为SCIM预配向Azure Active Directory添加用户属性(HiBob场景)
Got it, let's break down how to solve this for your all-cloud HiBob → Azure AD (Entra ID) provisioning workflow, since you've already ruled out AD Connect and tried some misaligned tools like B2C. The core goal here is to sync HiBob's unique fields (like emergency contacts) to custom attributes in AAD, which you can then use for Slack and other app provisioning.
Option 1: Use Azure AD Directory Extension Attributes (Recommended)
This is the native, cloud-first approach that fits your scenario—you might have confused it with B2C extensions, but standard AAD directory extensions work perfectly for member users in a cloud-only tenant.
Create a directory extension via Microsoft Graph API
Since you're in a cloud-only environment, you'll need to register a dummy application (to host the extension) and create the attribute:- First, register a new app in Entra ID (no permissions needed initially, just a container for the extension).
- Use this Graph API POST request to create the extension property:
The resulting attribute name will bePOST https://graph.microsoft.com/v1.0/applications/{your-app-id}/extensionProperties Content-Type: application/json { "name": "emergencyContactName", "dataType": "String", "targetObjects": [ "User" ] }extension_<your-app-id-without-dashes>_emergencyContactName(save this for mapping).
Map HiBob fields to the new extension in Entra ID Provisioning
- Go to Entra ID → Enterprise Applications → Your HiBob app → Provisioning → Edit provisioning.
- Under "Mappings", select "Provision Azure Active Directory Users".
- Click "Add New Mapping", set the source attribute to your HiBob emergency contact field (check the HiBob connector's available attributes list—you might need to enable "Show advanced options" to see custom HiBob fields), and the target attribute to the directory extension you just created.
- Save the mapping and trigger a test sync.
Verify the sync
Use this Graph API request to check if the attribute is populated:GET https://graph.microsoft.com/v1.0/users/{user-id}?$select=extension_<your-app-id-without-dashes>_emergencyContactName
Option 2: Use Pre-Provisioning Scripts (If Connector Doesn’t Support Direct Mapping)
If the HiBob pre-built connector doesn’t expose the custom fields you need for direct mapping, you can inject a PowerShell script into the provisioning flow to handle the data sync:
Enable pre-provisioning scripting
In your HiBob app's provisioning settings, under "Advanced Options", toggle on "Pre-provisioning Script".Write a script to sync custom fields
Here’s a simplified example that fetches the HiBob emergency contact and updates the AAD user’s directory extension:# Pull source data from HiBob $sourceUser = $Context.SourceObject $emergencyContact = $sourceUser."emergency_contact_full_details" # Use your actual HiBob field name # Skip if no emergency contact data if ([string]::IsNullOrEmpty($emergencyContact)) { return } # Update the AAD user's directory extension if ($Context.TargetObject -ne $null) { $graphUri = "https://graph.microsoft.com/v1.0/users/$($Context.TargetObject.Id)" $body = @{ "extension_<your-app-id-without-dashes>_emergencyContactDetails" = $emergencyContact } | ConvertTo-Json Invoke-RestMethod -Uri $graphUri -Method Patch ` -Headers @{Authorization = "Bearer $($Context.AccessToken)"} ` -Body $body -ContentType "application/json" }Note: You’ll need to grant the provisioning service principal the
User.ReadWrite.AllGraph permission for this to work.
Option 3: Use Logic Apps/Power Automate as a Sync Bridge
If the above options don’t fit, you can build a custom sync flow using Power Automate or Logic Apps:
- Trigger: Set up a HiBob webhook to fire when a new employee is created.
- Action 1: Call HiBob’s API to fetch the full employee record (including custom fields like emergency contacts).
- Action 2: Use the Microsoft Graph connector to find the corresponding AAD user (match via email).
- Action 3: Patch the AAD user’s directory extension attribute with the HiBob data.
- Add error handling: Include retry policies and alerts for failed syncs.
Key Notes to Remember
- Directory extensions are permanent (you can’t delete them, only disable), so plan your attribute names carefully.
- For Slack and other apps, ensure their Entra ID integration has permission to read the directory extensions (most apps allow custom attribute mapping if you enable the right Graph permissions).
- Double-check that your HiBob API credentials (used by the Entra ID connector) have access to the custom fields you want to sync.
内容的提问来源于stack exchange,提问作者Ben Camp

