# AttributeSync ProxyAddresses

**URL:** <https://developer.sailpoint.com/discuss/t/attributesync-proxyaddresses/207107>\
**Category:** SHF Discussion and Questions\
**Tags:** provisioning, identity-security-cloud, active-directory\
**Created:** [May 7, 2026, 12:48pm UTC](https://developer.sailpoint.com/discuss/t/attributesync-proxyaddresses/207107 "2026-05-07T12:48:05Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![DivyaL\_7](https://avatars.discourse-cdn.com/v4/letter/d/db5fbb/32.png) [@DivyaL\_7](https://developer.sailpoint.com/discuss/u/DivyaL_7)\
**Post date:** [May 7, 2026, 12:48pm UTC](https://developer.sailpoint.com/discuss/t/attributesync-proxyaddresses/207107/1 "2026-05-07T12:48:06Z")

</div>

Hello Community,

We are currently syncing the AD `proxyAddresses` attribute from an identity attribute that contains the expected list of proxy addresses.

However, we are seeing sync/provisioning events being triggered even when the identity attribute value has not actually changed.

My assumption is that the issue may be related to the order of the values. For example, the identity attribute contains:

`[proxyAddress1, proxyAddress2, proxyAddress3]`

while the AD account attribute contains:

`[proxyAddress3, proxyAddress1, proxyAddress2]`

The values are the same, but the order is different.

Has anyone encountered this behavior before with multi-valued attributes such as `proxyAddresses`? If so, how did you handle the comparison/synchronization to avoid unnecessary provisioning events?

Thanks in advance for your help.

---

<div class="post-metadata">

**Author:** ![bcariaga](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/bcariaga/32/1890_2.png) [@bcariaga](https://developer.sailpoint.com/discuss/u/bcariaga)\
**Post date:** [May 7, 2026, 2:45pm UTC](https://developer.sailpoint.com/discuss/t/attributesync-proxyaddresses/207107/2 "2026-05-07T14:45:08Z")

</div>

ISC does not truly hold the multi-valued attributes as an array in the identity attributes. Instead, it is translated into a comma separated string. This causes the equality check to fail on each refresh.

I’d recommend following this approach for achieving the multi-valued syncing: [Multivalued Attribute Sync](https://developer.sailpoint.com/discuss/t/multivalued-attribute-sync/16219)

---

<div class="post-metadata">

**Author:** ![DivyaL\_7](https://avatars.discourse-cdn.com/v4/letter/d/db5fbb/32.png) [@DivyaL\_7](https://developer.sailpoint.com/discuss/u/DivyaL_7)\
**Post date:** [May 29, 2026, 8:58am UTC](https://developer.sailpoint.com/discuss/t/attributesync-proxyaddresses/207107/3 "2026-05-29T08:58:58Z")

</div>

Hello @bcariaga,

Yhank you for your reply, and sorry for my late response.

The approach you recommended seems a litte bit too complex to implement, and I also noticed it dates back to 2023.

I was wondering whether there have been any improvements or new capabilities introduced in ISC since then that would allow synchronization of multi-valued attributes in a simpler way.

Thank you very much for your help,

---

<div class="post-metadata">

**Author:** ![pradeep1602](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/pradeep1602/32/30858_2.png) [@pradeep1602](https://developer.sailpoint.com/discuss/u/pradeep1602)\
**Post date:** [May 30, 2026, 4:41am UTC](https://developer.sailpoint.com/discuss/t/attributesync-proxyaddresses/207107/4 "2026-05-30T04:41:42Z")

</div>

> [@DivyaL\_7](#):
>
> I was wondering whether there have been any improvements or new capabilities introduced in ISC since then that would allow synchronization of multi-valued attributes in a simpler way.

Hi @DivyaL_7  
Unfortunately that is how attribute sync works.  
As mentioned previously by Braden that it is due to how ISC stores values version how is it stored in the application.  
I would recommend not to use ISC to sync proxy addresses since after every import it will trigger too many sync request which could lead to some serious performance issues.

Regards,  
Pradeep

---

<div class="post-metadata">

**Author:** ![RAKGDS](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/rakgds/32/2795_2.png) [@RAKGDS](https://developer.sailpoint.com/discuss/u/RAKGDS)\
**Post date:** [May 30, 2026, 11:25am UTC](https://developer.sailpoint.com/discuss/t/attributesync-proxyaddresses/207107/5 "2026-05-30T11:25:45Z")

</div>

Hi @Divya,

You might need to write a transform for this on the Identity Attribute and do a check by yourself that if the value are the same then Active Directory should take precedence.

Let me know if you need any help in the same

---

<div class="post-metadata">

**Author:** ![baoussounda](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/baoussounda/32/13095_2.png) [@baoussounda](https://developer.sailpoint.com/discuss/u/baoussounda)\
**Post date:** [June 1, 2026, 5:19pm UTC](https://developer.sailpoint.com/discuss/t/attributesync-proxyaddresses/207107/6 "2026-06-01T17:19:21Z")

</div>

Hi @DivyaL_7 ,

Rather than using Identity Attribute Sync, we generally use Before Provisioning Rules or connector Before/After Rules to synchronize `proxyAddresses`.

Since `proxyAddresses` is a multi-valued attribute and identity attributes in ISC do not natively support multi-valued attributes (only string values), it is difficult to implement this seamlessly using ISC’s native Attribute Sync.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [July 31, 2026, 5:19pm UTC](https://developer.sailpoint.com/discuss/t/attributesync-proxyaddresses/207107/7 "2026-07-31T17:19:24Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
