AD Connector - Office 365

zero000kool
zero000kool used Ask the Experts™
on
We are using Office 365 and us AD Connector to sync our on-premises Active Directory with O365.

We do NOT disable accounts, we just set the Logon Hours equal to NEVER.

What do I have to do in AD Connector to not sync users whose 'Logon Hours is set to NEVER.
I do not want to sync this option.

Thanks
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Most Valuable Expert 2015
Distinguished Expert 2018

Commented:
Check the guide I have here: http://www.michev.info/Blog/Post/62/How-to-prevent-disabled-accounts-from-syncing-to-Azure-AD-when-using-AADSync

On the Scope filter step, use the logonHours attribute instead of userAccountControl, and use the ISNOTNULL condition. Or use an actual proper filter that will check the value of logonHours (my example simply checks if the attribute exists).

Author

Commented:
That is the problem there is no LogonHours attribute when I do a connector.
Where is it?
Most Valuable Expert 2015
Distinguished Expert 2018

Commented:
On the AD Connector, go to properties -> Select attributes. Make sure the "show all" checkbox is ticked and find the logonHours attribute. If the checkbox in front of it is not ticked, check it and save the changes.
OWASP: Threats Fundamentals

Learn the top ten threats that are present in modern web-application development and how to protect your business from them.

Author

Commented:
I found the logon hours, what would the value have to be so users who's logon hours are set as logon disabled under their name?

thanks

Author

Commented:
We do not do disabled accounts, we set the LogonHours and then Logon Disabled

in AD these accounts are NOT disabled.
Most Valuable Expert 2015
Distinguished Expert 2018
Commented:
If it were me, I would just check whether the attribute exists (should not be populated by default), and act accordingly. But I dont know your current setup, so this might not be appropriate method.

The values you can check by looking at the Attributes Editor tab for one such user.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial