Views:

Background


Crossware Mail Signature can extract information from Windows Azure Active Directory (WAAD) using the published API (This is known as Graph API).

Most customers use AAD Connect to synchronize their on-premise Active Directory (AD) with Windows Azure Active Directory.

The main issue with WAAD and Graph API is the limited number of attributes available to Crossware Mail Signature.

To get around this limitation, AAD Connect has a feature to synchronize attributes within the customers Active Directory to Extension attributes within WAAD.

These Extension attributes are available to Crossware Mail Signature and can be used in lookups and rules.

 

Pre-requisite: Before proceeding with the setup/steps below, make sure you have migrated over from Azure AD graph to Microsoft Graph API by clicking this link.

 

Setup


The setup of the synchronization process is based on the following Microsoft article.
Crossware is not responsible for this part of the process.

https://azure.microsoft.com/en-us/documentation/articles/active-directory-aadconnect-get-started-custom/#directory-extension-attribute-sync

 

Enable Directory extension attribute sync

If not already enabled, you will need to enable this feature in AAD Connect.


When this option is selected, you can then select the Active Directory attribute to synchronize. Make sure you select user attributes and not "group" attributes.

If you need to add additional attributes you will need to re-run the AzureADConnect.exe application.




Once the changes have been saved, the synchronization process will create new attributes within Windows Azure Active Directory.

Finding the new attributes


The newly created attributes names are different for each tenant; therefore, you will need to find the attribute name.

The new attribute will take the following format:

e.g. extensionAttribute1

 

Filling in the values via Directory/PowerShell

There are two ways of filling in extension attributes.

1. The first way is through your local directory:

  • Open your local directory > Click on the Users file > Find the user, select the user's name and click on properties on the tool bar located on the top

 

  • Once you have loaded the user's information, click on Attribute Editor > Scroll till you find the list of attributes beginning with extensionAttribute (e.g., extensionAttribute1)

 

2. You can set it through a PowerShell command:

  • Open up Active Directory Module for Windows PowerShell > Enter the command in the terminal and click <enter> (replace the text "anyUser" with the user's email and "myString" with the desired value

 

Using Graph Explorer

Microsoft provide a web application for examining the raw output from Graph API. This allows customers to view the attributes available to Crossware Mail Signature.

Graph Explorer | Try Microsoft Graph APIs - Microsoft Graph

To use Graph Explorer, you must login with your Microsoft 365 credentials.

You examine an individual user's extension attributes using a URL similar to the one below

https://graph.microsoft.com/v1.0/users?$filter=startswith(userPrincipalName,'{user'sEmail}')&$select=id,displayname,mail,officeLocation,onPremisesExtensionAttributes



 

Creating a new lookup


Once the attribute name has been determined, a new lookup can be created to extract the information.

e.g.


 

Test/Preview the new lookup


Before testing the new lookup, please check the server log to ensure that all the changes have been correctly pushed out to Crossware's SMTP Servers.
Creating a new lookup, will have forced a refreshed our cache of WAAD
.



The test email should contain the correct data. This lookup can now be used in signature configuration documents and rules just like any other lookup.
Related Products: CMS M365, CMS MSE v4, CMS MSE v5