Following are steps to configure User attributes mapping for custom extension urn:ietf:params:scim:schemas:extension:broadcom:authentication:2.0:User which allows customers to map alternative user identities from their IDP that are not part of standard SCIM schema.
By default Entra ID does not import on-premises SamAccountName, you need to configure this before using this KB. One method to do this is using the Microsoft Entra Connect Sync: Directory extensions. Once you have this configured, you can use this KB to add the corresponding attribute in the WSS SCIM integration app.
Navigate to URL https://portal.azure.com/?Microsoft_AAD_Connect_Provisioning_forceSchemaEditorEnabled=true
Navigate to Enterprise applications | All applications
Select Symantec Web Security Service (WSS)
Click Provisioning
In Provisioning, expand mappings, select Provision Microsoft Entra ID Users
Check the Show advanced options checkbox
Then select Edit attribute list for SymantecWebSecurityService
At the bottom add urn:ietf:params:scim:schemas:extension:broadcom:authentication:2.0:User:sAMAccountName
Once saved, you can then map your source attribute to this new target attribute.