A global company has a single Azure Active Directory (Azure AD) tenant. Due to a recent internal re-organization, certain users from the 'Sales' department need to be moved to the 'Marketing' department. This move involves updating their user attributes, specifically their `department` and `jobTitle`. The company wants to ensure that these attribute changes are applied consistently and that the users retain their existing access to applications relevant to their new department. What is the most efficient way to achieve this in Azure AD?
- AUtilize Azure AD Connect to synchronize the `department` and `jobTitle` attributes from an on-premises Active Directory.
- BImplement Azure AD Identity Governance to manage user lifecycle and attribute updates.
- CUse PowerShell scripts or the Microsoft Graph API to bulk update the `department` and `jobTitle` attributes.
- DManually update each user's `department` and `jobTitle` attribute in the Azure portal.
Show answer & explanationAnswer & explanation
Correct answer: C. Use PowerShell scripts or the Microsoft Graph API to bulk update the `department` and `jobTitle` attributes.
For a re-organization involving multiple users, manually updating each user in the Azure portal is inefficient. While Azure AD Connect can synchronize attributes, the question implies these changes originate within the Azure AD context or need to be applied directly to Azure AD. PowerShell scripts or the Microsoft Graph API are the most efficient and scalable methods for bulk updating user attributes in Azure AD, ensuring consistency. Azure AD's dynamic groups can then automatically adjust application access based on these updated attributes.
Why the other options are wrong
- A. Azure AD Connect synchronizes from on-premises AD. If the changes are originating within Azure AD or need to be applied directly, this is not the most direct method.
- B. Azure AD Identity Governance provides features like access reviews, entitlement management, and PIM, but it's not primarily designed for bulk updating standard user attributes like department or job title directly; it leverages existing attributes for governance.
- D. Manually updating attributes in the portal is feasible for a few users but highly inefficient and prone to errors for a re-organization involving many users.
Bulk User Attribute Update
To efficiently update attributes for multiple Azure AD users, PowerShell scripts or the Microsoft Graph API are the recommended tools, enabling consistent and scalable changes.
- PowerShell cmdlets (e.g., Set-AzureADUser) for bulk updates.
- Microsoft Graph API for programmatic attribute management.
- Essential for re-organizations and large-scale changes.
Memory trick: Scripting or Graph API for bulk user data, like a data wizard.