Configuring the data source for Azure AD synchronization

2026-02-03Last updated

Before you can synchronize an external system with Genetec ClearID™, you must first configure the Genetec ClearID™ One Identity Synchronization Tool data sources for Azure Active Directory synchronization.

Before you begin

What you should know

This procedure is for IT or security personnel responsible for external system attributes administration.

This procedure describes how to configure the data source for Azure AD.

  • The data source order is important because the first data source always overrides common fields.
  • There is no limit to the number of data sources. However, larger sources require more memory.
  • When using an Azure data source to synchronize identities, the UserId field is automatically used as the Unique ID. When the Azure data source is selected, the Unique ID fields cannot be configured and use of the Azure UserId field is triggered by default.

Procedure

  1. In the One Identity Synchronization Tool Data sources section, click Add data source ().
    ClearID One Identity Synchronization Tool with Add data source highlighted.
  2. In the Source section, select Azure Active Directory and click Next.
    Data source configuration dialog in the ClearID One Identity Synchronization Tool showing Source settings page with Azure Active Directory selected.
  3. In the Configuration section, complete the following mandatory fields:
    Data source configuration dialog in the ClearID One Identity Synchronization Tool showing Configuration settings page.
    Tenant name
    Enter your Azure tenant name (account name). The tenant name is used to connect to the directory for the account. For example, a host address account.onmicrosoft.com or a GUID nxxnxnxx-nnnn-nxnn-nnnx-nxnnnxnnxnnn.
    Client ID
    Enter your registered Azure client ID. The Client ID format is an alpha-numeric format as follows: nxnxnxxn-xxnn-nnnx-xxnn-nxxxnxnnnxnn.
    App key
    Enter your App key to authenticate the connection. The App key format is an alpha-numeric format as follows: nXnxxxxXxxXnxxxXXXxXXnxxXXXnnxxxXXnXXXXXxxx=.
    Tip:
    The Tenant name, Client ID, and App key can be obtained from your Azure Active Directory application registration.
    1. Click Next.
      Data source configuration dialog in the ClearID One Identity Synchronization Tool showing data source configuration information for Groups and Users being fetched.
      Note:
      Fetching information may take time depending on the number of users and groups.
    2. (Optional) Use the Filter groups option to only synchronize a subset of selected Azure AD groups and group members. Search for or select the groups that you require and click Next.
      Data source configuration dialog in the ClearID One Identity Synchronization Tool showing Configuration page with Filter groups option active and some groups listed.
      Note:
      Use Check all or Uncheck all icons to help with long lists.
  4. In the What to sync section, select Identities to synchronize from the external system data source.
    Data source configuration dialog in the ClearID One Identity Synchronization Tool showing What to sync page with the data synchronization checkbox selected.
  5. If you selected Identities, configure the identity attributes settings.
    Note:
    The fields that are displayed in the Identities section vary depending on the data source you selected in the Source section.
    The following image shows the options that are displayed after selecting an Azure AD data source.
    Data source configuration dialog in the ClearID One Identity Synchronization Tool showing the Identities page including One Identity fields. external fields, sample values, and global key settings.
    1. Configure your External field attribute mappings.
      One Identity field
      Displays the ClearID identity attributes. Mandatory fields are highlighted using an asterisk (*).
      External Field
      Select the corresponding attributes from your external system that you want to map to each ClearID field.
      CAUTION:
      When using Azure AD as your data source, the One Identity Unique ID field must be mapped to the Azure AD User ID external field. This ensures that the identity attributes are correctly mapped and synchronized.
      Sample value
      If available, an example of the external field’s data is shown next to each selected mapping.
      Tip:
      Use the sample value column to check the format of the attributes data you are about to import from your external system fields into ClearID.
    2. (Optional) Click Script () to add a transform expression to find and replace external field text using regular expressions.
      For example, you can look for variations of a country name to replace with the correct country code.
      Add transform expressions for field dialog in the ClearID One Identity Synchronization Tool showing example find and replace expressions that replace the country names with country codes.
      • A script icon () appears in the Sample value column when a transform expression is applied.
      • The transform expressions are processed in the order specified in the Add transform expressions for field dialog.
      Tip:
      To remove an expression, select its row and click .
    3. (Optional) Click Refresh () to update the external fields data from your data source. This refresh option is used if data has changed in the external system, or if new data rows or attribute columns were added.
    4. Click Next.
  6. In the Summary section, review the data that will be synchronized.
    Data source configuration dialog in the ClearID One Identity Synchronization Tool showing the Roles page including One Identity fields. external fields, sample values, and global key settings.
    Note:
    If multiple data sources are selected, only the first data source file is displayed in the Summary section Data source name field. If you want each of the data files listed in the Data sources section, you must add them individually.
    1. If the data synchronization details look correct, click Finish.

After you finish

Configure your synchronization settings.