extensionAttribuut15XXX
extensionAttribuut2XXX
extensionAttribuut3XXX
extensionAttribuut4XXX
extensionAttribuut5XXX
extensionAttribuut6XXX
extensionAttribuut7XXX
extensionAttribuut8XXX
extensionAttribuut9XXX
fax phone numberXX
given nameXX
hide DL membershipX
house phoneXX
informationXXX
initialsXX
ipPhoneXX
IXX
mailXXX
mail nicknameXXX
managed byX
managerXX
lidX
Middle nameXX
mobileXX
msExchTeamMailboxExpiry dateX
msExchTeamMailboxOwnersX
msExchTeamMailboxSharePointLinkedByX
msExchTeamMailboxSharePointUrlX
objectSIDXXmechanical property. AD user ID used to maintain synchronization between Azure AD and AD.
oOFReplyToOriginatorX
other facsimile phoneXX
andereHomePhoneXX
otherIpPhoneXX
otherMobileXX
other pagersXX
other phoneXX
semaphoreXX
physicalDeliveryOfficeNameXX
PostcodeXX
mailboxXXThis attribute is not currently used by SharePoint Online.
Preferred LanguageX
proxyAdressenXXX
pwdLastSetXmechanical property. Used to know when to invalidate already issued tokens. Used by both password hash synchronization, pass-through authentication, and federation.
reportToOriginatorX
reportToOwnerX
snXX
almostAnkerXXXmechanical property. Immutable ID to maintain the relationship between ADDS and Azure AD.
stXX
AddressXX
destination addressXX
phoneAssistantXX
phone numberXX
thumbnail photoXXPeriodically synced with M365 profile picture. Administrators can set the frequency of synchronization by changing the Azure AD Connect value. Please note that if users change their photo both on-premises and in the cloud within a time span shorter than the Azure AD Connect value, we cannot guarantee that the latest photo will be displayed.
titleXX
unauthorizedOrigXXX
urlXX
useLocationXmechanical property. The country/region of the user
. Used for license assignment.
userPrincipalnaamXUPN is the login ID for the user. Usually the same as [mail] value.
wWWStart pageXX

Teams and Skype for Business Online

attribute nameUserContactGroupRemark
accountEnabledXDefines whether an account is enabled.
CXX
cnXX
coXX
companyXX
departmentXX
descriptionXXX
Display nameXXX
fax phone numberXXX
given nameXX
house phoneXX
ipPhoneXX
IXX
mailXXX
mailNicknameXXX
managed byX
managerXX
lidX
mobileXX
msExchHideFromAddressListsXXX
msRTCSIP Application OptionsX
msRTCSIP-DeploymentLocatorXX
msRTCSIP LineXX
msRTCSIP-OptionFlagsXX
msRTCSIP-OwnerUrnX
msRTCSIP-PrimaryUserAddressXX
msRTCSIP-UserEnabledXX
objectSIDXXmechanical property. AD user ID used to maintain synchronization between Azure AD and AD.
other phoneXX
physicalDeliveryOfficeNameXX
PostcodeXX
Preferred LanguageX
proxyAdressenXXX
pwdLastSetXmechanical property. Used to know when to invalidate already issued tokens. Used by both password hash synchronization, pass-through authentication, and federation.
snXX
almostAnkerXXXmechanical property. Immutable ID to maintain the relationship between ADDS and Azure AD.
stXX
AddressXX
phone numberXX
thumbnail photoXXPeriodically synced with M365 profile picture. Administrators can set the frequency of synchronization by changing the Azure AD Connect value. Please note that if users change their photo both on-premises and in the cloud within a time span shorter than the Azure AD Connect value, we cannot guarantee that the latest photo will be displayed.
titleXX
useLocationXmechanical property. The country/region of the user. Used for license assignment.
userPrincipalnaamXUPN is the login ID for the user. Usually the same as [mail] value.
wWWStart pageXX

Azure-RMS

attribute nameUserContactGroupRemark
accountEnabledXDefines whether an account is enabled.
cnXXCommon name or alias. Usually the prefix of [mail] value.
Display nameXXXA string representing the name often shown as the friendly name (first name last name).
mailXXXfull email address.
lidX
objectSIDXXmechanical property. AD user ID used to maintain synchronization between Azure AD and AD.
proxyAdressenXXXmechanical property. Used by Azure AD. Contains all of the user's secondary email addresses.
pwdLastSetXmechanical property. Used to know when to invalidate already issued tokens.
almostAnkerXXXmechanical property. Immutable ID to maintain the relationship between ADDS and Azure AD.
useLocationXmechanical property. The country/region of the user. Used for license assignment.
userPrincipalnaamXThis UPN is the login ID for the user. Usually the same as [mail] value.

In tune

attribute nameUserContactGroupRemark
accountEnabledXDefines whether an account is enabled.
CXX
cnXX
descriptionXXX
Display nameXXX
mailXXX
mail nicknameXXX
lidX
objectSIDXXmechanical property. AD user ID used to maintain synchronization between Azure AD and AD.
proxyAdressenXXX
pwdLastSetXmechanical property. Used to know when to invalidate already issued tokens. Used by both password hash synchronization, pass-through authentication, and federation.
almostAnkerXXXmechanical property. Immutable ID to maintain the relationship between ADDS and Azure AD.
useLocationXmechanical property. The country/region of the user. Used for license assignment.
userPrincipalnaamXUPN is the login ID for the user. Usually the same as [mail] value.

Dynamic CRM

attribute nameUserContactGroupRemark
accountEnabledXDefines whether an account is enabled.
CXX
cnXX
coXX
companyXX
LandcodeXX
descriptionXXX
Display nameXXX
fax phone numberXX
given nameXX
IXX
managed byX
managerXX
lidX
mobileXX
objectSIDXXmechanical property. AD user ID used to maintain synchronization between Azure AD and AD.
physicalDeliveryOfficeNameXX
PostcodeXX
Preferred LanguageX
pwdLastSetXmechanical property. Used to know when to invalidate already issued tokens. Used by both password hash synchronization, pass-through authentication, and federation.
snXX
almostAnkerXXXmechanical property. Immutable ID to maintain the relationship between ADDS and Azure AD.
stXX
AddressXX
phone numberXX
titleXX
useLocationXmechanical property. The country/region of the user. Used for license assignment.
userPrincipalnaamXUPN is the login ID for the user. Usually the same as [mail] value.

Third Party Applications

This group is a set of attributes used as the minimum attributes needed for a generic workload or application. It can be used for a workload not listed in another section or for a non-Microsoft app. It is used explicitly for the following:

  • Yammer (only User is consumed)
  • Hybrid Business-to-Business (B2B) cross-org collaboration scenarios provided by resources such as SharePoint

This group is a set of attributes that can be used if the Azure AD directory is not used to support Microsoft 365, Dynamics, or Intune. It has a small set of core attributes. Note that single sign-on or provisioning for some third-party applications requires configuring attribute synchronization in addition to those described here. The application requirements are described in theTutorial SaaS appfor every application.

attribute nameUserContactGroupRemark
accountEnabledXDefines whether an account is enabled.
cnXX
Display nameXXX
employeeIDX
given nameXX
mailXX
managed byX
mailNickNameXXX
lidX
objectSIDXmechanical property. AD user ID used to maintain synchronization between Azure AD and AD.
proxyAdressenXXX
pwdLastSetXmechanical property. Used to know when to invalidate already issued tokens. Used by both password hash synchronization, pass-through authentication, and federation.
snXX
almostAnkerXXXmechanical property. Immutable ID to maintain the relationship between ADDS and Azure AD.
useLocationXmechanical property. The country/region of the user. Used for license assignment.
userPrincipalnaamXUPN is the login ID for the user. Usually the same as [mail] value.

Windows 10

A computer (device) that is a member of a Windows 10 domain synchronizes some attributes with Azure AD. For more information about the scenarios, seeConnect domain-joined devices to Azure AD for Windows 10 experiences. These attributes are always synced and Windows 10 will not appear as an app that you can deselect. A computer that is a member of a Windows 10 domain is identified by having the userCertificate attribute populated.

attribute nameDeviceRemark
accountEnabledX
deviceTrustTypeXHard-coded value for domain-joined computers.
Display nameX
ms-DS-CreatorSIDXAlso called RegisteredOwnerReference.
objectGUIDXAlso referred to as device ID.
objectSIDXAlso known as onPremisesSecurityIdentifier.
operating systemXAlso called deviceOSType.
operatingSystemVersionXAlso called deviceOSVersion.
user certificateX

These attributes foruserare in addition to the other apps you have selected.

attribute nameUserRemark
domainFQDNXAlso called dnsDomainName. For example, contoso.com.
domainNetBiosXAlso called netBiosName. For example CONTOSO.
msDS-KeyCredentialLinkXOnce the user is enrolled in Windows Hello for Business.

Exchange hybrid writeback

These attributes are written back from Azure AD to on-premises Active Directory when you choose to enableWissel hybrid of. Depending on your Exchange version, fewer attributes can be synchronized.

Attribute name (on-premises AD)Attribute Name (Connect UI)UserContactGroupRemark
msDS-ExternDirectoryObjectIDms-DS-Externe-Directory-Object-IdXDerived from cloudAnchor in Azure AD. This attribute is new in Exchange 2016 and Windows Server 2016 AD.
msExchArchiveStatusms-Exch-ArchiveStatusXOnline Archive: Allows customers to archive email.
msExchBlockedSendersHashms-Exch-BlockedSendersHashXFiltering: Writes back on-premises filtering and online safe and blocked sender data from customers.
msExchSafeRecipientsHashms-Exch-SafeRecipientsHashXFiltering: Writes back on-premises filtering and online safe and blocked sender data from customers.
msExchSafeSendersHashms-Exch-SafeSendersHashXFiltering: Writes back on-premises filtering and online safe and blocked sender data from customers.
msExchUCVoiceMail Settingsms-Exch-UCVoiceMailSettingsXEnable Unified Messaging (UM) - Online Voicemail - Used by Microsoft Lync Server integration to indicate to Lync Server on-premises that the user has voicemail in online services.
msExchUserHoldPoliciesms-Exch-UserHoldPoliciesXLitigation Hold: Enables cloud services to determine which users are under Litigation Hold.
proxyAdressenproxyAdressenXXXOnly the Exchange Online x500 address is inserted.
public delegatesms-Exch-Public-DelegatesXAllows an Exchange Online mailbox to grant SendOnBehalfTo privileges to users with a local Exchange mailbox. Requires Azure AD Connect build 1.1.552.0 or later.

Openbare Exchange Mail-map

These attributes are synced from on-premises Active Directory to Azure AD when you choose to enableOpenbare Exchange Mail-map.

attribute namepublic folderRemark
Display nameX
mailX
msExchRecipientTypeDetailsX
objectGUIDX
proxyAdressenX
destination addressX

Write back device

Device objects are created in Active Directory. These objects can be Azure AD-joined devices or domain-joined Windows 10 computers.

attribute nameDeviceRemark
altSecurityIdentitiesX
Display nameX
dnX
msDS-CloudAnchorX
msDS-DeviceIDX
msDS-DeviceObjectVersionX
msDS-DeviceOSTypeX
msDS-DeviceOSVersionX
msDS-DevicePhysicalID'sX
msDS-KeyCredentialLinkXOnly with Windows Server 2016 AD schema
msDS-IsCompliantX
msDS-IsEnabledX
msDS-IsManagedX
msDS-RegisteredOwnerX

Notes

  • When you use an alternate ID, the on-premises userPrincipalName attribute is synchronized with the Azure AD onPremisesUserPrincipalName attribute. The Alternate ID attribute, e.g. email, is synchronized with the Azure AD userPrincipalName attribute.
  • While uniqueness is not enforced for the Azure AD onPremisesUserPrincipalName attribute, it is not supported to synchronize the same UserPrincipalName value with the Azure AD onPremisesUserPrincipalName attribute across multiple different Azure AD users.
  • In the lists above, the object typeUseralso applies to the object typeiNetOrgPerson.

Next steps

Learn more about theAzure AD Connect syncconfiguration.

Learn more aboutIntegrate your on-premises identities with Azure Active Directory.

Top Articles
Latest Posts
Article information

Author: Jeremiah Abshire

Last Updated: 06/21/2023

Views: 6166

Rating: 4.3 / 5 (54 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Jeremiah Abshire

Birthday: 1993-09-14

Address: Apt. 425 92748 Jannie Centers, Port Nikitaville, VT 82110

Phone: +8096210939894

Job: Lead Healthcare Manager

Hobby: Watching movies, Watching movies, Knapping, LARPing, Coffee roasting, Lacemaking, Gaming

Introduction: My name is Jeremiah Abshire, I am a outstanding, kind, clever, hilarious, curious, hilarious, outstanding person who loves writing and wants to share my knowledge and understanding with you.