Email Signature Platform - Help Desk and Knowledge Base

IT Pro: How to read users from Azure Active Directory (AAD)

This guide will walk you through the steps of how to integrate your Xink account with your Azure AD in order to export all users (or only the users you specify) to Xink. 

Once set up, it will also remove and add users as they come and go from your Active Directory.

Which fields are imported from Azure AD to Xink?

The following fields are imported into Xink once you've integrated them with Azure Active Directory.

Each of these properties is put into the corresponding default fields in Xink:

  • givenName (First Name)
  • sn (Last Name)
  • displayName (Display Name)
  • mail (Email)
  • telephoneNumber (Phone)
  • title (Job Title)
  • department (Department)
  • mobile (Mobile)
  • facsimiletelephonenumber (Fax)
  • company (Company)
  • streetAddress (Street)
  • (City)
  • st (State)
  • postalCode (Zip)
  • co (Country)
  • jpegPhoto (Photo)

Custom fields:

  • physicaldeliveryofficename (Office)
  • usageLocation (Location)
  • distinguishedname (user principal name)
  • preferredLanguage (Language)
  • extension_<CLIENT_DEPENDANT_GUID>_<ATTRIBUTE_DISPLAYNAME>

    Example:

    extension_f233e220d6f748ee99cdddf694012345_extensionAttribute2 (extensionAttribute2)


After you integrate to Azure AD, employees will show:

  • It automatically updates every two hours
  • You can also trigger the sync by clicking "Schedule Update" on your dashboard (will only show if you have set up O365 signatures).
  • It updates account information such as name, numbers, and titles adds new users and removes old users (if you have checked 'Delete Employees').


How to grant Xink access to your Azure Active Directory

All users will appear automatically when you integrate Xink with your Azure AD. 

To get started, you need to open your Windows Azure Management Console and follow these steps:

  1. Click “More services >” on the left navigation pane and scroll to "App registrations". Choose “App registrations”.



  2. Click the “Add” button.



  3. Fill the appeared Create pop-up.
    Give a Name to your application, choose Web app / API Application Type and enter https://app.xink.io into the Sign-on URL field.
    Then Push the Create button.



    The application has been added.


Next step is configuring your Azure Directory access for Xink

  1. Choose the created Xink application and copy the Application ID.
    Save the Application ID somewhere because you will need it later on the Xink side of this integration.



  2. Then switch to "All settings" and go to the Keys section. Choose the preferable key duration, Description is optional and save.



    The key value will appear after you save the above. Now copy the key as you will you need it along with Application ID later on Xink side integration.



  3. Then go to the Required permissions section. And choose the next:

    In Application Permissions drop-down menu, check the following:

    -  Read directory data

    In Delegated Permissions drop-down menu, check each of the following:

    -  Sign in and read the user profile
    -  Read directory data
    -  Access the directory as the signed-in user

  4. Click Save and click Grant Permissions for XINK. 
     


    Now the Azure side of allowing Xink to read users is completed.


Finally, update credentials in Xink

  1. Log into your Xink account.

  2. Click the drop-down next to your Profile in the upper right-hand corner > Preferences > Integration > Azure AD.

  3. Fill in the following information:

    Check Enable Azure AD user synchronization so you automatically import all users from Azure AD so you no longer have to import any manually.

    Tenant Name is the name of your Azure AD domain, like 'yourcompany.onmicrosoft.com'.

    Paste your copied Application ID into the Application ID field.
    Paste in your Azure AD key value.

    It's recommended to check Delete Employees for Xink to automatically remove users that no longer exist in your Azure AD, so you constantly have an accurate number of total licenses and users.

    Check Look at ProxyAddresses array for Email and if user's Email field is empty, export service can try to use the first element of this array.
    Check Look at Other (Alternative) array for Email and if user's Email field is still empty, export service can try to use the first element of this array.
    Try to use User Principal Name as Email is unchecked by default in Xink. If user's Email field is still empty, export service can try to use User Principal Name as Email once you check this item, but it is not recommended.

    Check Use import filter and fill out the criteria below if you want to set up certain import criteria.

    Check Connectivity.

    If it all works, hit Save and your Xink + Azure AD integration good to go!




Did you find it helpful? Yes No

Send feedback
Sorry we couldn't be helpful. Help us improve this article with your feedback.