troubleshooting Question

0365 user accounts still have sync status of 'Synced with Active Directory' after AD user account has been moved to a non-synced OU

Avatar of vistamed
vistamedFlag for Ireland asked on
Microsoft 365Active DirectoryAzure
6 Comments1 Solution133 ViewsLast Modified:
Hi, for the past month I've had a problem with handling leavers' accounts in O365.
We use Azure Active Directory Connect to handle the syncing between AD and O365.
The way the process used to work is this:
  • To begin with, the leaver's account appears in O365 Admin Center, with a Sync Type of 'Synced with Active Directory'.
  • In 0365 Exchange Admin Center, Convert the leaver's mailbox to a shared mailbox.
  • In 0365 Admin Center, remove their O365 licences
  • In ADUC, disable the leaver's user account and move the user to an OU which is not synced with O365.
  • In Azure Active Directory Connect, perform a delta sync cycle.
  • After the sync, the user will have moved from 'Active Users' to 'Deleted Users' in 0365 Admin Center.
  • Select the user and click 'Restore'. Set a new password for the user.
  • The user will now be restored to 'Active Users' in O365 Admin Center, with a Sync Type of 'In Cloud'.
  • In 0365 Exchange Admin Center, edit the settings of the leaver's mailbox and tick the 'Hide from Address Book' tickbox.

As I say, that's how it USED to work. But beginning about a month ago, the process isn't working properly.
When I restore the user from 'Deleted Users' in 0365 Admin Center, the user is restored but the Sync Type is still saying 'Synced with Active Directory' - even though the AD user account has been moved to an OU which is not synced with O365.
As a result, I can't edit the settings of the leaver's mailbox and tick the 'Hide from Address Book' tickbox - I get a message telling me the 'the object is being synchronized from your on-premises organization'.

Just to make things even more annoying, I tried re-enabling the leaver's AD user account and moving it back into the synced OU. Then I edited the MSExchHideFromAddressLists attribute, setting it to TRUE rather than 'not set'. Then I did another sync... but the change to the attribute is not appearing in o365 - the mailbox's 'Hide from Address Book' tickbox is STILL not ticked.

I've just updated the version of Azure Active Directory Connect on the Domain Controller to version 1.2.70.0, in case the problem was due to a bug in version 1.2.65.0 which I installed a couple of months ago. But it hasn't made any difference - the leaver accounts are still showing as 'Synced with Active Directory'.
The O365 accounts of users who left more than a month or two ago are fine - they're still 'In Cloud'. The problem is only happening with users who left in the last month or two.


Has anyone else experienced this sudden change in behaviour? Do you know how to fix it?

Any advice most welcome!
ASKER CERTIFIED SOLUTION
Join our community to see this answer!
Unlock 1 Answer and 6 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 6 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros