-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy path1-AADSyncRule_Basic.ps1
More file actions
67 lines (61 loc) · 2.13 KB
/
Copy path1-AADSyncRule_Basic.ps1
File metadata and controls
67 lines (61 loc) · 2.13 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
<#
.EXAMPLE 1
This example creates a basic inbound sync rule for users from Active Directory.
The rule includes scope filtering to only sync employees and sets up basic
attribute flow mappings.
#>
configuration Example_AADSyncRule_Basic
{
Import-DscResource -ModuleName AADConnectDsc
node localhost
{
AADSyncRule 'BasicUserRule'
{
Name = 'Example - Inbound - User - Basic'
ConnectorName = 'contoso.com'
Description = 'Basic user sync rule example'
Direction = 'Inbound'
TargetObjectType = 'person'
SourceObjectType = 'user'
LinkType = 'Provision'
Precedence = 0
Disabled = $false
# Scope filter - only sync enabled employees
ScopeFilter = @(
@{
ScopeConditionList = @(
@{
Attribute = 'userAccountControl'
ComparisonOperator = 'NOTEQUAL'
ComparisonValue = '514' # Account disabled
},
@{
Attribute = 'employeeType'
ComparisonOperator = 'EQUAL'
ComparisonValue = 'Employee'
}
)
}
)
# Basic attribute mappings
AttributeFlowMappings = @(
@{
Source = 'givenName'
Destination = 'firstName'
FlowType = 'Direct'
},
@{
Source = 'sn'
Destination = 'lastName'
FlowType = 'Direct'
},
@{
Source = 'mail'
Destination = 'mail'
FlowType = 'Direct'
}
)
Ensure = 'Present'
}
}
}