Add onPremisesSamAccountName attribute to CloudSOC Secondary ID via SCIM integration
search cancel

Add onPremisesSamAccountName attribute to CloudSOC Secondary ID via SCIM integration

book

Article ID: 452868

calendar_today

Updated On:

Products

CASB Securlet SAAS CASB Security Advanced CASB Security Premium CASB Security Standard

Issue/Introduction

Following are steps to configure User attributes mapping for custom extension urn:ietf:params:scim:schemas:extension:broadcom:authentication:2.0:User which allows customers to map alternative user identities from their IDP that are not part of standard SCIM schema.

Environment

By default Entra ID does not import on-premises SamAccountName, you need to configure this before using this KB. One method to do this is using the Microsoft Entra Connect Sync: Directory extensions. Once you have this configured, you can use this KB to add the corresponding attribute in the WSS SCIM integration app.

Resolution

  1. Navigate to URL https://portal.azure.com/?Microsoft_AAD_Connect_Provisioning_forceSchemaEditorEnabled=true

  2. Navigate to Enterprise applications | All applications

  3. Select Symantec Web Security Service (WSS)

  4. Click Provisioning

  5. In Provisioning, expand mappings, select Provision Microsoft Entra ID Users

  6. Check the Show advanced options checkbox

  7. Then select Edit attribute list for SymantecWebSecurityService

  8. At the bottom add urn:ietf:params:scim:schemas:extension:broadcom:authentication:2.0:User:sAMAccountName

  9. Once saved, you can then map your source attribute to this new target attribute.