Solved

azure active directory - On-premises users

Posted on 2016-07-20
4
64 Views
Last Modified: 2016-07-20
I just connected my on-premises active directory to Azure Active Directory. For 99% of the company, it worked perfectly and their Office365 user is connected to their local user and domain login. I have about 10 users whose username on-premises did not match their Office365 username and I now have two users in Azure Active Directory for them.

Is there a way to merge these two on Azure Active Directory so that changes on-premises replicate through to AAD and their local login will work for AAD enabled application authentication?
0
Comment
Question by:ScotSunnergren
  • 2
  • 2
4 Comments
 
LVL 40

Expert Comment

by:Vasil Michev (MVP)
ID: 41721192
The sync process sometimes fails to reflect changes in UPNs, but you can work around this by changing the UPN directly in O365. Use the WAAD module and the following cmdlet:

Set-MsolUserPrincipalName -UserPrincipalName user@domain.com -NewUserPrincipalName user@newdomain.com

Open in new window


The cmdlet will work regardless of the user's sync status.
0
 

Author Comment

by:ScotSunnergren
ID: 41721219
I am not sure if your solution resolves my issue.

I have an on-premises user of firstname@domain.com and their office365/AAD user is firstnamelastname@domain.com.

After the initialization of the connector, I now have two users in AAD:

firstname@domain.com  (sourced from local active directory)
firstnamelastname@domain.com  (sourced from Azure Active Directory)

Is there a way to associate or merge these two together within AAD or do I need to rename one of them?
0
 
LVL 40

Accepted Solution

by:
Vasil Michev (MVP) earned 500 total points
ID: 41721400
Ah, got it. The only way is to remove the newly created firstnamelastname@domain.com from Azure AD, remove it from the recycle bin as well, then use the soft-match mechanism to "link" the on-prem object and the firstname@domain.com one: http://support.microsoft.com/kb/2641663
0
 

Author Comment

by:ScotSunnergren
ID: 41721703
Thank you,  But I subsequently found that initiating this wiped out email aliases on userids that were the same and did sync. Those aliases were originally entered on O365 and are now gone. I am running an exchange change report and hope to get a listing of what they were so I can re-instate them.

But I also found that, with the two linked, I cannot edit aliases on O365. Instead I would have to enter them as proxy detail in the advanced users and computers on the DC. That is not something I want to do so I will have to turn off the directory link...

Seems very strange that they get Azure to link to all of these other online services but the connection back to the local domain is terrible.

Thanks for the assistance!
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Cloud-based technologies and services will continue to grow in popularity in 2017 thanks to the simple, scalable and cost-effective solutions they deliver. Here are three areas where cloud adoption is poised to really take off.
This article describes my battle tested process for setting up delegation. I use this process anywhere that I need to setup delegation. In the article I will show how it applies to Active Directory
Office 365 is currently available in five editions. Three of them are for business use: Office 365 Business Essentials, Office 365 Business, and Office 365 Business Premium. Two of them are for home/personal use: Office 365 Home and Office 365 Perso…
In this video I am going to show you how to back up and restore Office 365 mailboxes using CodeTwo Backup for Office 365. Learn more about the tool used in this video here: http://www.codetwo.com/backup-for-office-365/ (http://www.codetwo.com/ba…

792 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question