Question
What are the limitations when synchronizing user information from Microsoft Entra ID to Access Control?
Answer
There are several limitations when synchronizing user information from Microsoft Entra ID to Access Control.
-
For the Username of an Access Control account, you can choose only either the
UserPrincipalName(UPN) format of Microsoft Entra ID or the local part (the value before @).
Also, the Username in Access Control cannot be changed later.
Example: If the user'sUserPrincipalNameAttribute is "user@example.com", set the Username to either "user@example.com" or "user". -
When synchronizing users, the Password of Microsoft Entra ID cannot be synchronized to Access Control.
Therefore, after Synchronization is complete, the administrator must set an Initial password in Access Control.
※ If a Password is not set, the user will not be able to Login to Access Control. Be sure to set it.For instructions on how to set a Password, please refer to the following articles:
Access Control Create User / Edit
Access Control Bulk User Update -
If Access Control and Microsoft Entra ID are federated, users cannot be created from the Microsoft Entra ID GUI for Domains subject to federation.
To create a user, the administrator must Execute Microsoft Graph PowerShell commands each time, or synchronize user information from Active Directory.
※ This is a specification of Microsoft Entra ID. For details, please contact Microsoft.
Translation Disclaimer
This article has been automatically translated from the original Japanese version for your convenience.
While we strive to ensure accuracy, we cannot guarantee its reliability or completeness.
In the event of any discrepancies or questions regarding the content, the official Japanese version shall prevail.