Account Linking

Account Linking tells Identity360 how to recognize that an object in Universal Directory and an object in a connected directory are the same user or group. By matching them on a shared attribute, it makes sure that when something changes on either side, the update lands on the correct object instead of updating the wrong record or creating a duplicate. This matters most when the same people or groups arrive from more than one source, since a reliable link keeps each identity as a single, consistent record across every connected directory.

Prerequisites

  • A directory already connected on the Manage Directory page (for example, an Entra ID tenant) whose users and groups sync into Universal Directory.

Configuration steps

Open Universal Directory > Manage Directory, select the Active Directory or Azure Active Directory tab, click the advanced settings (icon-advanced-settings) icon for the directory, and open the Account Linking tab. Linking is configured separately for User and Group objects using the sub-tabs.

  • Click the Universal Directory Attribute drop-down, and select an attribute that uniquely identifies the object in Universal Directory.
  • From the connected directory's attribute drop-down beside it, select the attribute that uniquely identifies the same object in that directory.
  • Click Save to apply the linking configuration.

For example, Primary Email and User Principal Name are commonly linked for users, whereas Group GUID and Group ID are common to link for groups.

Tips

  • Choose an attribute that is both unique and stable. An identifier that never changes keeps the link intact, whereas an attribute that can change can break the link and cause the synced object to be treated as a new record.
  • Before saving, confirm the chosen attribute is populated and holds the same value on both sides. An empty or mismatched value leaves the objects unlinked, so changes will not reach the intended record.