Forum Discussion

RNalivaika's avatar
RNalivaika
Iron Contributor
Jan 15, 2021
Solved

Azure AD connect group soft match

Hi all, we have migrated to a new onprem AD forest recently, but kept the same O365 tenant. Soft matching of user accounts between new AD and O365 went just fine.  But we are facing some issues whe...
  • RNalivaika's avatar
    RNalivaika
    Feb 15, 2021

    catmur-fed I solved the issue by resorting to hard-match instead.

    I had also tried solving the issue with MS Support, but they were basically saying the same as you report in the thread, so that lead nowhere.

    The solution was to change source anchor to mS-DS-ConsistencyGuid on AzureAD Connect setup, populate matching immutableID on onprem groups and then run sync.

    you can take a look at this article for reference: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-design-concepts#changing-the-sourceanchor-attribute

    there was another article regarding group hard-maching but i cannot find it, i will maybe try later.

    Cheers

Resources