Solved

DirSync - Office365 filter

Posted on 2014-01-31
4
472 Views
Last Modified: 2014-02-09
I am using Office365 integrated with Microsoft DirSync (Directory Synchronization). I am using the password synchronization feature and it Works great

Now I want to bypass/filter password syncronization for few users in my network. This is because they are Office365 users only (They don't use Active Directory Accounts inside the network). So they need to change their passwords throw the Office365 Portal

How can I filter the password synchronization feature for these few users?
0
Comment
Question by:Schnell Solutions
  • 2
4 Comments
 
LVL 38

Expert Comment

by:Vasil Michev (MVP)
ID: 39826406
Can you please double-check your post, it doesn't really make much sense. Why would you need to filter them if the don't have AD accounts? :)

Here are the instructions just in case:

http://technet.microsoft.com/en-us/library/jj710171.aspx

You can also use the WAAD PowerShell module to change the password of a synchronized user.
0
 
LVL 14

Author Comment

by:Schnell Solutions
ID: 39826585
Hello Vasilcho,

I want to centrally adminístrate all the users properties using Active Directory. I just want to avoid password synchronization for few of them. In this way, I will be able to créate and edit my users from the Internet network. For the case of these few users, as far as they don't use computers inside the domain, when they need to change their passwords they won't be able to make it. However, if the password attribute for them is not synchronizing, them they will be able to change it logging in throw Office365

Any one knows what I need to do in order to filter "just" password syncronization for few users?
0
 
LVL 38

Accepted Solution

by:
Vasil Michev (MVP) earned 500 total points
ID: 39826772
No, there isn't such option:

http://social.technet.microsoft.com/wiki/contents/articles/18096.dirsyncwindows-azure-ad-password-sync-frequently-asked-questions.aspx#Can_I_control_which_passwords_synchronize_to_the_cloud

The only exception to that is when you have federated users (AD FS), but in such scenario you again manage the passwords on-prem, so it is of no use to you.

You can always submit a feedback to request this as a feature in next versions of dirsync trough your Microsoft Partner or from here:

http://g.microsoftonline.com/0BX11EN/135
0
 
LVL 74

Expert Comment

by:Jeffrey Kane - TechSoEasy
ID: 39834743
Unfortunately, this is one of the drawbacks of DirSync -- users cannot change their password online.  Which means that Office365 ONLY users are unable to change their passwords.  This is because sync is ONE-WAY (on-prem ----> cloud) so any changes to their PW's in the cloud will be overwritten by the on-prem settings.

There are a couple of work-around tools to allow for online password changes:

ForeFront Identity Manager
SysOp Tools Password Reset Pro

The other option is to deploy a virtual Windows 7/8 machine that these users can access via RDP -- but that is a bit cumbersome when they just need to change an expiring password.

Jeff
0

Join & Write a Comment

Synchronize a new Active Directory domain with an existing Office 365 tenant
Follow this checklist to learn more about the 15 things you should never include in an email signature from personal quotes, animated gifs and out-of-date marketing content.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now