Avatar of ICTIC
ICTIC

asked on 

Azure AD connect using the wrong domain on sync

Hi,

I've got Office 365 setup for a primary school I support and I want to utilise AAD connect to initially sync passwords but eventually look into SSO using ADFS.

However after going through the installation and doing my first sync with a test account, the wrong domain is selected. Instead of user@domain.something.something, the account created in Office 365 is user@domain.onmicrosoft.com??

The correct domain is setup within Office 365 as the school have been using it for some time.

Please can you advise?

Thanks
AzureMicrosoft 365

Avatar of undefined
Last Comment
ICTIC
Avatar of Vasil Michev (MVP)
Vasil Michev (MVP)
Flag of Bulgaria image

If the domain is verified in O365, check whether you have proper UPN configured for the user in question. There are certain characters that are acceptable on-prem but will be ignored in O365. And if the UPN gets ignored, the SamAccountName plus the default onmicrosoft.com will be used instead.
Avatar of ICTIC
ICTIC

ASKER

Thanks Vasil

Will have a look and come back to you.
Avatar of ICTIC
ICTIC

ASKER

Hi

The UPN of our users does contain numbers but no other special characters?

Would that be a problem?

Thanks
Avatar of ICTIC
ICTIC

ASKER

Does the UPN have to be the same as the Office 365 UPN?

For example does my AD user need a UPN of test@school.sch.uk to match the Office 365 domain (school.sch.uk)?

Currently my local ad domain is school.internal??

Thanks
If you use .local or similar, it will be replaced with @domain.onmicrosoft.com. Same will happen for any UPN suffix that does not correspond to domain you have verified in O365.
Avatar of ICTIC
ICTIC

ASKER

OK, so what do I do here (best practice) as for this site and others I manage, the local AD domain is often <name>.internal and the office 365 domain is always <name>@<organisation>.county.sch.uk?

I could perhaps still verify the .internal domain in Office 365 but I still want the email/login of the Office 365 user to be <name>@<organisation>.county.sch.uk? How would this work?

I could manually change the domain once they are synced but I don't know if this would cause further issues?

Finally I thought I could provide an alternative local domain suffix as discussed here: https://community.office365.com/en-us/f/613/t/284307

Thank you for your help thus far
ASKER CERTIFIED SOLUTION
Avatar of Vasil Michev (MVP)
Vasil Michev (MVP)
Flag of Bulgaria image

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
Avatar of ICTIC
ICTIC

ASKER

Thanks Vasil, for clarifying.

I think I will go with changing the UPNs locally to keep it automated, is there ay consequence to doing this?

Then I think I am good to go :-)
Avatar of ICTIC
ICTIC

ASKER

Resolved following advice from Vasil
Microsoft 365
Microsoft 365

Office 365 is a group of software plus services subscriptions that provides productivity software and related services to its subscribers. Office 365 allows the use of Microsoft Office apps on Windows and OS X, provides storage space on Microsoft's cloud storage service OneDrive, and grants 60 Skype minutes per month. Office 365 includes e-mail and social networking services through hosted versions of Exchange Server, Skype for Business Server, SharePoint and Office Online, integration with Yammer, as well as access to the Office software. All of Office 365's components can be managed and configured through an online portal; users can be added manually, imported from a CSV file, or Office 365 can be set up for single sign-on with a local Active Directory using Active Directory Federation Services.

17K
Questions
--
Followers
--
Top Experts
Get a personalized solution from industry experts
Ask the experts
Read over 600 more reviews

TRUSTED BY

IBM logoIntel logoMicrosoft logoUbisoft logoSAP logo
Qualcomm logoCitrix Systems logoWorkday logoErnst & Young logo
High performer badgeUsers love us badge
LinkedIn logoFacebook logoX logoInstagram logoTikTok logoYouTube logo