Skip to main content

We have an attribute “employeenumber” from on-premAD which is syncd to Entra. Was trying to use this for my directory attribute match for the privileged access but on the drop-down selection in BeyondInsight, it only shows “employeenumber” as the attribute name but the actual Entra attribute name is supposed to be “extensionattribute_<appreg_clientID>employeenumber”. 

Is there a way to map this to an on-premAD “employeenumber” attribute but use Entra for my requester group? I am just not sure if it PS will recognize it since it s trying to map the requester (from Entra SAML SSO) against the  on-prem AD attribute.

Currently the employeenumber for Entra ID is not supported. 

https://beyondtrustcorp.service-now.com/csm?id=kb_article&sysparm_article=KB0021516


thanks ​@Howard , I didn’t realize we cannot use that. I would assume that the on-prem AD attribute employeeID, which is currently not used can be re-purposed for this instead.


Yes the employeeID can be used. 

https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sysparm_article=KB0018945