Skip to content

Step 2: Populate the Custom Attributes ​

There are few options for populating these attributes. Choose the method that best fits your scenario.

Option A: Manual Population (For testing or small numbers of users) ​

  1. Go to Users: In the Entra ID admin center, navigate to Identity > Users > All users.

  2. Select a user: Click on the user you want to modify.

  3. Edit user properties: Click Custom security attributes under the 'Manage' section.

  4. Add assignment: Click Add assignment.

  5. Select attribute set and attribute: Choose the relevant attribute set (if applicable) and then select the account_level, account_id, account_billing_id attributes.

  6. Enter values: Input the appropriate values for each attribute.

  7. Save: Click Save to apply the changes.

  8. Repeat steps 2-7 for each user.

This method allows you to programmatically update user attributes, which is essential for any real-world application. You'll need to write a script or application to interact with the Microsoft Graph API.

  1. Register an application in Entra ID: This application will need permissions to read and write user attributes.

    • Go to Identity > Applications > App registrations > New registration.

    • Give your application a name (e.g., "User Attribute Sync").

    • Choose the appropriate supported account types.

    • Register the application.

  2. Create the Extension Attributes using Microsoft Graph Explorer:

    • Go to https://developer.microsoft.com/en-us/graph/graph-explorer

    • Sign in with your Entra ID administrator account.

    • Select POST from the HTTP method dropdown.

    • Set the API version to v1.0.

    • Set the request URL to: https://graph.microsoft.com/v1.0/applications/{extension-app-object-id}/extensionProperties

      • How to get {extension-app-object-id}: Go back to your "Extension App" registration in the Azure portal. You're looking for the Object ID, not the Client ID. It's usually found in the "Overview" blade of the app registration.
    • In the Request body (JSON):

      json
      {
        "name": "account_level",
        "dataType": "String",
        "targetObjects": [
          "User"
        ]
      }
    • And for account_id:

      json
      {
        "name": "account_id",
        "dataType": "String",
        "targetObjects": [
          "User"
        ]
      }
    • And for account_billing_id:

      json
      {
        "name": "account_billing_id",
        "dataType": "String",
        "targetObjects": [
          "User"
        ]
      }
    • Run Query. If successful, you'll get a 201 Created response.

    • Important: The actual name of the created extension attribute will be in the format extension_{clientId}_attributeName. For example, extension_abcdef1234567890_account_level. Make a note of these full, generated names. These are the "custom keys" you're looking for.