<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: Revoke user access in case of an emergency with a single click &#8211; on-premises AD integration	</title>
	<atom:link href="https://inthecloud247.com/revoke-user-access-in-case-of-an-emergency-with-a-single-click-on-premises-ad-integration/feed/" rel="self" type="application/rss+xml" />
	<link>https://inthecloud247.com/revoke-user-access-in-case-of-an-emergency-with-a-single-click-on-premises-ad-integration/</link>
	<description>Intune, Windows, Office 365, Microsoft 365, Azure, Automation</description>
	<lastBuildDate>Fri, 14 Feb 2025 08:21:44 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>
		By: Andy		</title>
		<link>https://inthecloud247.com/revoke-user-access-in-case-of-an-emergency-with-a-single-click-on-premises-ad-integration/#comment-246793</link>

		<dc:creator><![CDATA[Andy]]></dc:creator>
		<pubDate>Tue, 14 Jan 2025 08:46:07 +0000</pubDate>
		<guid isPermaLink="false">https://inthecloud247.com/?p=12774#comment-246793</guid>

					<description><![CDATA[Don&#039;t worry, I got it working. It was the primary key in the advanced API attribute mapping settings, within the enterprise app.]]></description>
			<content:encoded><![CDATA[<p>Don&#8217;t worry, I got it working. It was the primary key in the advanced API attribute mapping settings, within the enterprise app.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Andy		</title>
		<link>https://inthecloud247.com/revoke-user-access-in-case-of-an-emergency-with-a-single-click-on-premises-ad-integration/#comment-246384</link>

		<dc:creator><![CDATA[Andy]]></dc:creator>
		<pubDate>Fri, 10 Jan 2025 11:29:57 +0000</pubDate>
		<guid isPermaLink="false">https://inthecloud247.com/?p=12774#comment-246384</guid>

					<description><![CDATA[Hi Peter, thanks for the reply. Thought I&#039;d replied back but clearly not.

What about using a different attribute? I&#039;ve baked this config into an existing Logic App I have, and it works with employeeID, but if I switch the mapping to userPrincipalName, or displayName, I get and error in provisioning which is &#039;
Source identifier of an entry cannot be empty&#039;. I&#039;ve tried the expression mapping of UPN and even tried direct UPN to UPN but I get the same error.]]></description>
			<content:encoded><![CDATA[<p>Hi Peter, thanks for the reply. Thought I&#8217;d replied back but clearly not.</p>
<p>What about using a different attribute? I&#8217;ve baked this config into an existing Logic App I have, and it works with employeeID, but if I switch the mapping to userPrincipalName, or displayName, I get and error in provisioning which is &#8216;<br />
Source identifier of an entry cannot be empty&#8217;. I&#8217;ve tried the expression mapping of UPN and even tried direct UPN to UPN but I get the same error.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Peter Klapwijk		</title>
		<link>https://inthecloud247.com/revoke-user-access-in-case-of-an-emergency-with-a-single-click-on-premises-ad-integration/#comment-245995</link>

		<dc:creator><![CDATA[Peter Klapwijk]]></dc:creator>
		<pubDate>Tue, 07 Jan 2025 12:53:57 +0000</pubDate>
		<guid isPermaLink="false">https://inthecloud247.com/?p=12774#comment-245995</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://inthecloud247.com/revoke-user-access-in-case-of-an-emergency-with-a-single-click-on-premises-ad-integration/#comment-245993&quot;&gt;Andy&lt;/a&gt;.

Hi Andy,

The OU filled in is indeed only a provisioning OU. As long as you can make a match, like I do on the default employeeID, the user account can be located on other OUs. I&#039;m not aware of any requirement to exclude the provisioning OU. I have my provisioning OU synced with Entra ID Connect sync.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://inthecloud247.com/revoke-user-access-in-case-of-an-emergency-with-a-single-click-on-premises-ad-integration/#comment-245993">Andy</a>.</p>
<p>Hi Andy,</p>
<p>The OU filled in is indeed only a provisioning OU. As long as you can make a match, like I do on the default employeeID, the user account can be located on other OUs. I&#8217;m not aware of any requirement to exclude the provisioning OU. I have my provisioning OU synced with Entra ID Connect sync.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Andy		</title>
		<link>https://inthecloud247.com/revoke-user-access-in-case-of-an-emergency-with-a-single-click-on-premises-ad-integration/#comment-245993</link>

		<dc:creator><![CDATA[Andy]]></dc:creator>
		<pubDate>Tue, 07 Jan 2025 12:32:36 +0000</pubDate>
		<guid isPermaLink="false">https://inthecloud247.com/?p=12774#comment-245993</guid>

					<description><![CDATA[Hi Peter. Great article, and something I am currently working on where I feel this could really benefit us. A question I do have, as I noticed the provisioning OU was different to where your test account resides. I assume the provisioning OU is just a means to configure the enterprise app API. Would this OU need to be excluded from Entra ID Connect sync, as my understanding is you can have both EID-C and Cloud Sync in place, but not for the same OU&#039;s / objects.

In my environment we already have EID-C in place, with specific OUs selected to sync those users to Entra.]]></description>
			<content:encoded><![CDATA[<p>Hi Peter. Great article, and something I am currently working on where I feel this could really benefit us. A question I do have, as I noticed the provisioning OU was different to where your test account resides. I assume the provisioning OU is just a means to configure the enterprise app API. Would this OU need to be excluded from Entra ID Connect sync, as my understanding is you can have both EID-C and Cloud Sync in place, but not for the same OU&#8217;s / objects.</p>
<p>In my environment we already have EID-C in place, with specific OUs selected to sync those users to Entra.</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
