You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为SCIM预配向Azure Active Directory添加用户属性(HiBob场景)

Got it, let's break down how to solve this for your all-cloud HiBob → Azure AD (Entra ID) provisioning workflow, since you've already ruled out AD Connect and tried some misaligned tools like B2C. The core goal here is to sync HiBob's unique fields (like emergency contacts) to custom attributes in AAD, which you can then use for Slack and other app provisioning.

This is the native, cloud-first approach that fits your scenario—you might have confused it with B2C extensions, but standard AAD directory extensions work perfectly for member users in a cloud-only tenant.

  1. Create a directory extension via Microsoft Graph API
    Since you're in a cloud-only environment, you'll need to register a dummy application (to host the extension) and create the attribute:

    • First, register a new app in Entra ID (no permissions needed initially, just a container for the extension).
    • Use this Graph API POST request to create the extension property:
      POST https://graph.microsoft.com/v1.0/applications/{your-app-id}/extensionProperties
      Content-Type: application/json
      
      {
        "name": "emergencyContactName",
        "dataType": "String",
        "targetObjects": [
          "User"
        ]
      }
      
      The resulting attribute name will be extension_<your-app-id-without-dashes>_emergencyContactName (save this for mapping).
  2. Map HiBob fields to the new extension in Entra ID Provisioning

    • Go to Entra ID → Enterprise Applications → Your HiBob app → Provisioning → Edit provisioning.
    • Under "Mappings", select "Provision Azure Active Directory Users".
    • Click "Add New Mapping", set the source attribute to your HiBob emergency contact field (check the HiBob connector's available attributes list—you might need to enable "Show advanced options" to see custom HiBob fields), and the target attribute to the directory extension you just created.
    • Save the mapping and trigger a test sync.
  3. Verify the sync
    Use this Graph API request to check if the attribute is populated:

    GET https://graph.microsoft.com/v1.0/users/{user-id}?$select=extension_<your-app-id-without-dashes>_emergencyContactName
    

Option 2: Use Pre-Provisioning Scripts (If Connector Doesn’t Support Direct Mapping)

If the HiBob pre-built connector doesn’t expose the custom fields you need for direct mapping, you can inject a PowerShell script into the provisioning flow to handle the data sync:

  1. Enable pre-provisioning scripting
    In your HiBob app's provisioning settings, under "Advanced Options", toggle on "Pre-provisioning Script".

  2. Write a script to sync custom fields
    Here’s a simplified example that fetches the HiBob emergency contact and updates the AAD user’s directory extension:

    # Pull source data from HiBob
    $sourceUser = $Context.SourceObject
    $emergencyContact = $sourceUser."emergency_contact_full_details" # Use your actual HiBob field name
    
    # Skip if no emergency contact data
    if ([string]::IsNullOrEmpty($emergencyContact)) { return }
    
    # Update the AAD user's directory extension
    if ($Context.TargetObject -ne $null) {
        $graphUri = "https://graph.microsoft.com/v1.0/users/$($Context.TargetObject.Id)"
        $body = @{
            "extension_<your-app-id-without-dashes>_emergencyContactDetails" = $emergencyContact
        } | ConvertTo-Json
        
        Invoke-RestMethod -Uri $graphUri -Method Patch `
            -Headers @{Authorization = "Bearer $($Context.AccessToken)"} `
            -Body $body -ContentType "application/json"
    }
    

    Note: You’ll need to grant the provisioning service principal the User.ReadWrite.All Graph permission for this to work.

Option 3: Use Logic Apps/Power Automate as a Sync Bridge

If the above options don’t fit, you can build a custom sync flow using Power Automate or Logic Apps:

  • Trigger: Set up a HiBob webhook to fire when a new employee is created.
  • Action 1: Call HiBob’s API to fetch the full employee record (including custom fields like emergency contacts).
  • Action 2: Use the Microsoft Graph connector to find the corresponding AAD user (match via email).
  • Action 3: Patch the AAD user’s directory extension attribute with the HiBob data.
  • Add error handling: Include retry policies and alerts for failed syncs.

Key Notes to Remember

  • Directory extensions are permanent (you can’t delete them, only disable), so plan your attribute names carefully.
  • For Slack and other apps, ensure their Entra ID integration has permission to read the directory extensions (most apps allow custom attribute mapping if you enable the right Graph permissions).
  • Double-check that your HiBob API credentials (used by the Entra ID connector) have access to the custom fields you want to sync.

内容的提问来源于stack exchange,提问作者Ben Camp

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 15:32:44