You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant.
You deploy an app that adds custom attributes to the domain.
From Azure Cloud Shell, you discover that you cannot query the custom attributes of users.
You need to ensure that the custom attributes are available in Microsoft Entra ID.
Which task should you perform from Microsoft Entra Connect first?
Microsoft Entra Connect (Azure AD Connect) reads the on-premises AD DS schema to determine which attributes are available for synchronization. The hybrid administrator guidance states that after extending AD with new/custom attributes, you must refresh the directory schema in Entra Connect so the sync engine recognizes the new attributes; only then can you include them in the synchronization rules (''Customize synchronization options'') for export to Microsoft Entra ID. Until a schema refresh occurs, queries from Azure (e.g., via Cloud Shell) will not surface those attributes because the connector does not know about them. Thus, the first step is to run ''Refresh directory schema'' in Microsoft Entra Connect; afterwards you can map/select the custom attributes in the sync rules and verify they flow to Microsoft Entra ID.
Currently there are no comments in this discussion, be the first to comment!