Electric can automatically create and disable user profiles and push employee profile updates — name, work email, job title, phone number, and address — into your on-premise Active Directory. Updates are delivered through Microsoft Entra Cloud Sync, so if you already sync Entra ID to on-prem AD, you likely have most of what you need in place.
Setup has two parts: configuring Cloud Sync in Microsoft Entra, then connecting Electric.
Before you start
You'll need:
-
A Microsoft Entra tenant with Cloud Sync configured to your on-prem AD (with the Provisioning Agent installed on a server that can reach your domain controllers). If you don't have this yet, see Microsoft's guides:
-
A Global Administrator (or Application Administrator) in Entra, to approve Electric's access.
Step 1: Copy your Cloud Sync job details from Entra
Azure doesn't expose your Cloud Sync provisioning job's configuration to Electric automatically, so you'll need to copy two values over by hand before connecting:
-
In the Entra admin center, open your Cloud Sync provisioning job.
-
Copy its Service principal ID and Provisioning job ID — you'll need these in the next step.
Step 2: Connect Electric to Entra
-
In Electric, go to Applications in the sidebar, then click into On-Premise Active Directory.
-
On the application's details page, open the Actions menu and select Connect On-Premise Active Directory integration. This opens the connect flow in a new window.
-
Acknowledge that an Entra administrator role is required.
-
Enter the Service principal ID and Provisioning job ID you copied in Step 1, then continue.
-
You'll be sent to Microsoft to approve access. Sign in as a Global Administrator and grant consent. (Learn more about admin consent)
-
You'll be redirected back to Electric once your tenant is connected.
Step 3: Check attribute mapping in Entra
This is the most important step to get right. Before turning on profile push, open your Cloud Sync job's attribute mappings in Entra and confirm the following Electric fields are mapped to the AD attributes you expect.
In the Entra Cloud Sync mapping editor, each row maps a source attribute (what Electric sends) to a target attribute (the AD field it fills in). Entra will provide you a default attribute mapping that in most cases will be sufficient. The following table shows a suggested minimum attribute mapping:
|
Source attribute |
Target attribute |
Mapping Type |
|---|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Note that the value of cn is only set during initial account creation. Updating a user’s display name after creation will update the displayName attribute, but won’t alter the value of cn.
If your AD schema uses different attributes for any of these (e.g. a custom extension attribute), map to those instead.
A couple of things to know:
-
Electric only sends work addresses — if you want address updates to land in AD, make sure your mapping expects a work-type address, not home.
-
Electric doesn't currently sync manager or department. If you need those kept in sync, this integration won't cover that today.
Microsoft's guide on mapping attributes: Customize attribute mappings for provisioning
Step 4: Turn on Provisioning
In the Entra console, navigate to your “API-driven provisioning to on-premises Active Directory” application that you previously created.
Select Provisioning → Provisioning.
Ensure that the toggle for Provisioning Status is set to On.
Troubleshooting
-
Updates aren't showing up in AD: check the Provisioning logs in your Entra console for specific errors and contact support@electric.ai if you need further assistance. Note that it can take several minutes for accounts to be created and logs to show.
-
Integration shows as unhealthy in Electric: check your Cloud Sync job's status in the Entra admin center; if it's paused or quarantined, Electric can't deliver updates until it's resumed.
-
Can't connect / consent fails: reconnecting requires a Global Administrator in your Entra tenant.