Review the user attributes that are set for all Workspace ONE Access directories in the User Attributes page and modify them, if necessary. When a user is provisioned through Just-in-Time provisioning, the data in the SAML assertion or the OpenID Connect token is used to create the user. Only those SAM attributes or OpenID Connect claims that match the attributes listed in the User Attributes page are used.

Note: An OpenID Connect identity provider is only for Workspace ONE Access cloud tenants.
Important: If an attribute is marked required in the User Attributes page, the SAML assertion or OpenID Connect token must include the attribute, otherwise login fails.

When you make changes to the user attributes, consider the effect on other directories and configurations in your tenant. The User Attributes page applies to all directories in your tenant.

Note: You do not have to mark the domain attribute required.


  1. In the administration console Settings > User Attributes page, review the attributes and make changes, if necessary.
  2. Click Save.