Create Profile Policy
The following lists the attributes in the create

User principal name (UPN) of the user.
Generator: Create Unique Account ID
For example, jeff@contoso.onmicrosoft.com
Note
You must edit your domain in the Pattern Used field to match your domain.

Password for the new account.
Generator: Create Password

Display name of the account.
Generator: Identity Attribute

Mail alias for the account.
Generator: Create Unique Account ID

Set it to false to create disabled account. Default: True
Generator: Static

If true, asks user to change password on next login. Default: True
Generator: Static

Department in which the user works.
Generator: Disable

User's job title.
Generator: Disable

Set it true to create federated domain user. If this is checked and immutableId is not set then random immutableId value will be used.
Generator: Static

This property is used to associate an on-premises Active Directory user account to their Microsoft Azure Active Directory user account; Populate this attribute with objectGUID of account from on-premises Active Directory to create federated user synchronized with on –premises Active Directory user.
Generator: Disable

Specifies password policies for the user.
Generator: Disable
For example: DisablePasswordExpiration, DisableStrongPassword

Additional email addresses for the user.
Generator: Disable

First name of the user.
Generator: Identity Attribute

Surname of the user.
Generator: Identity Attribute

A two letter country code (ISO standard 3166). Required for users that will be assigned licenses.
Generator: Static

Country/region in which the user is located. For example, US or UK
Generator: Disable

State or province in the user's address.
Generator: Disable

City in which the user is located.
Generator: Disable

Street address of the user's place of business.
Generator: Disable

Postal code for the user's postal address.
Generator: Disable

Office location in the user's place of business.
Generator: Disable

Preferred language for the user. Should follow ISO 639-1 Code.
Generator: Disable
For example, en-US

Primary telephone number of the user's place of business.
Generator: Disable

Primary cellular telephone number for the user.
Generator: Disable

Telephone number of the user's business fax machine.
Generator: Disable

ServicePrincipal Role Id.
By default not present in the schema. It is required if you want to assign ServicePrincipal during account creation. For more information, see .

A string value that can be used to classify user types in your directory.
Generator: Disable
Guest User (B2B) Support
The Microsoft Azure Active Directory connector supports creation of Guest User (B2B) by sending invitations. Creation of Guest User (B2B) varies from normal user creation in terms of attributes provided during creation.
Create Guest User (B2B) Account Policy

Default is User
To create Guest User (B2B), set this value to Guest User B2B.

Email address of the user.

The URL that the user will be redirected to after redemption.

Set it to False if invitation email need not to be sent to the user. Default is True

Customized message text that can be added in the invitation email for the B2B Guest User.

The display name of the user being invited.

A two letter country code indicating usage location (ISO standard 3166).

ServicePrincipal Role Id.
By default not present in the schema. It is required if you want to assign ServicePrincipal during account creation. For more information, see .
Local User (B2C) Support
The Microsoft Azure Active Directory connector supports creation of Local Users. Creation of Local User account varies from normal user in terms of attributes provided during creation. Account creation also supports custom attribute.
Create Local User (B2C) Account Policy

Default is User
To create Local User (B2C), set this value to Local User B2C.

Sign-in type for user in your Azure directory.

Sign-in name for user.

Display name of account.

Password for the new account.

Set it to false to create disabled account. Default: True

If true, asks user to change password on next login. Default: True

ServicePrincipal Role Id.
By default not present in the schema. It is required if you want to assign ServicePrincipal during account creation. For more information, see .
Note
Custom user attributes can be added in B2C create account policy by appending suffix "_C" to the attribute.