List of attributes that are synced by Microsoft Intune

Applies to: Microsoft Intune


This article documents the attributes that are synced from the on-premises Active Directory Domain Services (AD DS) to Microsoft Intune.

More Information

The following table lists the attributes that are synced from the on-premises AD DS to Microsoft Intune.

Note Be aware that objects must contain values in the following attributes to be considered for sync:

Attribute nameUserContactGroupIntune requiredDescription of attribute
AccountEnabledXXStates whether the account is active
cXXXCountry code
cnXXCommon name of the object
descriptionXXXXHuman-readable descriptive phrases about the object
displayNameXXXXDisplay name for the object, usually the combination of the user's first name, middle initial, and last name
mailXXXXLists the email addresses for a user or contact
mailnicknameXXXXFriendly name for mail
memberXXObject, not attribute
objectSIDXUnique object ID
proxyAddressesXXXXThe address by which a Microsoft Exchange Server recipient object is recognized in a foreign mail system
pwdLastSetXStores the time of last password change
securityEnabledXXSpecifies whether the group is a security group
sourceAnchorXXEach account in your local on-premises environment will be linked to the corresponding Azure AD account through the sourceAnchor value
usageLocationXUsage location