Can we sync private phone or private mail to AzureAD

%3CLINGO-SUB%20id%3D%22lingo-sub-2653966%22%20slang%3D%22en-US%22%3ECan%20we%20sync%20private%20phone%20or%20private%20mail%20to%20AzureAD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2653966%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3EHI%2C%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3EI'm%20working%20on%20a%20project%20where%20the%20goal%20is%20to%20give%20access%20for%20candidates%20(before%20they%20are%20hired)%20to%20the%20internal%20application%20published%20as%20Enterprise%20App%20in%20Azure%20AD.%20Employees%20use%20SSO%20to%20access%20the%20application.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3EThe%20solution%20we%20think%20of%20is%20to%20create%20an%20AD%20account%20for%20the%20candidate%20with%20private%20mobile%20and%2For%20mail%2C%20sync%20it%20to%20AzureAD%20and%20let%20the%20candidate%20reset%20the%20password%20using%20that%20security%20information.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3ERelated%20to%20the%20above%2C%20is%20there%20an%20attribute%20in%20local%20AD%20equivalent%20to%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory-b2c%2Fuser-profile-attributes%23%3A~%3Atext%3DstrongAuthentication%2520AlternativePhoneNumber1%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAlternativeAuthenticationPhone%3C%2FA%3E%3CSPAN%3E%26nbsp%3Bor%20%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory-b2c%2Fuser-profile-attributes%23%3A~%3Atext%3DstrongAuthenticationEmailAddress1%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EstrongAuthenticationEmailAddress%3C%2FA%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FSPAN%3E%3CSPAN%3Ein%20AzureAD%2C%20which%20can%20be%20synced%20by%20Azure%20AD%20Connect%20and%20use%20in%20the%20SSPR%20process%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2653966%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAccess%20Management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAD%20Connect%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2654007%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20sync%20private%20phone%20or%20private%20mail%20to%20AzureAD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2654007%22%20slang%3D%22en-US%22%3EHi%20Michal%2C%3CBR%20%2F%3E%3CBR%20%2F%3EWhy%20wouldn't%20you%20use%20Azure%20AD%20Access%20Packages%3F%20I%20have%20written%20a%20blog%20about%20this%20great%20feature%3A%20%3CA%20href%3D%22https%3A%2F%2Fwww.bilalelhaddouchi.nl%2Findex.php%2F2021%2F07%2F31%2Fget-started-with-azure-ad-access-packges%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.bilalelhaddouchi.nl%2Findex.php%2F2021%2F07%2F31%2Fget-started-with-azure-ad-access-packges%2F%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3ERegarding%20the%20attributes%2C%20you%20can%20also%20create%20a%20dynamic%20group%20with%20the%20hires%20as%20members%20of%20this%20particular%20group.%20An%20expression%20could%20be%20the%20Department%20attribute%20with%20the%20value%20%22hire%22%20or%20you%20could%20use%20the%20CloudExtenstionAttributes%20with%20a%20custom%20value%20set.%3CBR%20%2F%3E%3CBR%20%2F%3ELet%20me%20know%20if%20you%20still%20need%20some%20help%20or%20advice%20regarding%20this%20functionality.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2663697%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20sync%20private%20phone%20or%20private%20mail%20to%20AzureAD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2663697%22%20slang%3D%22en-US%22%3EAlthough%20we%20found%20Azure%20AD%20Access%20Packages%20interesting%2C%20after%20further%20investigation%2C%20we%20still%20need%20to%20sync%20private%20phone%20numbers%20and%2For%20e-mails%20to%20AzureAD%20for%20SSPR%2FMFA.%20We%20need%20it%20for%20employed%20users%2C%20as%20we%20have%20this%20data%20in%20our%20HR%20system%20integrated%20with%20our%20AD%20on-prem.%3CBR%20%2F%3EAnd%20we%20cannot%20use%20standard%20fields%20like%20a%20mobile%20phone%20number%2C%20to%20protect%20user's%20privacy%2C%20as%20this%20field%20is%20visible%20for%20other%20users%20in%20the%20company.%3CBR%20%2F%3ESo%20my%20question%20still%20stays%20open.%20Is%20there%20a%20field%20in%20Active%20Directory%20which%20directly%20refers%20to%20AlternativeAuthenticationPhone%20or%20strongAuthenticationEmailAddress%20fields%20in%20AzureAD%3F%20Or%20should%20we%20use%20custom%20attributes%20in%20AD%20for%20that%3F%3C%2FLINGO-BODY%3E
Contributor

HI, 

I'm working on a project where the goal is to give access for candidates (before they are hired) to the internal application published as Enterprise App in Azure AD. Employees use SSO to access the application.

The solution we think of is to create an AD account for the candidate with private mobile and/or mail, sync it to AzureAD and let the candidate reset the password using that security information. 

Related to the above, is there an attribute in local AD equivalent to AlternativeAuthenticationPhone or strongAuthenticationEmailAddress in AzureAD, which can be synced by Azure AD Connect and use in the SSPR process?

 

9 Replies
Hi Michal,

Why wouldn't you use Azure AD Access Packages? I have written a blog about this great feature: https://www.bilalelhaddouchi.nl/index.php/2021/07/31/get-started-with-azure-ad-access-packges/

Regarding the attributes, you can also create a dynamic group with the hires as members of this particular group. An expression could be the Department attribute with the value "hire" or you could use the CloudExtenstionAttributes with a custom value set.

Let me know if you still need some help or advice regarding this functionality.
Hi BilalelHadd,
Thank you for pointing me in this direction. I was not aware of this functionality and it puts a new light on the project. I am now exploring this area further. I'll let you know if I have more questions.

Although we found Azure AD Access Packages interesting, after further investigation, we still need to sync private phone numbers and/or e-mails to AzureAD for SSPR/MFA. We need it for employed users, as we have this data in our HR system integrated with our AD on-prem.
And we cannot use standard fields like a mobile phone number, to protect user's privacy, as this field is visible for other users in the company.
So my question still stays open. Is there a field in Active Directory which directly refers to AlternativeAuthenticationPhone or strongAuthenticationEmailAddress fields in AzureAD? Or should we use custom attributes in AD for that?
The following article describes the attributes that we sync by default:

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/reference-connect-sync-attributes-syn...

To answer your question, no there is no attribute in AD. It is best that you set that authentication data directly via PowerShell. See here for details:

https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-sspr-authenticationdata...

I don't think you want to be in the business of synchronizing that type of data because AD is not Source of Authority (SOA). So, even if you can attempt to export it once, the moment a user updates their mobile number, you are not longer in "sync", despite attempting to update it again from AD. Hope this helps.
I was thinking about it and you are totally right. This wouldn't be a good idea to get it continuously in sync. As you suggested, it should be one-time sync so later users are able to control it.
Thank you for your answer and suggestion.

@Josh Villagomez 

But how can I set the strongAuthenticationEmailAddress using PowerShell? Can you provide an example?

 

@Michal_Z Did you refer to article I provided earlier? 

Yes. And I didn't find the parameter strongAuthenticationEmailAddress working on the Set-AzureADUser command.
I see. That specific attribute is not meant to be read or modified directly. Its values come through a claim type and there is no exposed PowerShell or Graph API to modify it directly. From what I understand, it can only be modified through custom user flow policies. I would check this documentation:

https://github.com/azure-ad-b2c/samples
https://github.com/azure-ad-b2c/samples/tree/master/policies/username-signup-or-signin

I've never tried this, but this is the best I provide for you. Hope this helps.