How do I clear an attribute value using "expressions for attribute mappings in Azure Active Directory" - Revisitng

Michael Liben 161 Reputation points
2023-10-12T09:30:02.1566667+00:00

With Azure Inbound Provisioning I need the ability remove an attribute's value when it is removed from the source of truth. The best I can do is flow a single character value--in this case a space. I can't flow an empty string that would leave an attribute with no value.

RFC 7644, "System for Cross-domain Identity Management: Protocol," provides for removal of an attribute value (see section 3.5.2.2, Remove Operation). Is this supported by Inbound Provisioning? If it is, how do I trigger? If not, is this a planned feature?

There doesn't seem to be a way of clearing an attribute value or flowing a NULL in the published reference at https://learn.microsoft.com/en-us/azure/active-directory/app-provisioning/functions-for-customizing-application-data .

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,630 questions
{count} votes

Accepted answer
  1. Danny Zollner 9,871 Reputation points Microsoft Employee
    2023-10-12T15:56:19.8833333+00:00

    This isn't possible right now with the AAD Provisioning platform either inbound or outbound to the best of my knowledge. It's been requested before, but I am not aware of any immediate plans for this or any shareable ETA.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful