Machine Identity Rules
Where this data comes from

What you can do here
Action
What it does
How to use it
1
2
3
4
5
Related
Last updated
The MI Rules tab lets you define rules that automatically classify incoming accounts as Machine Identities — such as service accounts or system users — before they are classified in AOH Sync.
Rules are evaluated against each incoming record during a Sync. The source data is the same row your Connector reads from the Source System. When a record's User Principal Name (UPN) matches a rule's pattern, AOH Sync classifies that record as a Machine Identity instead of a standard Account — the original Source System data is unchanged.

The MI Rules tab shows your active classification rules on the left and a form to add a new rule on the right.
New rule — Rule type selector
Chooses the matching method for the rule. The available type shown is UPN regex (case-insensitive match against the User Principal Name).
UPN regex field
Enter the regular expression pattern to match against incoming UPN values (for example, ^svc[-_].+ to catch any UPN starting with svc- or svc_).
Classification field
A free-text label applied to every account matched by this rule (for example, service_account). This label is stored with the Machine Identity record.
Priority field
A numeric value that controls the order in which rules are evaluated. Lower numbers are evaluated first.
Enabled toggle
Activates or pauses a rule without deleting it.
Add rule button
Saves the new rule and adds it to the active list.
Identify your machine account patterns
Review your Source System's user population and identify naming conventions used for service accounts, system accounts, or non-human identities (for example, UPNs beginning with svc-, app-, or bot-).
Set the Rule type
Select UPN regex from the Rule type dropdown. This matches accounts by their User Principal Name using a case-insensitive regular expression.
Enter the regex pattern
Type your pattern in the UPN regex field. For example, ^svc[-_].+ matches any UPN that starts with svc- or svc_ followed by one or more characters.
Add a Classification label
Type a descriptive label in the Classification field (for example, service_account). This label is stored with the Machine Identity record and helps you identify these accounts in AOH Sync.
Set priority and enable the rule
Enter a Priority number. If you have multiple rules, lower numbers are evaluated first — the first match wins. Toggle Enabled on, then click Add rule.
When no rules are defined, every incoming account is treated as a human Identity. Rules only affect records processed after the rule is saved and enabled — existing records are not reclassified retroactively.
Last updated