立即与支持人员聊天
与支持团队交流

Active Roles 8.1.1 - Synchronization Service Administration Guide

Synchronization Service overview Deploying Synchronization Service Getting started Connections to external data systems
External data systems supported with built-in connectors
Working with Active Directory Working with an AD LDS (ADAM) instance Working with Skype for Business Server Working with Oracle Database Working with Oracle Database user accounts Working with Exchange Server Working with Active Roles Working with One Identity Manager Working with a delimited text file Working with Microsoft SQL Server Working with Micro Focus NetIQ Directory Working with Salesforce Working with ServiceNow Working with Oracle Unified Directory Working with an LDAP directory service Working with an OpenLDAP directory service Working with IBM DB2 Working with IBM AS/400 Working with IBM RACF Working with MySQL database Working with an OLE DB-compliant relational database Working with SharePoint Working with Microsoft 365 Working with Microsoft Azure Active Directory Configuring data synchronization with the SCIM Connector Configuring data synchronization with the Generic SCIM Connector Objects and operations supported by the SCIM Connector Example of using the Generic SCIM Connector for data synchronization
Using connectors installed remotely Creating a connection Renaming a connection Deleting a connection Modifying synchronization scope for a connection Using connection handlers Specifying password synchronization settings for a connection
Synchronizing identity data Mapping objects Automated password synchronization Synchronization history Scenarios of use Developing PowerShell scripts for attribute synchronization rules Using PowerShell script to transform passwords

Microsoft 365 data supported out of the box

The next table lists the Microsoft 365 object types supported by the Office 365 Connector out of the box and provides information about the operations you can perform on these objects by using the Office 365 Connector.

Table 74: Supported objects and operations

Object

Read

Create

Delete

Update

ClientPolicy

Allows you to work with client policies in Skype for Business Online. You can use client policies to determine the features of Skype for Business Online that are available to users.

For more information on what data you can read and write, see ClientPolicy object attributes.

Yes

No

No

No

ConferencingPolicy

Allows you to work with conferencing policies in Skype for Business Online. You can use conferencing policies to determine the features available to the users participating in a conference.

For more information on what data you can read and write, see ConferencingPolicy object attributes.

Yes

No

No

No

Contact

Allows you to work with external contact properties in Microsoft 365.

For more information on what data you can read and write, see Contact object attributes.

Yes

Yes

Yes

Yes

DistributionGroup

Allows you to work with distribution group properties in Microsoft 365.

For more information on what data you can read and write, see DistributionGroup object attributes.

Yes

Yes

Yes

Yes

Domain

Allows you to retrieve information about domains in Microsoft 365.

For more information on what data you can retrieve, see Domain object attributes.

Yes

No

No

No

DynamicDistributionGroup

Allows you to work with dynamic distribution group properties in Microsoft 365.

For more information on what data you can read and write, see DynamicDistributionGroup object attributes.

Yes

Yes

Yes

Yes

ExternalAccessPolicy

Allows you to work with external access policies in Skype for Business Online.

For more information on what data you can read and write, see ExternalAccessPolicy object attributes.

Yes

No

No

No

HostedVoicemailPolicy

Allows you to work with voice mail policies in Skype for Business Online.

For more information on what data you can read and write, see HostedVoicemailPolicy object attributes.

Yes

No

No

No

LicensePlanService

Allows you to retrieve information related to the license plans and services that are currently in use in Microsoft 365.

For more information on what data you can read and write, see LicensePlanService object attributes.

Yes

No

No

No

Mailbox

Allows you to work with Exchange Online mailboxes in Microsoft 365.

For more information on what data you can read and write, see Mailbox object attributes.

Yes

Yes

Yes

Yes

MailUser

Allows you to work with mail user properties in Microsoft 365.

For more information on what data you can read and write, see MailUser object attributes.

Yes

Yes

Yes

Yes

PresencePolicy

Allows you to work with presence policies in Skype for Business Online.

For more information on what data you can read and write, see PresencePolicy object attributes.

Yes

No

No

No

SecurityGroup

Allows you to work with security group properties in Microsoft 365.

For more information on what data you can read and write, see SecurityGroup objects attributes.

Yes

Yes

Yes

Yes

SPOSite

Allows you to work with the properties of site collections in SharePoint Online.

For more information on what data you can read and write, see SPOSite object attributes.

Yes

Yes

Yes

Yes

SPOSiteGroup

Allows you to work with groups inside site collections in SharePoint Online.

For more information on what data you can read and write, see SPOSiteGroup object attributes.

Yes

Yes

Yes

Yes

SPOWebTemplate

Allows you to work with web templates in SharePoint Online.

For more information on what data you can read and write, see SPOWebTemplate object attributes.

Yes

No

No

No

SPOTenant

Allows you to work with SharePoint Online organization.

For more information on what data you can read and write, see SPOTenant object attributes.

Yes

No

No

Yes

User

Allows you to read and write user properties in Microsoft 365.

For more information on what data you can read and write, see User object attributes.

Yes

Yes

Yes

Yes

VoicePolicy

Allows you to read or write data related to voice policies in Skype for Business Online.

For more information on what data you can read and write, see VoicePolicy object attributes.

Yes

No

No

No

Microsoft 365 Group

Allows you to read or write data related to Microsoft 365 group.

For more information on what data you can read and write, see Microsoft 365 group attributes.

Yes

Yes Yes Yes

ClientPolicy object attributes

Table 75: ClientPolicy object attributes

Attribute

Description

Supported operations

Anchor

Gets the Anchor property value of the policy.

Read

Description

Gets the policy description.

Read

Identity

Gets the unique identifier assigned to the policy.

Read

Members

Gets the users who have been assigned the policy.

Read

ObjectID

Gets the unique object identifier (GUID).

Read

ConferencingPolicy object attributes

Table 76: ConferencingPolicy object attributes

Attribute

Description

Supported operations

Anchor

Gets the Anchor property value of the policy.

Read

Description

Gets the policy description.

Read

Identity

Gets the unique identifier assigned to the policy.

Read

Members

Gets the users who have been assigned the policy.

Read

ObjectID

Gets the unique object identifier (GUID).

Read

Contact object attributes

Table 77: Contact object attributes

Attribute

Description

Supported operations

AcceptMessagesOnlyFrom

Gets or sets the senders that can send email messages to the contact.

This reference attribute can take senders in any of the following formats:

  • Alias

  • Canonical name

  • Display name

  • DN

  • Exchange DN

  • GUID

  • Name

  • Primary SMTP email address

This reference attribute accepts the following object types:

  • MailUser

  • Mailbox

  • Contact

Read, Write

AcceptMessagesOnlyFromDLMembers

Gets or sets the distribution groups whose members are allowed to send email messages to the contact.

This reference attribute can take distribution groups in any of the following formats:

  • Canonical name

  • Display name

  • DN

  • GUID

  • Legacy Exchange DN

  • Name

  • Primary SMTP email address

This reference attribute accepts the following object types:

  • DistributionGroup

  • DynamicDistributionGroup

Read, Write

AcceptMessagesOnlyFromSendersOrMembers

Gets or sets the senders who can send email messages to the contact.

This reference attribute can take senders in any of the following formats:

  • Canonical name

  • Display name

  • Distinguished name (DN)

  • GUID

  • Legacy Exchange DN

  • Name

  • Primary SMTP email address

This reference attribute accepts the following object types:

  • Contact

  • DistributionGroup

  • DynamicDistributionGroup

  • Mailbox

  • MailUser

Read, Write

Alias

Gets or sets the alias of the mail-enabled contact.

Read, Write

AllowUMCallsFromNonUsers

Gets or sets whether to exclude or include the contact in directory searches.

This attribute can take one of the following values:

  • None: Specifies to exclude the contact from directory searches.

  • SearchEnabled: Specifies to include the contact in directory searches.

Read, Write

AssistantName

Gets or sets the name of the contact’s assistant.

Read, Write

BypassModerationFromSendersOrMembers

Gets or sets the senders whose messages bypass moderation for the contact.

This reference attribute can take any of the following values for the senders:

  • Canonical name

  • Display name

  • Distinguished name (DN)

  • GUID

  • Name

  • Legacy Exchange DN

  • Primary SMTP email address

  • Moderation does not apply to the senders designated as moderators for the contact.

  • This reference attribute accepts the following object types:

  • Contact

  • DistributionGroup

  • DynamicDistributionGroup

  • Mailbox

  • MailUser

Read, Write

City

Gets or sets the city of the contact.

Read, Write

Company

Gets or sets the company of the contact.

Read, Write

CountryOrRegion

Gets or sets the country or region of the contact.

Read, Write

CreateDTMFMap

Gets or sets whether to create a dual-tone multi-frequency (DTMF) map for the contact.

This attribute can take one of the following values:

  • TRUE: Specifies to create a DTMF map for the contact.

  • FALSE: Specifies not to create a DTMF map for the contact.

Read, Write

CustomAttribute1

Get or set the additional custom values you specify.

Read, Write

CustomAttribute2

CustomAttribute3

CustomAttribute4

CustomAttribute5

CustomAttribute6

CustomAttribute7

CustomAttribute8

CustomAttribute9

CustomAttribute10

CustomAttribute11

CustomAttribute12

CustomAttribute13

CustomAttribute14

CustomAttribute15

Department

Gets or sets the department of the contact.

Read, Write

DisplayName

Gets or sets the name displayed in Microsoft 365 for the mail-enabled contact.

Read, Write

EmailAddresses

Gets or sets the email alias of the contact.

Read, Write

ExtensionCustomAttribute1

Get or set the additional custom values you specify. These attributes are multivalued. To specify multiple values, use a comma as a separator.

Read, Write

ExtensionCustomAttribute2

ExtensionCustomAttribute3

ExtensionCustomAttribute4

ExtensionCustomAttribute5

ExternalDirectoryObjectId

Gets the GUID of the contact.

Read

ExternalEmailAddress

Gets or sets the contact’s e-mail address.

Read, Write

Fax

Gets or sets the fax number of the contact.

Read, Write

FirstName

Gets or sets the first name of the mail-enabled contact.

Read, Write

GrantSendOnBehalfTo

Gets or sets the distinguished name (DN) of other senders that can send messages on behalf of the contact.

This reference attribute only accepts the following object type:

  • Mailbox

Read, Write

HiddenFromAddressListsEnabled

Gets or sets whether or not Microsoft 365 hides the contact from the address lists.

This attribute can take one of the following values:

  • TRUE: Specifies to hide the contact from the address lists.

  • FALSE (default): Specifies to display the contact in the address lists.

Read, Write

HomePhone

Gets or sets the home phone number of the contact.

Read, Write

Initials

Gets or sets the initials of the mail-enabled contact.

Read, Write

LastName

Gets or sets the last name of the mail-enabled contact.

Read, Write

MacAttachmentFormat

Gets or sets the Apple Macintosh operating system attachment format for messages sent to the contact.

This attribute can take the following values:

  • BinHex

  • UuEncode

  • AppleSingle

  • AppleDouble

Read, Write

MailTip

Gets or sets the message displayed to senders when they start writing an email message to the contact.

Read, Write

MailTipTranslations

Gets or sets the MailTip message translations in additional languages.

This attribute accepts the following format:

<LanguageLocale>:<MailTipMessageTranslation>

A MailTip message translation cannot exceed 250 characters.

Read, Write

Manager

Gets or sets the manager of the contact.

Read, Write

MaxRecipientPerMessage

Gets or sets the maximum number of recipients to which the contact can address a message.

Read, Write

MessageBodyFormat

Gets or sets the message body format for messages sent to the contact.

The values this attribute can write depend on the value in the MessageFormat attribute.

When the value in the MessageFormat is Mime, the MessageBodyFormat attribute can write the following values:

  • Text

  • Html

  • TextAndHtml

When the value in the MessageFormat is Text, the MessageBodyFormat attribute can only write the Text value.

Read, Write

MessageFormat

Gets or sets the message format for messages sent to the contact.

This attribute can take the following values:

  • Text

  • Mime

Read, Write

MobilePhone

Gets or sets the mobile phone number of the contact.

Read, Write

ModeratedBy

Gets or sets the moderators who are moderating the messages sent to the contact. To specify multiple moderators, use a comma as a separator.

This reference attribute is required if you set the value of the ModerationEnabled attribute to TRUE.

This reference attribute accepts the following object types:

  • Mailbox

  • MailUser

Read, Write

ModerationEnabled

Gets or sets whether moderation is enabled for the contact.

This attribute can take one of the following values:

  • TRUE

  • FALSE

Read, Write

Name

Gets or sets the name of the mail-enabled contact.

Read, Write

Notes

Gets or sets notes about the contact.

Read, Write

ObjectID

Gets the unique object identifier (GUID).

Read

Office

Gets or sets the office of the contact.

Read, Write

OtherFax

Gets or sets the alternate fax number of the contact.

Read, Write

OtherHomePhone

Gets or sets the alternate home phone number of the contact.

Read, Write

Pager

Gets or sets the pager of the contact.

Read, Write

Phone

Gets or sets the work phone number of the contact.

Read, Write

PhoneticDisplayName

Gets or sets a phonetic pronunciation of the value specified in the DisplayName attribute for the contact.

Read, Write

PostalCode

Gets or sets the postal code of the contact.

Read, Write

PostOfficeBox

Gets or sets the post office box number of the contact.

Read, Write

RejectMessagesFrom

Gets or sets the senders whose messages to the contact are rejected.

This attribute can take senders in one of the following formats:

  • Alias

  • Canonical name

  • Display name

  • Distinguished name (DN)

  • GUID

  • Name

  • Legacy Exchange DN

  • Primary SMTP email address

This reference attribute accepts the following object types:

  • Contact

  • Mailbox

Read, Write

RejectMessagesFromDLMembers

Gets or sets the distribution groups whose members cannot send email messages to the contact (their messages are rejected).

This reference attribute can take distribution groups in one of the following formats:

  • Alias

  • Canonical name

  • Display name

  • Distinguished name (DN)

  • GUID

  • Legacy Exchange DN

  • Name

  • Primary SMTP email address

This reference attribute accepts the following object types:

  • DistributionGroup

  • DynamicDistributionGroup

Read, Write

RejectMessagesFromSendersOrMembers

Gets or sets the senders that cannot send email messages to the contact (their messages are rejected).

This reference attribute can take any of the following values for the senders:

  • Alias

  • Canonical name

  • Display name

  • Distinguished name (DN)

  • GUID

  • Name

  • Legacy Exchange DN

  • Primary SMTP email address

This reference attribute accepts the following object types:

  • Contact

  • DistributionGroup

  • DynamicDistributionGroup

  • Mailbox

Read, Write

RequireSenderAuthenticationEnabled

Gets or sets whether the senders that send messages to this contact must be authenticated.

This attribute can take one of the following values:

  • TRUE

  • FALSE

Read, Write

SecondaryAddress

Gets or sets the secondary address for the contact if it has Unified Messaging enabled.

Read, Write

SecondaryDialPlan

Gets or sets a secondary Unified Messaging dial plan for the contact.

Read, Write

SendModerationNotifications

Gets or sets whether to send status notifications to users when a message they sent to the moderated distribution group is rejected by a moderator.

This attribute can take one of the following values:

  • Always: Specifies that notifications are sent to all senders.

  • Internal: Specifies that notifications are only sent to the senders internal to your organization.

  • Never: Specifies that all status notifications are disabled.

Read, Write

SimpleDisplayName

Gets or sets an alternate description of the contact in a situation where a limited set of characters is allowed.

The limited set of characters includes ASCII characters from 26 to 126.

Read, Write

StateOrProvince

Gets or sets the state or province of the contact.

Read, Write

StreetAddress

Gets or sets the street address of the contact.

Read, Write

TelephoneAssistant

Gets or sets the phone number of the contact’s assistant.

Read, Write

Title

Gets or sets the title of the contact.

Read, Write

UMCallingLineIds

Gets or sets telephone numbers or telephone extensions that can be mapped to the contact if it has Unified Messaging enabled.

To specify multiple telephone numbers use a comma as a separator.

This attribute only accepts values that have less than 128 characters.

Read, Write

UMDtmfMap

Gets or sets whether to create a user-defined DTMF map for the contact if it has Unified Messaging enabled.

Read, Write

UseMapiRichTextFormat

Gets or sets a format for the MAPI Rich Text Format messages sent to the contact.

This attribute can take one of the following values:

  • Never: Specifies to convert all messages sent to the contact to the plain text format.

  • Always: Specifies to always use the MAPI Rich Text Format (RTF) for the messages sent to the contact.

  • UseDefaultSettings: Specifies to use the message format set in the MAPI client that sent the message to the contact.

Read, Write

UsePreferMessageFormat

Gets or sets whether the message format specified for the contact overrides any global settings (such as those configured for the remote domain).

This attribute can take one of the following values:

  • TRUE: Specifies that the message format set for the mail user overrides any global settings.

  • FALSE: Specifies that global settings have precedence over the mail format set for the mail user.

Read, Write

WebPage

Gets or sets the web page address of the contact.

Read, Write

WindowsEmailAddress

Gets or sets the email address of the contact stored in Active Directory.

Read, Write

相关文档

The document was helpful.

选择评级

I easily found the information I needed.

选择评级