You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WorkDay→本地AD→Azure AD架构下邮件属性(Mail Attribute)的管理及同步方案咨询

Managing Mail Attribute/Mailbox ID in Workday → On-Prem AD → Azure AD → O365 Scenario

Great question—let’s break down your specific setup (Workday as identity source, on-prem AD, Azure AD Connect, no on-prem Exchange) and walk through how to manage the mail attribute (mailbox ID) so it exists in both on-prem AD and Azure AD, plus get those attributes written back to Workday.

Core Context First

Since you don’t have an on-prem Exchange server, Azure AD handles mailbox provisioning directly when you assign O365 licenses to users. The key here is aligning the mail attribute across your identity systems so everything syncs correctly, and you can write it back to Workday.

Can Azure AD Provisioning Agent Generate Mailbox IDs for AD Accounts?

Absolutely—this is exactly what the Workday-to-on-prem AD inbound provisioning (via Azure AD Provisioning Agent) is designed to handle. Here’s how to set it up:

  1. Configure Attribute Mapping in Inbound Provisioning

    • In your Azure AD portal, navigate to the Workday inbound provisioning setup for on-prem AD.
    • Edit the user creation attribute mapping rules. You have two options:
      • Map a pre-existing email field from Workday (like Work Email) directly to the on-prem AD mail attribute. This is the cleanest approach if Workday already defines the desired mailbox ID.
      • If Workday doesn’t provide the full email address, use a custom expression to generate it. For example, combine the user’s first name, last name, and your verified O365 domain:
        Join("", [GivenName], ".", [Surname], "@your-verified-domain.com")
        
        You can add logic to handle duplicates (e.g., appending a number) using functions like GetUniqueString if needed.
    • Ensure the mapping applies during both user creation and updates.
  2. Sync to Azure AD via AADC

    • Once the mail attribute is populated in on-prem AD, Azure AD Connect will sync this value to Azure AD’s mail attribute by default. Since there’s no on-prem Exchange, AADC won’t override this with Exchange-specific attributes.
    • When you assign an O365 license to the Azure AD user, Azure AD will automatically use this mail attribute as the primary SMTP address for the new mailbox—no extra configuration needed, as long as the domain is verified in Azure AD.

Alternative: Let Azure AD Generate the Mailbox ID, Then Sync Back to AD

If you prefer to let Azure AD handle mailbox ID generation when licenses are assigned, you can still get this value back to on-prem AD (and then to Workday):

  • After assigning the license, Azure AD sets the mail attribute to the primary SMTP address of the mailbox.
  • Configure Azure AD Connect to write back the mail attribute from Azure AD to on-prem AD. Note: This requires enabling appropriate writeback permissions in AADC and ensuring your AD schema allows attribute updates.
  • Once the mail attribute is synced back to AD, use the Workday writeback provisioning flow to send it back to Workday.

Key Best Practices for Consistency

  • Use a Verified Domain: Ensure the domain in your mailbox IDs is verified in Azure AD—this is mandatory for O365 mailbox provisioning and avoids sync errors.
  • Align UPN with Mail (If Possible): While not required, setting the userPrincipalName (UPN) in AD/Azure AD to match the mail attribute reduces confusion and simplifies user sign-in.
  • Test Provisioning Flows: Always test with a test user first to verify that the mail attribute is correctly populated in AD, synced to Azure AD, used for the O365 mailbox, and written back to Workday.
  • Permission Checks: Make sure the Azure AD Provisioning Agent has sufficient permissions in on-prem AD to create users and update the mail attribute (minimum: Create User and Write Property for mail).

Writing Back to Workday

Once the mail attribute is correctly populated in Azure AD, use the Workday writeback provisioning feature to map Azure AD’s mail attribute to the corresponding field in Workday (e.g., Work Email). Configure this mapping in the Azure AD portal’s Workday writeback setup to include the attribute in the sync to Workday.

内容的提问来源于stack exchange,提问作者himu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 22:32:49