Microsoft Entra ID
Provisioning

Customize Application Attributes

In brief

The documentation now states that null values are not sent by default. Clearing attribute values is available only in preview for API-driven inbound provisioning apps and isn’t supported for other provisioning scenarios.

What Entra admins need to know

Administrators must verify that their provisioning scenario supports this capability before relying on attribute clearing.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • The user is out of scope due to not meeting a scoping filter.
  • The user is soft deleted in Microsoft Entra ID.
  • The property AccountEnabled is set to false on the user. Try to keep the IsSoftDeleted attribute in your attribute mappings.
  • TheBy default, the Microsoft Entra provisioning service doesn't supportsend null values to target systems. Clearing attribute values is available in preview only for API-driven inbound provisioning null values.apps. It isn't currently supported for other application provisioning scenarios or for inbound provisioning from Workday or SAP SuccessFactors. To enable this feature for API-driven inbound provisioning apps, see Clear attribute values (Preview).
  • They primary key, typically ID, shouldn't be included as a target attribute in your attribute mappings.
  • The role attribute typically needs to be mapped using an expression, rather than a direct mapping. For more information about role mapping, see Provisioning a role to a SCIM app.
  • While you can disable groups from your mappings, disabling users isn't supported.
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…