charles sims
asked on
Convert On-prem 365 users to cloud only
What is the best way to convert users to cloud only from being synced with on-prem?
I've done this in the past and had issues with users getting blocked even if we move them out of synced containers in AD.
I've done this in the past and had issues with users getting blocked even if we move them out of synced containers in AD.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
uninstall AD connect from on-prem,
Remove federation between on-prem and your tenant by following ps command as below;
get-OrganizationRelationsh ip | Remove-OrganizationRelatio nship
Remove federation between on-prem and your tenant by following ps command as below;
get-OrganizationRelationsh
Set-MsolUser -UserPrincipalName user@domain.com -ImmutableId ""
If you want to do this without turning off DirSync, then you can remove the user from scope or filter them out, (this will soft-delete the user in Office 365, blocking them from login temporarily). Then you can then restore the users to active and run the command above to remove the ImmutableID. As mentioned this method will result in a temporary sign-in blockage.