Azure AD Connect 同步:与 Azure Active Directory 同步的属性Azure AD Connect sync: Attributes synchronized to Azure Active Directory

本主题列出通过 Azure AD Connect 同步进行同步的属性。This topic lists the attributes that are synchronized by Azure AD Connect sync.
属性按照相关的 Azure AD 应用进行分组。The attributes are grouped by the related Azure AD app.

要同步的属性Attributes to synchronize

常见的问题是:要同步的最小属性的列表是什么。 A common question is what is the list of minimum attributes to synchronize. 默认的(也是建议的)方法是保留默认属性,以便可以在云中构造完整的 GAL(全局地址列表),并获取 Office 365 工作负荷中的所有功能。The default and recommended approach is to keep the default attributes so a full GAL (Global Address List) can be constructed in the cloud and to get all features in Office 365 workloads. 在某些情况下,组织并不想要将某些属性同步到云中,因为这些属性包含敏感数据或 PII(个人身份信息),如以下示例中所示:In some cases, there are some attributes that your organization does not want synchronized to the cloud since these attributes contain sensitive or PII (Personally identifiable information) data, like in this example:
错误的属性bad attributes

在此情况下,请从本主题中的属性列表着手,并识别包含敏感数据或 PII 数据、因而不能同步的属性。In this case, start with the list of attributes in this topic and identify those attributes that would contain sensitive or PII data and cannot be synchronized. 然后在安装期间使用 Azure AD 应用和属性筛选取消选择这些属性。Then deselect those attributes during installation using Azure AD app and attribute filtering.

Warning

取消选择属性时,应该小心,只取消选择那些绝对不能同步的属性。When deselecting attributes, you should be cautious and only deselect those attributes absolutely not possible to synchronize. 取消选择其他属性可能会对功能造成负面影响。Unselecting other attributes might have a negative impact on features.

Office 365 ProPlusOffice 365 ProPlus

属性名称Attribute Name 用户User 注释Comment
accountEnabledaccountEnabled XX 如果启用了帐户,则进行定义。Defines if an account is enabled.
cncn XX
displayNamedisplayName XX
objectSIDobjectSID XX 机械属性。mechanical property. 用于维护 Azure AD 和 AD 之间的同步的 AD 用户标识符。AD user identifier used to maintain sync between Azure AD and AD.
pwdLastSetpwdLastSet XX 机械属性。mechanical property. 用于了解使已颁发令牌失效的时间。Used to know when to invalidate already issued tokens. 由密码哈希同步和联合使用。Used by both password hash sync and federation.
samAccountNamesamAccountName XX
sourceAnchorsourceAnchor XX 机械属性。mechanical property. 用于保持 ADDS 与 Azure AD 之间的关系的不可变标识符。Immutable identifier to maintain relationship between ADDS and Azure AD.
usageLocationusageLocation XX 机械属性。mechanical property. 用户所在的国家/地区。The user’s country/region. 用于进行许可证分配。Used for license assignment.
userPrincipalNameuserPrincipalName XX UPN 是用户的登录 ID。UPN is the login ID for the user. 大多数情况下与 [mail] 值相同。Most often the same as [mail] value.

Exchange OnlineExchange Online

属性名称Attribute Name UserUser 联系人Contact Group 注释Comment
accountEnabledaccountEnabled XX 如果启用了帐户,则进行定义。Defines if an account is enabled.
assistantassistant XX XX
altRecipientaltRecipient XX 需要 Azure AD Connect 版本 1.1.552.0 或更高版本。Requires Azure AD Connect build 1.1.552.0 or after.
authOrigauthOrig XX XX XX
cc XX XX
cncn XX XX
coco XX XX
companycompany XX XX
countryCodecountryCode XX XX
departmentdepartment XX XX
说明description XX XX XX
displayNamedisplayName XX XX XX
dLMemRejectPermsdLMemRejectPerms XX XX XX
dLMemSubmitPermsdLMemSubmitPerms XX XX XX
extensionAttribute1extensionAttribute1 XX XX XX
extensionAttribute10extensionAttribute10 XX XX XX
extensionAttribute11extensionAttribute11 XX XX XX
extensionAttribute12extensionAttribute12 XX XX XX
extensionAttribute13extensionAttribute13 XX XX XX
extensionAttribute14extensionAttribute14 XX XX XX
extensionAttribute15extensionAttribute15 XX XX XX
extensionAttribute2extensionAttribute2 XX XX XX
extensionAttribute3extensionAttribute3 XX XX XX
extensionAttribute4extensionAttribute4 XX XX XX
extensionAttribute5extensionAttribute5 XX XX XX
extensionAttribute6extensionAttribute6 XX XX XX
extensionAttribute7extensionAttribute7 XX XX XX
extensionAttribute8extensionAttribute8 XX XX XX
extensionAttribute9extensionAttribute9 XX XX XX
facsimiletelephonenumberfacsimiletelephonenumber XX XX
givenNamegivenName XX XX
homePhonehomePhone XX XX
infoinfo XX XX XX 组当前不使用此属性。This attribute is currently not consumed for groups.
InitialsInitials XX XX
ll XX XX
legacyExchangeDNlegacyExchangeDN XX XX XX
mailNicknamemailNickname XX XX XX
managedBymanagedBy XX
managermanager XX XX
membermember XX
mobilemobile XX XX
msDS-HABSeniorityIndexmsDS-HABSeniorityIndex XX XX XX
msDS-PhoneticDisplayNamemsDS-PhoneticDisplayName XX XX XX
msExchArchiveGUIDmsExchArchiveGUID XX
msExchArchiveNamemsExchArchiveName XX
msExchAssistantNamemsExchAssistantName XX XX
msExchAuditAdminmsExchAuditAdmin XX
msExchAuditDelegatemsExchAuditDelegate XX
msExchAuditDelegateAdminmsExchAuditDelegateAdmin XX
msExchAuditOwnermsExchAuditOwner XX
msExchBlockedSendersHashmsExchBlockedSendersHash XX XX
msExchBypassAuditmsExchBypassAudit XX
msExchBypassModerationLinkmsExchBypassModerationLink XX 在 Azure AD Connect 版本 1.1.524.0 中可用Available in Azure AD Connect version 1.1.524.0
msExchCoManagedByLinkmsExchCoManagedByLink XX
msExchDelegateListLinkmsExchDelegateListLink XX
msExchELCExpirySuspensionEndmsExchELCExpirySuspensionEnd XX
msExchELCExpirySuspensionStartmsExchELCExpirySuspensionStart XX
msExchELCMailboxFlagsmsExchELCMailboxFlags XX
msExchEnableModerationmsExchEnableModeration XX XX
msExchExtensionCustomAttribute1msExchExtensionCustomAttribute1 XX XX XX Exchange Online 当前不使用此属性。This attribute is currently not consumed by Exchange Online.
msExchExtensionCustomAttribute2msExchExtensionCustomAttribute2 XX XX XX Exchange Online 当前不使用此属性。This attribute is currently not consumed by Exchange Online.
msExchExtensionCustomAttribute3msExchExtensionCustomAttribute3 XX XX XX Exchange Online 当前不使用此属性。This attribute is currently not consumed by Exchange Online.
msExchExtensionCustomAttribute4msExchExtensionCustomAttribute4 XX XX XX Exchange Online 当前不使用此属性。This attribute is currently not consumed by Exchange Online.
msExchExtensionCustomAttribute5msExchExtensionCustomAttribute5 XX XX XX Exchange Online 当前不使用此属性。This attribute is currently not consumed by Exchange Online.
msExchHideFromAddressListsmsExchHideFromAddressLists XX XX XX
msExchImmutableIDmsExchImmutableID XX
msExchLitigationHoldDatemsExchLitigationHoldDate XX XX XX
msExchLitigationHoldOwnermsExchLitigationHoldOwner XX XX XX
msExchMailboxAuditEnablemsExchMailboxAuditEnable XX
msExchMailboxAuditLogAgeLimitmsExchMailboxAuditLogAgeLimit XX
msExchMailboxGuidmsExchMailboxGuid XX
msExchModeratedByLinkmsExchModeratedByLink XX XX XX
msExchModerationFlagsmsExchModerationFlags XX XX XX
msExchRecipientDisplayTypemsExchRecipientDisplayType XX XX XX
msExchRecipientTypeDetailsmsExchRecipientTypeDetails XX XX XX
msExchRemoteRecipientTypemsExchRemoteRecipientType XX
msExchRequireAuthToSendTomsExchRequireAuthToSendTo XX XX XX
msExchResourceCapacitymsExchResourceCapacity XX
msExchResourceDisplaymsExchResourceDisplay XX
msExchResourceMetaDatamsExchResourceMetaData XX
msExchResourceSearchPropertiesmsExchResourceSearchProperties XX
msExchRetentionCommentmsExchRetentionComment XX XX XX
msExchRetentionURLmsExchRetentionURL XX XX XX
msExchSafeRecipientsHashmsExchSafeRecipientsHash XX XX
msExchSafeSendersHashmsExchSafeSendersHash XX XX
msExchSenderHintTranslationsmsExchSenderHintTranslations XX XX XX
msExchTeamMailboxExpirationmsExchTeamMailboxExpiration XX
msExchTeamMailboxOwnersmsExchTeamMailboxOwners XX
msExchTeamMailboxSharePointUrlmsExchTeamMailboxSharePointUrl XX
msExchUserHoldPoliciesmsExchUserHoldPolicies XX
msOrg-IsOrganizationalmsOrg-IsOrganizational XX
objectSIDobjectSID XX XX 机械属性。mechanical property. 用于维护 Azure AD 和 AD 之间的同步的 AD 用户标识符。AD user identifier used to maintain sync between Azure AD and AD.
oOFReplyToOriginatoroOFReplyToOriginator XX
otherFacsimileTelephoneotherFacsimileTelephone XX XX
otherHomePhoneotherHomePhone XX XX
otherTelephoneotherTelephone XX XX
pagerpager XX XX
physicalDeliveryOfficeNamephysicalDeliveryOfficeName XX XX
postalCodepostalCode XX XX
ProxyAddressesproxyAddresses XX XX XX
publicDelegatespublicDelegates XX XX XX
pwdLastSetpwdLastSet XX 机械属性。mechanical property. 用于了解使已颁发令牌失效的时间。Used to know when to invalidate already issued tokens. 由密码同步和联合使用。Used by both password sync and federation.
reportToOriginatorreportToOriginator XX
reportToOwnerreportToOwner XX
snsn XX XX
sourceAnchorsourceAnchor XX XX XX 机械属性。mechanical property. 用于保持 ADDS 与 Azure AD 之间的关系的不可变标识符。Immutable identifier to maintain relationship between ADDS and Azure AD.
stst XX XX
streetAddressstreetAddress XX XX
targetAddresstargetAddress XX XX
telephoneAssistanttelephoneAssistant XX XX
telephoneNumbertelephoneNumber XX XX
thumbnailphotothumbnailphoto XX XX
titletitle XX XX
unauthOrigunauthOrig XX XX XX
usageLocationusageLocation XX 机械属性。mechanical property. 用户所在的国家/地区。The user’s country/region. 用于进行许可证分配。Used for license assignment.
userCertificateuserCertificate XX XX
userPrincipalNameuserPrincipalName XX UPN 是用户的登录 ID。UPN is the login ID for the user. 大多数情况下与 [mail] 值相同。Most often the same as [mail] value.
userSMIMECertificatesuserSMIMECertificates XX XX
wWWHomePagewWWHomePage XX XX

SharePoint OnlineSharePoint Online

属性名称Attribute Name UserUser 联系人Contact Group 注释Comment
accountEnabledaccountEnabled XX 如果启用了帐户,则进行定义。Defines if an account is enabled.
authOrigauthOrig XX XX XX
cc XX XX
cncn XX XX
coco XX XX
companycompany XX XX
countryCodecountryCode XX XX
departmentdepartment XX XX
说明description XX XX XX
displayNamedisplayName XX XX XX
dLMemRejectPermsdLMemRejectPerms XX XX XX
dLMemSubmitPermsdLMemSubmitPerms XX XX XX
extensionAttribute1extensionAttribute1 XX XX XX
extensionAttribute10extensionAttribute10 XX XX XX
extensionAttribute11extensionAttribute11 XX XX XX
extensionAttribute12extensionAttribute12 XX XX XX
extensionAttribute13extensionAttribute13 XX XX XX
extensionAttribute14extensionAttribute14 XX XX XX
extensionAttribute15extensionAttribute15 XX XX XX
extensionAttribute2extensionAttribute2 XX XX XX
extensionAttribute3extensionAttribute3 XX XX XX
extensionAttribute4extensionAttribute4 XX XX XX
extensionAttribute5extensionAttribute5 XX XX XX
extensionAttribute6extensionAttribute6 XX XX XX
extensionAttribute7extensionAttribute7 XX XX XX
extensionAttribute8extensionAttribute8 XX XX XX
extensionAttribute9extensionAttribute9 XX XX XX
facsimiletelephonenumberfacsimiletelephonenumber XX XX
givenNamegivenName XX XX
hideDLMembershiphideDLMembership XX
homePhonehomephone XX XX
infoinfo XX XX XX
Initialsinitials XX XX
ipPhoneipPhone XX XX
ll XX XX
mailmail XX XX XX
mailNicknamemailnickname XX XX XX
managedBymanagedBy XX
managermanager XX XX
membermember XX
middleNamemiddleName XX XX
mobilemobile XX XX
msExchTeamMailboxExpirationmsExchTeamMailboxExpiration XX
msExchTeamMailboxOwnersmsExchTeamMailboxOwners XX
msExchTeamMailboxSharePointLinkedBymsExchTeamMailboxSharePointLinkedBy XX
msExchTeamMailboxSharePointUrlmsExchTeamMailboxSharePointUrl XX
objectSIDobjectSID XX XX 机械属性。mechanical property. 用于维护 Azure AD 和 AD 之间的同步的 AD 用户标识符。AD user identifier used to maintain sync between Azure AD and AD.
oOFReplyToOriginatoroOFReplyToOriginator XX
otherFacsimileTelephoneotherFacsimileTelephone XX XX
otherHomePhoneotherHomePhone XX XX
otherIpPhoneotherIpPhone XX XX
otherMobileotherMobile XX XX
otherPagerotherPager XX XX
otherTelephoneotherTelephone XX XX
pagerpager XX XX
physicalDeliveryOfficeNamephysicalDeliveryOfficeName XX XX
postalCodepostalCode XX XX
postOfficeBoxpostOfficeBox XX XX SharePoint Online 当前不使用此属性。This attribute is currently not consumed by SharePoint Online.
preferredLanguagepreferredLanguage XX
ProxyAddressesproxyAddresses XX XX XX
pwdLastSetpwdLastSet XX 机械属性。mechanical property. 用于了解使已颁发令牌失效的时间。Used to know when to invalidate already issued tokens. 由密码哈希同步和联合使用。Used by both password hash sync and federation.
reportToOriginatorreportToOriginator XX
reportToOwnerreportToOwner XX
snsn XX XX
sourceAnchorsourceAnchor XX XX XX 机械属性。mechanical property. 用于保持 ADDS 与 Azure AD 之间的关系的不可变标识符。Immutable identifier to maintain relationship between ADDS and Azure AD.
stst XX XX
streetAddressstreetAddress XX XX
targetAddresstargetAddress XX XX
telephoneAssistanttelephoneAssistant XX XX
telephoneNumbertelephoneNumber XX XX
thumbnailphotothumbnailphoto XX XX
titletitle XX XX
unauthOrigunauthOrig XX XX XX
urlurl XX XX
usageLocationusageLocation XX 机械属性。mechanical property. 用户所在的国家/地区。The user’s country/region. 用于进行许可证分配。Used for license assignment.
userPrincipalNameuserPrincipalName XX UPN 是用户的登录 ID。UPN is the login ID for the user. 大多数情况下与 [mail] 值相同。Most often the same as [mail] value.
wWWHomePagewWWHomePage XX XX

Teams 和 Skype for Business OnlineTeams and Skype for Business Online

属性名称Attribute Name UserUser 联系人Contact Group 注释Comment
accountEnabledaccountEnabled XX 如果启用了帐户,则进行定义。Defines if an account is enabled.
cc XX XX
cncn XX XX
coco XX XX
companycompany XX XX
departmentdepartment XX XX
说明description XX XX XX
displayNamedisplayName XX XX XX
facsimiletelephonenumberfacsimiletelephonenumber XX XX XX
givenNamegivenName XX XX
homePhonehomephone XX XX
ipPhoneipPhone XX XX
ll XX XX
mailmail XX XX XX
mailNicknamemailNickname XX XX XX
managedBymanagedBy XX
managermanager XX XX
membermember XX
mobilemobile XX XX
msExchHideFromAddressListsmsExchHideFromAddressLists XX XX XX
msRTCSIP-ApplicationOptionsmsRTCSIP-ApplicationOptions XX
msRTCSIP-DeploymentLocatormsRTCSIP-DeploymentLocator XX XX
msRTCSIP-LinemsRTCSIP-Line XX XX
msRTCSIP-OptionFlagsmsRTCSIP-OptionFlags XX XX
msRTCSIP-OwnerUrnmsRTCSIP-OwnerUrn XX
msRTCSIP-PrimaryUserAddressmsRTCSIP-PrimaryUserAddress XX XX
msRTCSIP-UserEnabledmsRTCSIP-UserEnabled XX XX
objectSIDobjectSID XX XX 机械属性。mechanical property. 用于维护 Azure AD 和 AD 之间的同步的 AD 用户标识符。AD user identifier used to maintain sync between Azure AD and AD.
otherTelephoneotherTelephone XX XX
physicalDeliveryOfficeNamephysicalDeliveryOfficeName XX XX
postalCodepostalCode XX XX
preferredLanguagepreferredLanguage XX
ProxyAddressesproxyAddresses XX XX XX
pwdLastSetpwdLastSet XX 机械属性。mechanical property. 用于了解使已颁发令牌失效的时间。Used to know when to invalidate already issued tokens. 由密码哈希同步和联合使用。Used by both password hash sync and federation.
snsn XX XX
sourceAnchorsourceAnchor XX XX XX 机械属性。mechanical property. 用于保持 ADDS 与 Azure AD 之间的关系的不可变标识符。Immutable identifier to maintain relationship between ADDS and Azure AD.
stst XX XX
streetAddressstreetAddress XX XX
telephoneNumbertelephoneNumber XX XX
thumbnailphotothumbnailphoto XX XX
titletitle XX XX
usageLocationusageLocation XX 机械属性。mechanical property. 用户所在的国家/地区。The user’s country/region. 用于进行许可证分配。Used for license assignment.
userPrincipalNameuserPrincipalName XX UPN 是用户的登录 ID。UPN is the login ID for the user. 大多数情况下与 [mail] 值相同。Most often the same as [mail] value.
wWWHomePagewWWHomePage XX XX

Azure RMSAzure RMS

属性名称Attribute Name UserUser 联系人Contact Group 注释Comment
accountEnabledaccountEnabled XX 如果启用了帐户,则进行定义。Defines if an account is enabled.
cncn XX XX 公用名或别名。Common name or alias. 大多数情况下是 [mail] 值的前缀。Most often the prefix of [mail] value.
displayNamedisplayName XX XX XX 表示通常显示为友好名称(名字姓氏)的名称的字符串。A string that represents the name often shown as the friendly name (first name last name).
mailmail XX XX XX 完整的电子邮件地址。full email address.
membermember XX
objectSIDobjectSID XX XX 机械属性。mechanical property. 用于维护 Azure AD 和 AD 之间的同步的 AD 用户标识符。AD user identifier used to maintain sync between Azure AD and AD.
ProxyAddressesproxyAddresses XX XX XX 机械属性。mechanical property. 由 Azure AD 使用。Used by Azure AD. 包含用户的所有辅助电子邮件地址。Contains all secondary email addresses for the user.
pwdLastSetpwdLastSet XX 机械属性。mechanical property. 用于了解使已颁发令牌失效的时间。Used to know when to invalidate already issued tokens.
sourceAnchorsourceAnchor XX XX XX 机械属性。mechanical property. 用于保持 ADDS 与 Azure AD 之间的关系的不可变标识符。Immutable identifier to maintain relationship between ADDS and Azure AD.
usageLocationusageLocation XX 机械属性。mechanical property. 用户所在的国家/地区。The user’s country/region. 用于进行许可证分配。Used for license assignment.
userPrincipalNameuserPrincipalName XX 此 UPN 是用户的登录 ID。This UPN is the login ID for the user. 大多数情况下与 [mail] 值相同。Most often the same as [mail] value.

IntuneIntune

属性名称Attribute Name UserUser 联系人Contact Group 注释Comment
accountEnabledaccountEnabled XX 如果启用了帐户,则进行定义。Defines if an account is enabled.
cc XX XX
cncn XX XX
说明description XX XX XX
displayNamedisplayName XX XX XX
mailmail XX XX XX
mailNicknamemailnickname XX XX XX
membermember XX
objectSIDobjectSID XX XX 机械属性。mechanical property. 用于维护 Azure AD 和 AD 之间的同步的 AD 用户标识符。AD user identifier used to maintain sync between Azure AD and AD.
ProxyAddressesproxyAddresses XX XX XX
pwdLastSetpwdLastSet XX 机械属性。mechanical property. 用于了解使已颁发令牌失效的时间。Used to know when to invalidate already issued tokens. 由密码哈希同步和联合使用。Used by both password hash sync and federation.
sourceAnchorsourceAnchor XX XX XX 机械属性。mechanical property. 用于保持 ADDS 与 Azure AD 之间的关系的不可变标识符。Immutable identifier to maintain relationship between ADDS and Azure AD.
usageLocationusageLocation XX 机械属性。mechanical property. 用户所在的国家/地区。The user’s country/region. 用于进行许可证分配。Used for license assignment.
userPrincipalNameuserPrincipalName XX UPN 是用户的登录 ID。UPN is the login ID for the user. 大多数情况下与 [mail] 值相同。Most often the same as [mail] value.

Dynamics CRMDynamics CRM

属性名称Attribute Name UserUser 联系人Contact Group 注释Comment
accountEnabledaccountEnabled XX 如果启用了帐户,则进行定义。Defines if an account is enabled.
cc XX XX
cncn XX XX
coco XX XX
companycompany XX XX
countryCodecountryCode XX XX
说明description XX XX XX
displayNamedisplayName XX XX XX
facsimiletelephonenumberfacsimiletelephonenumber XX XX
givenNamegivenName XX XX
ll XX XX
managedBymanagedBy XX
managermanager XX XX
membermember XX
mobilemobile XX XX
objectSIDobjectSID XX XX 机械属性。mechanical property. 用于维护 Azure AD 和 AD 之间的同步的 AD 用户标识符。AD user identifier used to maintain sync between Azure AD and AD.
physicalDeliveryOfficeNamephysicalDeliveryOfficeName XX XX
postalCodepostalCode XX XX
preferredLanguagepreferredLanguage XX
pwdLastSetpwdLastSet XX 机械属性。mechanical property. 用于了解使已颁发令牌失效的时间。Used to know when to invalidate already issued tokens. 由密码哈希同步和联合使用。Used by both password hash sync and federation.
snsn XX XX
sourceAnchorsourceAnchor XX XX XX 机械属性。mechanical property. 用于保持 ADDS 与 Azure AD 之间的关系的不可变标识符。Immutable identifier to maintain relationship between ADDS and Azure AD.
stst XX XX
streetAddressstreetAddress XX XX
telephoneNumbertelephoneNumber XX XX
titletitle XX XX
usageLocationusageLocation XX 机械属性。mechanical property. 用户所在的国家/地区。The user’s country/region. 用于进行许可证分配。Used for license assignment.
userPrincipalNameuserPrincipalName XX UPN 是用户的登录 ID。UPN is the login ID for the user. 大多数情况下与 [mail] 值相同。Most often the same as [mail] value.

第三方应用程序3rd party applications

此组是用作常规工作负荷或应用程序所需的最低属性。This group is a set of attributes used as the minimal attributes needed for a generic workload or application. 它可以用于另一部分中未列出的工作负荷或非 Microsoft 应用。It can be used for a workload not listed in another section or for a non-Microsoft app. 它显式用于以下目的:It is explicitly used for the following:

  • Yammer(只使用 User)Yammer (only User is consumed)

如果不使用 Azure AD 目录来支持 Office 365、Dynamics 或 Intune,则可以使用这一组属性。This group is a set of attributes that can be used if the Azure AD directory is not used to support Office 365, Dynamics, or Intune. 它包含一小部分核心属性。It has a small set of core attributes.

属性名称Attribute Name UserUser 联系人Contact Group 注释Comment
accountEnabledaccountEnabled XX 如果启用了帐户,则进行定义。Defines if an account is enabled.
cncn XX XX
displayNamedisplayName XX XX XX
employeeIDemployeeID XX
givenNamegivenName XX XX
mailmail XX XX
managedBymanagedBy XX
mailNicknamemailNickName XX XX XX
membermember XX
objectSIDobjectSID XX 机械属性。mechanical property. 用于维护 Azure AD 和 AD 之间的同步的 AD 用户标识符。AD user identifier used to maintain sync between Azure AD and AD.
ProxyAddressesproxyAddresses XX XX XX
pwdLastSetpwdLastSet XX 机械属性。mechanical property. 用于了解使已颁发令牌失效的时间。Used to know when to invalidate already issued tokens. 由密码哈希同步和联合使用。Used by both password hash sync and federation.
snsn XX XX
sourceAnchorsourceAnchor XX XX XX 机械属性。mechanical property. 用于保持 ADDS 与 Azure AD 之间的关系的不可变标识符。Immutable identifier to maintain relationship between ADDS and Azure AD.
usageLocationusageLocation XX 机械属性。mechanical property. 用户所在的国家/地区。The user’s country/region. 用于进行许可证分配。Used for license assignment.
userPrincipalNameuserPrincipalName XX UPN 是用户的登录 ID。UPN is the login ID for the user. 大多数情况下与 [mail] 值相同。Most often the same as [mail] value.

Windows 10Windows 10

已加入 Windows 10 域的计算机(设备)会将某些属性同步到 Azure AD。A Windows 10 domain-joined computer(device) synchronizes some attributes to Azure AD. 这些属性始终同步,Windows 10 不会显示为可以取消选择的应用。These attributes always synchronize and Windows 10 does not appear as an app you can unselect. 通过填充 userCertificate 属性来标识已加入 Windows 10 域的计算机。A Windows 10 domain-joined computer is identified by having the attribute userCertificate populated.

属性名称Attribute Name 设备Device 注释Comment
accountEnabledaccountEnabled XX
deviceTrustTypedeviceTrustType XX 已加入域的计算机的硬编码值。Hardcoded value for domain-joined computers.
displayNamedisplayName XX
ms-DS-CreatorSIDms-DS-CreatorSID XX 也称为 registeredOwnerReference。Also called registeredOwnerReference.
objectGUIDobjectGUID XX 也称为 deviceID。Also called deviceID.
objectSIDobjectSID XX 也称为 onPremisesSecurityIdentifier。Also called onPremisesSecurityIdentifier.
operatingSystemoperatingSystem XX 也称为 deviceOSType。Also called deviceOSType.
operatingSystemVersionoperatingSystemVersion XX 也称为 deviceOSVersion。Also called deviceOSVersion.
userCertificateuserCertificate XX

用户 的这些属性是所选其他应用的补充。These attributes for user are in addition to the other apps you have selected.

属性名称Attribute Name 用户User 注释Comment
domainFQDNdomainFQDN XX 也称为 dnsDomainName。Also called dnsDomainName. 例如 contoso.com。For example, contoso.com.
domainNetBiosdomainNetBios XX 也称为 netBiosName。Also called netBiosName. 例如 CONTOSO。For example, CONTOSO.
msDS-KeyCredentialLinkmsDS-KeyCredentialLink XX 在用户已注册 Windows Hello for Business 后。Once the user is enrolled in Windows Hello for Business.

Exchange 混合写回Exchange hybrid writeback

选择启用 Exchange 混合部署时,这些属性从 Azure AD 写回到本地 Active Directory。These attributes are written back from Azure AD to on-premises Active Directory when you select to enable Exchange hybrid. 根据 Exchange 版本,可能会同步更少的属性。Depending on your Exchange version, fewer attributes might be synchronized.

属性名称(本地 AD)Attribute Name (On-premises AD) 属性名称(连接 UI)Attribute Name (Connect UI) UserUser 联系人Contact Group 注释Comment
msDS-ExternalDirectoryObjectIDmsDS-ExternalDirectoryObjectID ms-DS-External-Directory-Object-Idms-DS-External-Directory-Object-Id XX 派生自 Azure AD 中的 cloudAnchor。Derived from cloudAnchor in Azure AD. 此属性是 Exchange 2016 和 Windows Server 2016 AD 中的新增属性。This attribute is new in Exchange 2016 and Windows Server 2016 AD.
msExchArchiveStatusmsExchArchiveStatus ms-Exch-ArchiveStatusms-Exch-ArchiveStatus XX 联机存档:使客户能够存档邮件。Online Archive: Enables customers to archive mail.
msExchBlockedSendersHashmsExchBlockedSendersHash ms-Exch-BlockedSendersHashms-Exch-BlockedSendersHash XX 筛选:从客户端回写本地筛选及在线安全和已阻止的发件人数据。Filtering: Writes back on-premises filtering and online safe and blocked sender data from clients.
msExchSafeRecipientsHashmsExchSafeRecipientsHash ms-Exch-SafeRecipientsHashms-Exch-SafeRecipientsHash XX 筛选:从客户端回写本地筛选及在线安全和已阻止的发件人数据。Filtering: Writes back on-premises filtering and online safe and blocked sender data from clients.
msExchSafeSendersHashmsExchSafeSendersHash ms-Exch-SafeSendersHashms-Exch-SafeSendersHash XX 筛选:从客户端回写本地筛选及在线安全和已阻止的发件人数据。Filtering: Writes back on-premises filtering and online safe and blocked sender data from clients.
msExchUCVoiceMailSettingsmsExchUCVoiceMailSettings ms-Exch-UCVoiceMailSettingsms-Exch-UCVoiceMailSettings XX 启用统一消息 (UM) - 在线语音邮件:供 Microsoft Lync Server 集成用于向 Lync Server 本地指示用户在联机服务中有语音邮件。Enable Unified Messaging (UM) - Online voice mail: Used by Microsoft Lync Server integration to indicate to Lync Server on-premises that the user has voice mail in online services.
msExchUserHoldPoliciesmsExchUserHoldPolicies ms-Exc-hUserHoldPoliciesms-Exc-hUserHoldPolicies XX 诉讼数据保留:启用云服务来确定哪些用户正处于诉讼数据保留状态。Litigation Hold: Enables cloud services to determine which users are under Litigation Hold.
ProxyAddressesproxyAddresses ProxyAddressesproxyAddresses XX XX XX 只插入 Exchange Online 中的 x500 地址。Only the x500 address from Exchange Online is inserted.
publicDelegatespublicDelegates ms-Exch-Public-Delegatesms-Exch-Public-Delegates XX 允许向拥有本地 Exchange 邮箱的用户授予 Exchange Online 邮箱的 SendOnBehalfTo 权限。Allows an Exchange Online mailbox to be granted SendOnBehalfTo rights to users with on-premises Exchange mailbox. 需要 Azure AD Connect 内部版本 1.1.552.0 或更高版本。Requires Azure AD Connect build 1.1.552.0 or after.

Exchange 邮件公共文件夹Exchange Mail Public Folder

如果选择启用 Exchange 邮件公用文件夹 ,这些属性将从本地 Active Directory 同步到 Azure AD。These attributes are synchronized from on-premises Active Directory to Azure AD when you select to enable Exchange Mail Public Folder.

属性名称Attribute Name PublicFolderPublicFolder 注释Comment
displayNamedisplayName XX
mailmail XX
msExchRecipientTypeDetailsmsExchRecipientTypeDetails XX
objectGUIDobjectGUID XX
ProxyAddressesproxyAddresses XX
targetAddresstargetAddress XX

注释Notes

  • 使用替代 ID 时,本地属性 userPrincipalName 将与 Azure AD 属性 onPremisesUserPrincipalName 同步。When using an Alternate ID, the on-premises attribute userPrincipalName is synchronized with the Azure AD attribute onPremisesUserPrincipalName. 替代 ID 属性(例如 mail)将与 Azure AD 属性 userPrincipalName 同步。The Alternate ID attribute, for example mail, is synchronized with the Azure AD attribute userPrincipalName.
  • 在上述列表中,对象类型 User 也适用于对象类型 iNetOrgPerson。 In the lists above, the object type User also applies to the object type iNetOrgPerson.

后续步骤Next steps

了解有关 Azure AD Connect 同步配置的详细信息。Learn more about the Azure AD Connect sync configuration.

了解有关将本地标识与 Azure Active Directory 集成的详细信息。Learn more about Integrating your on-premises identities with Azure Active Directory.