NOTE: This feature in the AirWatch Provisioning Adapter is only available in Preview

 

Are you using the AirWatch Provisioning Adapter without a locally configured directory in Workspace ONE UEM and when trying to enroll your Windows 10 Devices and you are getting the following error:

 

Screen Shot 08-17-20 at 11.48 AM.PNG

 

The reason behind this error is because UEM is checking if the attribute "aadMappingAtribute" is currently set for the particular user received in the request from Azure.  If the attribute is not currently set, UEM will search the directory to retrieve this attribute based on on the value configured in UEM:

 

Screen Shot 08-20-20 at 12.25 PM.PNG

 

UEM will retrieve this value from Active Directory (typically) and store this as a binary/hex (ie. 1e7306a8-7eb8-4b6e-a22f-c3e951a5db6e) or as a string depending on the mapping attribute data type.  This is very important because UEM will not successfully map to a user if the value is Base64 encoded. So the following "vZ/lGAC9bUWiA7Egpw5fqg==" is not acceptable.

 

If this attribute is not set and you don't have an  Enterprise Systems Connector (ACC) with a directory configured, you will receive this error. If you are using the AirWatch Provisioning Adapter, you probably don't have an Enterprise Systems Connector (ACC) and directory configured.

 

Workspace ONE UEM will allow you to update this attribute manually in the Admin Console:

Screen Shot 08-20-20 at 12.33 PM.PNG

 

This however is not scalable by any means. Workspace ONE Access is releasing functionality to set this attribute when the user is created by the AirWatch Provisioning Adapter. Unfortunately, UEM will not allow this attribute to be updated via the API so only "CREATE" is supported at this time.

 

In the AirWatch Provisioning Adapter, you'll soon be able to map this attribute:

 

Screen Shot 08-20-20 at 12.42 PM.PNG

 

Please remember that this value can NOT be Based64 encoded.  The following is a guideline of possible values:

 

 

aadMappingAttribute in Workspace ONE UEMImmutable ID in AzureAcceptable
18e59fbd-bd00-456d-a203-b120a70e5faavZ/lGAC9bUWiA7Egpw5fqg==YES
00ut8unvqk5z6cgtG0h700ut8unvqk5z6cgtG0h7YES
vZ/lGAC9bUWiA7Egpw5fqg==vZ/lGAC9bUWiA7Egpw5fqg==NO