This isn't possible right now with the AAD Provisioning platform either inbound or outbound to the best of my knowledge. It's been requested before, but I am not aware of any immediate plans for this or any shareable ETA.
How do I clear an attribute value using "expressions for attribute mappings in Azure Active Directory" - Revisitng
With Azure Inbound Provisioning I need the ability remove an attribute's value when it is removed from the source of truth. The best I can do is flow a single character value--in this case a space. I can't flow an empty string that would leave an attribute with no value.
RFC 7644, "System for Cross-domain Identity Management: Protocol," provides for removal of an attribute value (see section 3.5.2.2, Remove Operation). Is this supported by Inbound Provisioning? If it is, how do I trigger? If not, is this a planned feature?
There doesn't seem to be a way of clearing an attribute value or flowing a NULL in the published reference at https://learn.microsoft.com/en-us/azure/active-directory/app-provisioning/functions-for-customizing-application-data .
-
Danny Zollner 9,871 Reputation points Microsoft Employee
2023-10-12T15:56:19.8833333+00:00