# Multivalued attribute provisioning in AD

**URL:** <https://developer.sailpoint.com/discuss/t/multivalued-attribute-provisioning-in-ad/84365>\
**Category:** SHF Discussion and Questions\
**Tags:** transforms, provisioning, identity-security-cloud\
**Created:** [October 8, 2024, 1:36pm UTC](https://developer.sailpoint.com/discuss/t/multivalued-attribute-provisioning-in-ad/84365 "2024-10-08T13:36:51Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![Prashanth1812](https://avatars.discourse-cdn.com/v4/letter/p/41988e/32.png) [@Prashanth1812](https://developer.sailpoint.com/discuss/u/Prashanth1812)\
**Post date:** [October 8, 2024, 1:36pm UTC](https://developer.sailpoint.com/discuss/t/multivalued-attribute-provisioning-in-ad/84365/1 "2024-10-08T13:36:51Z")

</div>

Hi everyone,

I’m trying to provision “proxyAddresses” as a multivalued field, and I have referred this doc, but still it provisions as a string but not multi valued, does someone have a working process, TIA.

[Best Practices: Provisioning Multi-Valued Attributes - Compass (sailpoint.com)](https://community.sailpoint.com/t5/IdentityNow-Articles/Best-Practices-Provisioning-Multi-Valued-Attributes/ta-p/153748)

---

<div class="post-metadata">

**Author:** ![jesvin90](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jesvin90/32/5301_2.png) [@jesvin90](https://developer.sailpoint.com/discuss/u/jesvin90)\
**Post date:** [October 8, 2024, 2:26pm UTC](https://developer.sailpoint.com/discuss/t/multivalued-attribute-provisioning-in-ad/84365/2 "2024-10-08T14:26:20Z")

</div>

Hi @Prashanth1812,

Take a look at the below thread, could be helpful.

> [@Multi values syntax for account attributes](https://developer.sailpoint.com/discuss/t/multi-values-syntax-for-account-attributes/17128):
>
> We are setting the proxyaddresses in AD. The JSON has been updated to allow multiple values. However, when setting static values I’m not sure of the syntax to use. If I have the static value set to: [SMTP:user@example.com](mailto:SMTP:user@example.com),smtp:user@example.com It only stores the first value. If I have the static value set to: {SMTP:user@example.com,smtp:user@example.com} to generates multipe values, but retains the curly braces. I have tried quotation marks, which keeps only one value with the full string, ign…

If it still don’t work, please share your account creation policy here so that someone can take a look.

---

<div class="post-metadata">

**Author:** ![Prashanth1812](https://avatars.discourse-cdn.com/v4/letter/p/41988e/32.png) [@Prashanth1812](https://developer.sailpoint.com/discuss/u/Prashanth1812)\
**Post date:** [October 8, 2024, 3:11pm UTC](https://developer.sailpoint.com/discuss/t/multivalued-attribute-provisioning-in-ad/84365/3 "2024-10-08T15:11:12Z")

</div>

This is what i have:

```auto
 {
            "name": "proxyAddresses",
            "transform": {
                "type": "static",
                "attributes": {
                    "name": "proxyAddress"
                }
            },
            "attributes": {
                "cloudDelimiter": ","
            },
            "isRequired": false,
            "type": "string",
            "isMultiValued": true
        }

```

and its still not updating as multivalued on AD.

---

<div class="post-metadata">

**Author:** ![jesvin90](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jesvin90/32/5301_2.png) [@jesvin90](https://developer.sailpoint.com/discuss/u/jesvin90)\
**Post date:** [October 8, 2024, 3:38pm UTC](https://developer.sailpoint.com/discuss/t/multivalued-attribute-provisioning-in-ad/84365/4 "2024-10-08T15:38:21Z")

</div>

Hi @Prashanth1812,

Your overall format for the static transform doesn’t look correct. Where are you getting the proxy value from.?

You will need the comma separated values inside the static value field for this to work. Below is the example :

```auto
{
            "name": "proxyAddresses",
            "transform": {
                "type": "static",
                "attributes": {
                    "value": "smtp:$sAMAccountName@example.mail.onmicrosoft.com,SMTP:$sAMAccountName@example.com"
                }
            },
            "attributes": {
                "cloudDelimiter": ","
            },
            "isRequired": false,
            "type": "string",
            "isMultiValued": true
        },

```

If you are getting the proxyaddress from an identity attribute, something like this should work, given that the identity attribute has commas separated values.

```auto
{
            "name": "proxyAddresses",
            "transform": {
                "type": "identityAttribute",
                "attributes": {
                    "name": "proxyAddress"
                }
            },
            "attributes": {
                "cloudDelimiter": ","
            },
            "isRequired": false,
            "type": "string",
            "isMultiValued": true
        }

```

---

<div class="post-metadata">

**Author:** ![Prashanth1812](https://avatars.discourse-cdn.com/v4/letter/p/41988e/32.png) [@Prashanth1812](https://developer.sailpoint.com/discuss/u/Prashanth1812)\
**Post date:** [October 8, 2024, 3:47pm UTC](https://developer.sailpoint.com/discuss/t/multivalued-attribute-provisioning-in-ad/84365/5 "2024-10-08T15:47:34Z")

</div>

Hi @jesvin90 ,

thanks, but i tried the below, but its still not setting the value as multivalued. Not sure if we are missing config anywhere else.

```auto
{
            "name": "proxyAddresses",
            "transform": {
                "type": "identityAttribute",
                "attributes": {
                    "name": "proxyAddress"
                }
            },
            "attributes": {
                "cloudDelimiter": ","
            },
            "isRequired": false,
            "type": "string",
            "isMultiValued": true
        }

```

---

<div class="post-metadata">

**Author:** ![jesvin90](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jesvin90/32/5301_2.png) [@jesvin90](https://developer.sailpoint.com/discuss/u/jesvin90)\
**Post date:** [October 8, 2024, 3:51pm UTC](https://developer.sailpoint.com/discuss/t/multivalued-attribute-provisioning-in-ad/84365/6 "2024-10-08T15:51:30Z")

</div>

Have you set the proxyAddresses value in the account schema as multi-valued.?

Also, you have the identity attribute with comma separated values.?

---

<div class="post-metadata">

**Author:** ![Prashanth1812](https://avatars.discourse-cdn.com/v4/letter/p/41988e/32.png) [@Prashanth1812](https://developer.sailpoint.com/discuss/u/Prashanth1812)\
**Post date:** [October 8, 2024, 4:04pm UTC](https://developer.sailpoint.com/discuss/t/multivalued-attribute-provisioning-in-ad/84365/7 "2024-10-08T16:04:59Z")

</div>

Yes, that’s correct Jesvin. Both are good. Not sure why it’s still not able to set the values as Multi-valued.

---

<div class="post-metadata">

**Author:** ![KRM7](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/krm7/32/2685_2.png) [@KRM7](https://developer.sailpoint.com/discuss/u/KRM7)\
**Post date:** [October 8, 2024, 6:10pm UTC](https://developer.sailpoint.com/discuss/t/multivalued-attribute-provisioning-in-ad/84365/8 "2024-10-08T18:10:14Z")

</div>

Technically this should work and we have implemented this already.

Can you get me sample value of your ProxyAddress Identity attribute.

Thanks  
Krish

---

<div class="post-metadata">

**Author:** ![Prashanth1812](https://avatars.discourse-cdn.com/v4/letter/p/41988e/32.png) [@Prashanth1812](https://developer.sailpoint.com/discuss/u/Prashanth1812)\
**Post date:** [October 8, 2024, 6:28pm UTC](https://developer.sailpoint.com/discuss/t/multivalued-attribute-provisioning-in-ad/84365/9 "2024-10-08T18:28:29Z")

</div>

Sure Krishna, “test, test1,test2,test3” is the value

![image](https://global.discourse-cdn.com/sailpoint/original/3X/7/9/795ed2d24d8d9d5b58aee883b36c9cd98a25ff33.png)

---

<div class="post-metadata">

**Author:** ![KRM7](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/krm7/32/2685_2.png) [@KRM7](https://developer.sailpoint.com/discuss/u/KRM7)\
**Post date:** [October 8, 2024, 6:32pm UTC](https://developer.sailpoint.com/discuss/t/multivalued-attribute-provisioning-in-ad/84365/10 "2024-10-08T18:32:48Z")

</div>

This should work, I would ask you to perform a testcase. Below is the working config for ProxyAddress in AD create account provisioning policy form.

Hardcode values and try.

```auto
{
            "name": "proxyAddresses",
            "transform": {
                "attributes": {
                    "values": [
                        {
                            "type": "static",
                            "attributes": {
                                "value": "test1"
                            }
                        },
						",",
						{
                            "type": "static",
                            "attributes": {
                                "value": "test2"
                            }
                        }
                    ]
                },
                "type": "concat"
            },
            "attributes": {
                "cloudDelimiter": ","
            },
            "isRequired": false,
            "type": "string",
            "isMultiValued": true
        }

```

---

<div class="post-metadata">

**Author:** ![Prashanth1812](https://avatars.discourse-cdn.com/v4/letter/p/41988e/32.png) [@Prashanth1812](https://developer.sailpoint.com/discuss/u/Prashanth1812)\
**Post date:** [October 8, 2024, 7:26pm UTC](https://developer.sailpoint.com/discuss/t/multivalued-attribute-provisioning-in-ad/84365/12 "2024-10-08T19:26:24Z")

</div>

Thanks Krishna,

let me try this

---

<div class="post-metadata">

**Author:** ![Prashanth1812](https://avatars.discourse-cdn.com/v4/letter/p/41988e/32.png) [@Prashanth1812](https://developer.sailpoint.com/discuss/u/Prashanth1812)\
**Post date:** [October 9, 2024, 4:10pm UTC](https://developer.sailpoint.com/discuss/t/multivalued-attribute-provisioning-in-ad/84365/13 "2024-10-09T16:10:06Z")

</div>

Thanks for the help Jesvin and Krishna,

Basically, I feel the issue was for the source I did not had UPDATE policy, as soon as i have created new POLICY with the below code it started working.

```auto
{
    "name": "Account",
    "description": null,
    "usageType": "UPDATE",
    "fields": [
       {
                "name": "proxyAddresses",
                "transform": {
                    "type": "identityAttribute",
                    "attributes": {
                        "name": "proxyAddress"
                    }
                },
                "attributes": {
                    "cloudDelimiter": ","
                },
                "isRequired": false,
                "type": "string",
                "isMultiValued": true
            }
    ]
}

```

---

<div class="post-metadata">

**Author:** ![Prashanth1812](https://avatars.discourse-cdn.com/v4/letter/p/41988e/32.png) [@Prashanth1812](https://developer.sailpoint.com/discuss/u/Prashanth1812)\
**Post date:** [October 29, 2024, 5:50pm UTC](https://developer.sailpoint.com/discuss/t/multivalued-attribute-provisioning-in-ad/84365/14 "2024-10-29T17:50:10Z")

</div>

Hi All,

looks like the above transform is adding the duplicates on the account,  
for example, proxy Address identity attribute value is test1,test2… but AD proxyAddresses values are being set as  
test1  
test2  
test1,test2.

Anyone have the same issue or a successful/working code here to update multivalued proxyAddresses in AD?

---

<div class="post-metadata">

**Author:** ![jesvin90](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jesvin90/32/5301_2.png) [@jesvin90](https://developer.sailpoint.com/discuss/u/jesvin90)\
**Post date:** [October 29, 2024, 5:59pm UTC](https://developer.sailpoint.com/discuss/t/multivalued-attribute-provisioning-in-ad/84365/15 "2024-10-29T17:59:39Z")

</div>

Hi @Prashanth1812,

Have you setup an attribute sync on this.? If yes, then that could be the issue as attribute sync does not work on these multivalued attributes.

---

<div class="post-metadata">

**Author:** ![Prashanth1812](https://avatars.discourse-cdn.com/v4/letter/p/41988e/32.png) [@Prashanth1812](https://developer.sailpoint.com/discuss/u/Prashanth1812)\
**Post date:** [October 29, 2024, 7:22pm UTC](https://developer.sailpoint.com/discuss/t/multivalued-attribute-provisioning-in-ad/84365/16 "2024-10-29T19:22:47Z")

</div>

Yes, I have setup attribute sync, @jesvin90 . Is there a way we can provision this to AD as multi valued when we see any updates on identity attribute other than attribute sync?

---

<div class="post-metadata">

**Author:** ![jesvin90](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jesvin90/32/5301_2.png) [@jesvin90](https://developer.sailpoint.com/discuss/u/jesvin90)\
**Post date:** [October 29, 2024, 7:36pm UTC](https://developer.sailpoint.com/discuss/t/multivalued-attribute-provisioning-in-ad/84365/17 "2024-10-29T19:36:07Z")

</div>

One way of handling this is by syncing the comma separated Identity attribute as such to a different single valued attribute in AD.

Then have an AfterModify script that catches changes to that attribute and call the Set AD powerShell commandlet to update the multivalued attribute.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [December 28, 2024, 7:36pm UTC](https://developer.sailpoint.com/discuss/t/multivalued-attribute-provisioning-in-ad/84365/18 "2024-12-28T19:36:43Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
