AD SYNC problems

Hi Experts,

we have problems with AD SYNC to O365.
In the past all items were synced.

The AD SYNC was reinstalled and the anchor was changed to the recommended Microsoft value.
But old items in the Cloud cannot be deleted.

Do you know a way to clean up the synced objects ?
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
If the Objects in question are on On-Premise then they need to be deleted from On-Premise and not on Cloud. BTW what error do you get?
Eprs_AdminSystem Architect

Author

Commented:
the customer has objects in the cloud which are needed to delte.

In the past the source anchor was -> ObjectGuid
Here all items were synced to cloud.

Now the new source anchor is -> ms-ds Consistency Guid
Here just the users are synced

What I have to do, when I like to delete objects from the cloud ?
MaheshArchitect
Distinguished Expert 2018

Commented:
Are you saying that duplication is happened in cloud after you changed source anchor to consistency-guid?

what do you mean by old objects?

Changing source anchor should not create any issues as far as I know since objectGuid gets copied in consistency-guid attribute and based on that only immutable ID gets generated, so technically there should not be any duplication as immutable Id won't change

There is provision in msol powershell cmdlets to delete objects forcefully from cloud
Eprs_AdminSystem Architect

Author

Commented:
Hi Mahesh,

I never spoke from duplication.

1. in the past the customer synced all

2. Now a new AADSYNC install is in place and just the user OU is selected to sync. But still old objects in the cloud.

How to delete old objects from cloud ?
Architect
Distinguished Expert 2018
Commented:
Remove them manually / with script (foreach loop)
Get-msoluser -userPrincipalName <UPN> | remove-Msoluser -Force
Get-Msoluser -ReturnDeletedUsers | remove-msoluser -RemovefromRecyclebin -Force

OR

1st remove OU from sync and allow sync to run, this will soft delete those users from azure and remain in Azure Recyclebin (deleted users container)

Now Run,
get-msoluser -All | remove-msoluser -Force
Above command will delete all remaining users,
Now put Ou back to sync and users in synced OU will get pulled back from deleted users container

Finally once above process is completed, run
Get-Msoluser -ReturnDeletedUsers | remove-msoluser -RemovefromRecyclebin -Force
Above command will delete those users from deleted container as well
Eprs_AdminSystem Architect

Author

Commented:
this is good plan. Thanks.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial