Step 2: Populate the Custom Attributes
There are few options for populating these attributes. Choose the method that best fits your scenario.
Option A: Manual Population (For testing or small numbers of users)
Go to Users: In the Entra ID admin center, navigate to Identity > Users > All users.
Select a user: Click on the user you want to modify.
Edit user properties: Click Custom security attributes under the 'Manage' section.
Add assignment: Click Add assignment.
Select attribute set and attribute: Choose the relevant attribute set (if applicable) and then select the
account_level,account_id,account_billing_idattributes.Enter values: Input the appropriate values for each attribute.
Save: Click Save to apply the changes.
Repeat steps 2-7 for each user.
Option B: Using Microsoft Graph API (Recommended for most scenarios)
This method allows you to programmatically update user attributes, which is essential for any real-world application. You'll need to write a script or application to interact with the Microsoft Graph API.
Register an application in Entra ID: This application will need permissions to read and write user attributes.
Go to Identity > Applications > App registrations > New registration.
Give your application a name (e.g., "User Attribute Sync").
Choose the appropriate supported account types.
Register the application.
Create the Extension Attributes using Microsoft Graph Explorer:
Go to https://developer.microsoft.com/en-us/graph/graph-explorer
Sign in with your Entra ID administrator account.
Select POST from the HTTP method dropdown.
Set the API version to v1.0.
Set the request URL to:
https://graph.microsoft.com/v1.0/applications/{extension-app-object-id}/extensionProperties- How to get
{extension-app-object-id}: Go back to your "Extension App" registration in the Azure portal. You're looking for the Object ID, not the Client ID. It's usually found in the "Overview" blade of the app registration.
- How to get
In the Request body (JSON):
json{ "name": "account_level", "dataType": "String", "targetObjects": [ "User" ] }And for
account_id:json{ "name": "account_id", "dataType": "String", "targetObjects": [ "User" ] }And for
account_billing_id:json{ "name": "account_billing_id", "dataType": "String", "targetObjects": [ "User" ] }Run Query. If successful, you'll get a
201 Createdresponse.Important: The actual name of the created extension attribute will be in the format
extension_{clientId}_attributeName. For example,extension_abcdef1234567890_account_level. Make a note of these full, generated names. These are the "custom keys" you're looking for.
