Aggregation, Filter, and Partitioning Settings

When configuring the filters, consider that the connector prioritizes account filters over group filters during aggregation. For example, the connector aggregates groups, which fall outside of the group filter, if the group is associated with an account included within the account filter.


This is the companion discussion topic for the documentation at https://documentation.sailpoint.com/connectors/microsoft/entra_id/help/integrating_entra_id/aggregation_settings.html

Please update the documentation to say if using Advanced Account filter, then you must delete the manager attribute from the account schema

If you dont, you get the error 'ConsistencyLevel:eventual' header is missing.

Similarly, if you want to use the Advanced Group Filter, then you must delete the owners attribute from the group schema.

This needs to be explicitly called out.
If not for the forum, i would never have found the answer.

Azure Active Directory Connector, User filter - IdentityIQ (IIQ) / IIQ Discussion and Questions - SailPoint Developer Community
Azure Active Directory source - Advanced user filter - Identity Security Cloud (ISC) / ISC Discussion and Questions - SailPoint Developer Community

Thank you

Hi Jason, we currently have that information in the topic. The second bullet in the note for that section mentions that you need to delete the manager attribute when using the advanced filters.