Home

Using onPremisesDistinguishedName Attribute in Group Base License (GBL)

%3CLINGO-SUB%20id%3D%22lingo-sub-888659%22%20slang%3D%22en-US%22%3EUsing%20onPremisesDistinguishedName%20Attribute%20in%20Group%20Base%20License%20(GBL)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-888659%22%20slang%3D%22en-US%22%3E%3CP%3EI'm%20trying%20to%20use%20Azure%20AD%20user%20Extension%20Property%20onPremisesDistinguishedName%20attribute%20as%20part%20of%20an%20expression%20in%20a%20GBL%20Dynamic%20User%20query.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3BI've%20used%20custom%20extension%20like%20user.extension._xxxxxxxxxxxxxxx_CustomAttribute%20successfully%20within%20my%20query%20for%20GBL%3B%20however%2C%20I'm%20having%20an%20issue%20trying%20to%20use%20onPremisesDistinguishedName%20to%20my%20GBL%20query.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20help%20with%20adding%20onPremisesDistinguishedName%20to%20Dynamic%20membership%20rule%20in%20GBL%20would%20be%20appreciated.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20You%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-Larry%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-888659%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-895171%22%20slang%3D%22en-US%22%3ERe%3A%20Using%20onPremisesDistinguishedName%20Attribute%20in%20Group%20Base%20License%20(GBL)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-895171%22%20slang%3D%22en-US%22%3EHey%20there.%20You%20wouldn't%20be%20able%20to%20directly%20use%20on%20prem%20DN%20for%20Dynamic%20membership.%20What%20you%20can%20do%20though%20is%20use%20AAD%20Connect%20custom%20sync%20rule%20to%20write%20the%20DN%20to%20one%20of%20the%20extension%20attributes%20and%20in%20turn%20configure%20a%20Dynamic%20membership%20rules%20using%20that%20specific%20extension%20attributes.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E
Highlighted
Larry Jones
Contributor

I'm trying to use Azure AD user Extension Property onPremisesDistinguishedName attribute as part of an expression in a GBL Dynamic User query. 

 

 I've used custom extension like user.extension._xxxxxxxxxxxxxxx_CustomAttribute successfully within my query for GBL; however, I'm having an issue trying to use onPremisesDistinguishedName to my GBL query.

 

Any help with adding onPremisesDistinguishedName to Dynamic membership rule in GBL would be appreciated.

 

Thank You,

 

-Larry

1 Reply
Hey there. You wouldn't be able to directly use on prem DN for Dynamic membership. What you can do though is use AAD Connect custom sync rule to write the DN to one of the extension attributes and in turn configure a Dynamic membership rules using that specific extension attributes.

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies