Home

AAD Connect - Object matching across forests, post-installation

%3CLINGO-SUB%20id%3D%22lingo-sub-227553%22%20slang%3D%22en-US%22%3EAAD%20Connect%20-%20Object%20matching%20across%20forests%2C%20post-installation%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-227553%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20would%20like%20to%20connect%20a%20second%20resource%20forest%20to%20our%20instance%20of%20AAD%20Connect.%26nbsp%3B%20This%20forest%20is%20used%20a%20Skype%20resource%20forest%20with%20disabled%20users%20populated%20with%20the%20necessary%20Skype%20attributes%20with%20the%20goal%20of%20hybrid%20enablement.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDuring%20the%20initial%20setup%20of%20AAD%20Connect%2C%20there%20is%20the%20option%20for%20%22Uniquely%20identifying%20your%20users%22.%26nbsp%3B%20However%2C%20this%20screen%20is%20not%20available%20during%20a%20re-run%20of%20the%20AAD%20config%20once%20it%20was%20been%20installed.%26nbsp%3B%20Is%20it%20possible%20post-installation%20to%20define%20a%20custom%20attribute%20to%20match%20users%20existing%20more%20than%20once%20across%20forests%3F%26nbsp%3B%20Is%20retroactive%20object%20matching%20possible%20or%20do%20we%20need%20to%20re-install%20AAD%20Connect%2C%20and%20recreate%20the%20metaverse%20and%20connectors%20once%20again%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAdditionally%2C%20we%20plan%20to%20use%20a%20custom%20attribute%20which%20is%20also%20our%20chosen%20ImmutableID%20and%20is%20written%20to%20both%20user%20objects%20through%20our%20identity%20provisioning%20system.%26nbsp%3B%20Do%20you%20see%20any%20issues%20using%20this%20attribute%20for%20the%20matching%20or%20would%20another%20be%20preferred%20in%20a%20Skype%20hybrid%20scenario%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-227553%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAAD%20Connect%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-227708%22%20slang%3D%22en-US%22%3ERe%3A%20AAD%20Connect%20-%20Object%20matching%20across%20forests%2C%20post-installation%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-227708%22%20slang%3D%22en-US%22%3E%3CP%3EHey%20Keith%2C%3CBR%20%2F%3E%3CBR%20%2F%3ENot%20sure%20I%20can%20answer%20all%20of%20your%20questions%2C%20but%20hopefully%20I%20can%20help%20the%20conversation%20along%20some.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconnect%2Factive-directory-aadconnect-topologies%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconnect%2Factive-directory-aadconnect-topologies%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EThat%20link%20goes%20over%20all%20the%20supported%20topologies.%20The%20good%20news%20is%20what%20you%20are%20describing%20is%20in%20there%20in%20two%20different%20forms%20(all%20under%20the%20multiple%20forest%20match%20users%20settings).%20As%20long%20as%20your%20users%20only%20have%20one%20active%20account%20(which%20your%20description%20points%20out)%20this%20should%20work.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20bad%20news%20is%20that%20it%20seems%20to%20match%20pre-defined%20the%20attributes%20for%20you%20to%20use%20as%20either%20Mail%20or%20ObjectSid%2Fan%20exchangeSid.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20would%20read%20into%20those%20topologies%20more%2C%20and%20with%20that%20as%20a%20starting%20point%20I%20am%20sure%20you%20can%20get%20more%20details%2C%20or%20perhaps%20someone%20smarter%20than%20me%20to%20help%20you%20here!%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EFinally%20yes%2C%20you%20want%20to%20re-install%20AADC%20as%20your%20are%20changing%20your%20topology%20and%20design%2C%20not%20modifying%20your%20existing%20one.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAdam%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Keith Potter
Occasional Contributor

We would like to connect a second resource forest to our instance of AAD Connect.  This forest is used a Skype resource forest with disabled users populated with the necessary Skype attributes with the goal of hybrid enablement.

 

During the initial setup of AAD Connect, there is the option for "Uniquely identifying your users".  However, this screen is not available during a re-run of the AAD config once it was been installed.  Is it possible post-installation to define a custom attribute to match users existing more than once across forests?  Is retroactive object matching possible or do we need to re-install AAD Connect, and recreate the metaverse and connectors once again? 

 

Additionally, we plan to use a custom attribute which is also our chosen ImmutableID and is written to both user objects through our identity provisioning system.  Do you see any issues using this attribute for the matching or would another be preferred in a Skype hybrid scenario?

1 Reply

Hey Keith,

Not sure I can answer all of your questions, but hopefully I can help the conversation along some.

 

https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-topologi...

That link goes over all the supported topologies. The good news is what you are describing is in there in two different forms (all under the multiple forest match users settings). As long as your users only have one active account (which your description points out) this should work.

 

The bad news is that it seems to match pre-defined the attributes for you to use as either Mail or ObjectSid/an exchangeSid.

I would read into those topologies more, and with that as a starting point I am sure you can get more details, or perhaps someone smarter than me to help you here! :)


Finally yes, you want to re-install AADC as your are changing your topology and design, not modifying your existing one.

 

Adam

 

Related Conversations
Extentions Synchronization
Deleted in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
36 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies