sharepoint 2013 azure ad application proxy - set email property in user profile

MARCEL BALCAREK 61 Reputation points
2021-05-05T18:26:32.62+00:00

Hello,

We are using the Azure AD Application Proxy to allow users to sign on to our on-premise SharePoint 2013 system with Azure AD credentials. Ref: https://learn.microsoft.com/en-us/azure/active-directory/saas-apps/sharepoint-on-premises-tutorial

I have noticed that when I invite an Azure AD user to a SharePoint group, their Work Email (email) user profile property is not set.

I can set it manually by using Set-SPUser, but is there a way to set it automatically via the proxy?

Update: In https://learn.microsoft.com/en-us/sharepoint/user-profile-sync it indicates that the proxy address is mapped to the work email. I have checked and the proxy address is set correctly.
Do I need to have a functioning User Profile Sync to make this work?

SharePoint Server Management
SharePoint Server Management
SharePoint Server: A family of Microsoft on-premises document management and storage systems.Management: The act or process of organizing, handling, directing or controlling something.
2,798 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Echo Du_MSFT 17,116 Reputation points
    2021-05-06T08:18:34.733+00:00

    Hello @MARCEL BALCAREK ,

    According to my research, we recommend you to have a functioning User profile synchronization.

    Thanks,
    Echo Du

    =====================

    If an Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Balcarek, Marcel 76 Reputation points
    2021-05-12T19:12:20.673+00:00

    The issue is not resolved. I have a guest user from Azure AD invited into SharePoint 2013 on-premise by inviting the user to a SP group

    96111-azad-userinsp2013.png

    Here are my settings in the Azure AD Enterprise application:
    96009-azad-userinazad.png

    96049-azad-attributemappings.png

    My User Profile Synch Service Application is 'started' and User Profile Synch Service is 'started', but I do not see the new user in Central Admin; Manage User Profiles.

    0 comments No comments

  3. Balcarek, Marcel 76 Reputation points
    2021-05-12T22:53:04.35+00:00

    The tutorial documentation (https://learn.microsoft.com/en-us/azure/active-directory/saas-apps/sharepoint-on-premises-tutorial) changed about 5/5/2021, so I have adjusted my claims section in azure AD
    96151-azad-attributemappingsnew.png

    It seems like the email claim is no longer required (?) and I have removed it from the above Claims list. Based on the tutorial and https://learn.microsoft.com/en-us/sharepoint/user-profile-sync) - I expect the Work Email to still be populated.

    This article also suggests "Typically, user profiles are created automatically for all accounts that are created in Microsoft 365. For organizations that have a Microsoft 365 Education subscription, user profiles are not created for new accounts by default. The user must access SharePoint once, at which time a basic stub profile will be created for the user account. The stub profile will be updated with all remaining data as part of the sync process."

    I am using a developer tenant - I noticed that the user shows up in Central Admin; Manage User Profiles once the user has signed on to SharePoint on-premise the first time.
    Update: after the users first signon and having checked their profile existed in Central Admin; Manage User Profiles - I ran the full synchronization timer job - after this job completed, the "work email" is still not populated.

    Do I need to set anything up in Central Admin, for the User Profile Service Application - under Synchronization "Configure Synchronization Connections"? Currently this area is empty.
    96449-azad-upsa.png

    Any advise is appreciated.

    0 comments No comments