Skip to content

Map Entra email attribute through Coalesce, not mail#537

Open
dopey wants to merge 1 commit into
mainfrom
worktree-fix-entra-email-mapping
Open

Map Entra email attribute through Coalesce, not mail#537
dopey wants to merge 1 commit into
mainfrom
worktree-fix-entra-email-mapping

Conversation

@dopey

@dopey dopey commented Jul 25, 2026

Copy link
Copy Markdown
Contributor

The Entra SCIM tutorial told readers to leave
emails[type eq "work"].value at its default Direct mapping from mail. Microsoft documents that mail "is only populated if the user has a Microsoft Exchange Mailbox," and that Entra skips null attributes rather than sending them, so users without a mailbox sync into Smallstep with no email address at all. SSO login matches users by email, so those users appear correctly provisioned in the directory but cannot sign in — they get "You are not authorized to access this account," which also wrongly suggests email/password as a fallback that directory users do not have.

Map the attribute through Coalesce([mail],[userPrincipalName]) instead — Microsoft's own documented example for exactly this case — and link the reference docs. Also note that mapping changes require Restart provisioning to reach already-synced users, and add a troubleshooting entry for the sign-in failure.

The screenshot in graphics/entra-id-mappings.png still shows the mail mapping; the text now calls that out until it can be retaken

The Entra SCIM tutorial told readers to leave
`emails[type eq "work"].value` at its default Direct mapping from
`mail`. Microsoft documents that `mail` "is only populated if the user
has a Microsoft Exchange Mailbox," and that Entra skips null attributes
rather than sending them, so users without a mailbox sync into
Smallstep with no email address at all. SSO login matches users by
email, so those users appear correctly provisioned in the directory but
cannot sign in — they get "You are not authorized to access this
account," which also wrongly suggests email/password as a fallback that
directory users do not have.

Map the attribute through `Coalesce([mail],[userPrincipalName])`
instead — Microsoft's own documented example for exactly this case — and
link the reference docs. Also note that mapping changes require Restart
provisioning to reach already-synced users, and add a troubleshooting
entry for the sign-in failure.

The screenshot in graphics/entra-id-mappings.png still shows the `mail`
mapping; the text now calls that out until it can be retaken.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@dopey
dopey requested a review from a team as a code owner July 25, 2026 02:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant