May 2019
Intermediate to advanced
620 pages
21h 41m
English
In hybrid identity, where Active Directory and Azure AD work together, an attribute needs to be agreed upon to be the end-to-end identifier. In some synchronization solutions, this attribute is called the ImmutableId. In Azure AD Connect, it's called the sourceAnchor.
For synchronization purposes, this attribute needs to be immutable, meaning it doesn't change during the lifetime of an object, and unique. That's why an email address or surname make for bad sourceAnchor attributes: the email address might change when someone gets married. A surname might not be unique throughout the organization.
Beyond immutability and uniqueness, the attribute value for a sourceAnchor attribute must be fewer than 60 characters in length; ...