Attribute Mapping

Attribute Mapping lines up the fields of a synced object between a connected directory and the Universal Directory. Because different directories name and structure the same information differently (e.g., Mobile Number vs. Mobile Phone), mapping tells the product which source attribute fills each Universal Directory attribute.

Accurate mapping means synced profiles arrive complete and correct, with each value in the field the product expects. This keeps everything that later reads those attributes, such as search and dynamic group membership configurations, working as intended.

Prerequisites

  • A directory whose users and groups sync into Universal Directory (for example, a Microsoft Entra ID tenant) must be connected on the Manage Directory page.

Configuration steps

Open Universal Directory > Manage Directory and select the Active Directory or Azure Active Directory tab. Click the advanced settings icon (icon-advanced-settings) for the directory and open the Attribute Mapping tab. Mapping is configured separately for User and Group objects using the sub-tabs.

  1. The left column lists the Universal Directory attributes (for users, fields such as First Name, Mobile Number, User Status, and Employee ID; for groups, fields such as Group Name, Group Description, and Created Time).
  2. For each attribute, select the matching attribute from the connected directory in the right column's drop-down menu. Use the search field in the drop-down to find attributes quickly.
  3. Click Save.

For example, users are typically mapped First Name to First Name, Mobile Number to Mobile Phone, User Status to Account Enabled, Group Name to Display Name, and Created Time to When Created.

Tips

  • If a dynamic group or a search needs to act on a field like Country or Employee ID, map that field first. Otherwise, it stays empty and the rule has nothing to match.
  • Map User Status to the source's account-enabled attribute so the enabled or disabled state carries across. Otherwise, Universal Directory may not reflect when an account has been disabled at the source, which matters for offboarding and access reviews.
  • Check the mappings where the source and target names are similar but not identical, such as Mobile Number to Mobile Phone or Street to Street Address. A plausible but incorrect mapping silently imports the wrong value into the field.