Azure Active Directory

Welcome to the Azure Active Directory suggestions and feedback site! We love hearing from you. If you have suggestions, please submit an idea or vote up an idea. We are monitoring the site actively.

Thank you for joining our community and helping improve Azure AD!

Wehave a new log in experience integrated with Azure AD, and we stronglyrecommend you log in with your Azure AD (Office 365) account. If yourUserVoice account is the same email address as your Azure AD account, yourprevious activities will be automatically mapped to your Azure AD account.  You can read more here for details: https://techcommunity.microsoft.com/t5/Azure-Active-Directory-Identity/Putting-customers-first-for-f...

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Allow BambooHR to write to AD Azure when a new starter is created so it creates a new user. HRaaM.

    Okta has the ability to use HR as a source of truth and are really engaging with HR as a master for AD. I know Bamboo can do that with Okta and Workday can as well. This would be a great way to have a flawless clear process using HR systems. From recruiting, to creating an employee in the system and then pushing it to ADAzure. Otherwise it's better to go with Okta. Higher price point but lower risk.

    42 votes
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    5 comments  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →
  2. Support for Workday "Integration System" custom attributes

    Sourced from https://github.com/MicrosoftDocs/azure-docs/issues/21671

    Adjust Workday web service call (get_workers) by adding a reference criteria call

    As an AD Admin, I would like the Azure AD Workday connector to support "integration system" attributes which are retrieved through special modification to the Get_Workers() API call.

    It would be beneficial if the web service call for workers could be adjusted to call another integration to get values that the normal API call won't get.
    Example: Some values needed or recommended for provisioning might be part of custom objects or derived from other objects in Workday.
    What I propose is that you at least…

    28 votes
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    3 comments  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →
  3. Workday-driven automatic AD group assignment

    When a new AD account is created using Workday, it should be possible to assign birthright AD groups to the user automatically.

    27 votes
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    2 comments  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →
  4. Workday to AAD/AD provisioning query scope

    Workday to AD/AAD provisioning
    please add the ability to scope the query passed to getworkers api. For instance, pass to getworkers company=schoolA.
    Workday is now implementing shared tenants in the EDU space. In a shared tenant, the current query to get_workers pulls all workers and then allows scoping. but the worker data for all schools has to be pulled before it can be scoped. The result is AAD audit logs saturated with other schools employee data. Also need to be able to control audit data written to azure activity logs, or at least be able to clear the…

    20 votes
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →
  5. Workday trigger delta sync

    The ability to trigger a delta sync in the Workday provisioning application would be helpful during development of the connector as well as for emergency scenarios. In addition, the ability to change the sync interval (15 min afaik) to something different.

    16 votes
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    4 comments  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →
  6. Workday to OnPremise Sync with non Global Admin Account

    In the current configuration of the "Workday to Active Directory Provisioning"  you are required to create an account in Azure with Global Admin permissions to be used by the onPremise agent.   All changes made to Active directory are made in the onPremise AD and not in Azure and the permissions appear to be above the needed level in order to maintain our security delegation of lowest level required to perform a task.     
    Is there are a solution to have the interaction between onPremise Agent, Azure and Workday that does not require this level of permission?

    9 votes
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →
  7. Support synchronization and modification of binary attributes

    Add support for the synchronization of binary attributes within the Azure AD provisioning / sync system.

    Example: The Workday to AAD or ADDS integration allows you to extend the attribute list (e.g. photo). AAD is able to receive that attribute but wont be able to sync it to AAD or ADDS due to size limitations on the photo attributes (<100k).

    In best case, provide us with a function which can be used in a expression of the attribute mappings. Possible ways: 1) photo specific function which allows you to provide pixel height and/or width (if only one is specified the…

    8 votes
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →
  8. Workday inbound provisioning to AD - allow password to be set and sent mail

    Please add more control when provisioning AD accounts, with Workday as source, about how password can be provided to manager and/or generic mail address.

    Send password to email address: Enter the email address to which you want the password sent.

    Send password to user’s manager: Sends the password to the manager’s email address. Ensure that you have the email address specified in Workday.

    Send password to user’s personal email: Sends the password to the user’s personal email address. Ensure that you have the email address specified in Workday.

    If you have more than one option selected, the password is sent…

    7 votes
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →
  9. inbound provisioning talent

    Support inbound provisioning from Dynamics 365 for Talent to Azure AD. If this can work for Workday, it should work for Microsoft's flagship HCM.

    6 votes
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →
  10. workday to Azure AD automatic user provision

    We are implementing the Workday Azure AD automatic user account provisioning for our client and we are facing below issues.

    https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/workday-inbound-tutorial

    *Workday account username is employeeID. As of now, the employeeID attribute is blank at Azure

    Issue 1: Automatic provisioning creates the duplicate user record at Azure with email id as userid@domain(20955@clientdomain.com), whereas the client is using their own logic to create the email ids (firstname+MiddleName_Lastname@clientdomain.com). After provisioning of accounts, we are getting duplicate records with different email ids.

    Issue 2: Automatic Provisioning is not updating the employeeId attribute in the Azure user account even when…

    6 votes
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →
  11. Inbound provisioning from Oracle

    Would like something similar to the inbound provisioning for workday to be available for Oracle HCM hr system.

    5 votes
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →
  12. Support inbound provisioning from TalentSoft to Azure AD

    Similar to Workday, add support for inbound provisioning from https://www.talentsoft.com/ to Azure AD.

    5 votes
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →
  13. SelectUniqueValue function should check AD Global Catalog for uniquenesss

    When configuring Workday to Active Directory User Provisioning integration with multiple child domains, it will be beneficial if the SelectUniqueValue function checks for uniqueness of samAccountName and userPrincipalName across the forest by querying the global catalog.

    5 votes
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →
  14. Workday to AD provisioning - Disable AD users after Account_Disabled attribute instead of Active attribute

    User would like to have a feature implemented:
    - That the account in AD is disabled responding to Accountdisabled in Workday Account instead of the "Active" attribute from the Worker object.
    - That the Expiration Date in AD is updated with the Account
    expiration_Date of the Workday Account.

    This requires the API call GetWorkdayAccount, from WorkDay's v34.1 API

    Here's the API documentation that specifies the XML for that call: https://community.workday.com/sites/default/files/file-hosting/productionapi/HumanResources/v34.1/GetWorkday_Account.html

    4 votes
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →
  15. Date time comparison in scoping filter of Workday to AD provisioning service

    We want to control user provisioning/deprovisioning based on termination date comparing it with current date using scoping filter.
    Can you please introduce this feature so that it will ease implementation process.

    Reason: In some environment we need to control this with time comparison.

    3 votes
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →
  16. Workday to Azure AD provisioning application under attribute mapping, under target object action delete feature deleting users in Azure

    Workday to Azure AD provisioning application

    under attribute mapping, under target object action delete feature deleting users from Azure AD. Instead of deleting user from Azure AD the account should disable in AD

    2 votes
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    under review  ·  0 comments  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →
  17. *Workday to Azure AD UPN attribute our requirement is upn and email should create like this firstnamefirstletterandlastname@domain.com.au

    *Workday to Azure AD UPN attribute

    our requirement is upn and email should create like this firstnamefirstletterandlastname@domain.com.au
    for Example

    Firstname : Sam
    lastname :Dood
    upn should like this sdood@domain.com.au
    With the help of an expression its creating no issue.

    Issue is if we have a duplicate user and if the upn already exist in Azure AD ,based on our expression user is not provisioning .Not sure the expression is correct.
    we need to create upn based on this requirement firstnamefirst2letterandlastname@domain.com.au

    for example Samson Dood
    First Name : Samson
    Last Name :Dood

    UPN should create like this : sadood@domain.com.au

    Please provide…

    2 votes
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    3 comments  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →

    Currently SelectUniqueValue function only works with Workday/SuccessFactors to on-premises AD User Provisioning app.
    After further review, realized that this feedback item is a request to enable use of SelectUniqueValue function in the Workday to Azure AD User Provisioning App. Hence reactivating it. This is in our backlog, but not scheduled yet.

  18. workday inbound provisioning - allow remote mailbox enable task during provisioning for hybrid Exchange scenario

    Allow the execution of Powershell commands as task during provisioning. In that case also "enable-RemoteMailbox" task is possible to automate and therefore no separate tasks are needed outside the provisioning engine and it can all be integrated.

    2 votes
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →
  19. Create a standard API for Inbound Provisioning

    Create a standardized API that can be used for inbound provisioning.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →
  20. workday

    Regarding Workday integration with AD, will you update the Azure AD User Provisioning Service/tool to sync photos from Workday to AD? It would need to read the data for a jpg file (the photo from workday) into a byte-encoded object and then stamp that data on the thumbnailphoto attribute of the AD account.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Provisioning from Cloud HR  ·  Flag idea as inappropriate…  ·  Admin →
← Previous 1
  • Don't see your idea?

Feedback and Knowledge Base