Forum Discussion
Martin Andersson
Oct 09, 2018Brass Contributor
Problems setting up Azure AD Connect
Hello! Ive recently installed Azure AD Connect on one of our DCs. Ive started out with an testing OU with 1 user. This user also existed in Office365/AzureAD as "In-cloud" user. I made the ...
- Oct 09, 2018
You need to look at the Export flows. In general, the question you need to answer here is whether you see a new/duplicate account provisioned for the same user in O365? And, whether there are "quarantined" objects due to the duplicate attribute resiliency feature: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-syncservice-duplicate-attribute-resiliency
For general info, objects are being matched between AD and AAD on objectGUID first, and if that fails on the PrimarySMTPAddress (so-called hard-match and soft-match mechanisms). The later will only work if the ImmutableID is empty. Neither one will work if there are errors/quarantined object due to duplicate attributes. Matching UPNs will not "link" the two objects, but you can force the matching process using the articles I linked to above.
One other thing, you should not mess with the objectIdentifier/sourceAnchor, unless you have some specific configurations in place. It's not clear to me why you have chosen to use the mail attribute and not leave the default.
Martin Andersson
Oct 09, 2018Brass Contributor
Hey Adam!
I have tried both
Start-AdSyncSyncCycle -Policytype Initial
Start-AdSyncSyncCycle -Policytype Delta
I have not changed the default source anchor, from what i know atleast, is there any way to check this?
During the setup, i choose.
"Uniquely identifying your users
• User identities exist across multiple directories. Match using:
•Mail attribute
Select how users should be identified with Azure AD
• Let Azure manage the source anchor"
I have tried both
Start-AdSyncSyncCycle -Policytype Initial
Start-AdSyncSyncCycle -Policytype Delta
I have not changed the default source anchor, from what i know atleast, is there any way to check this?
During the setup, i choose.
"Uniquely identifying your users
• User identities exist across multiple directories. Match using:
•Mail attribute
Select how users should be identified with Azure AD
• Let Azure manage the source anchor"
Oct 09, 2018
What happens during sync? Is the ad user created as a second account or nothing happens?