Home

Azure AD Sync to On-Prem AD

%3CLINGO-SUB%20id%3D%22lingo-sub-103196%22%20slang%3D%22en-US%22%3EAzure%20AD%20Sync%20to%20On-Prem%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-103196%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3EI%20have%20Azure%20AD%20with%20about%2050%20users.%20These%20users%20were%20made%20when%20we%20purchased%20Office365.%20Let's%20say%20domain%26nbsp%3Bon%20Azure%20AD%20is%20example.com.%20(username%40example.com)%3C%2FP%3E%3CP%3ELocally%2C%20we%20use%20on-prem%20AD%20to%20authenticate%20computers%20as%20well%20as%20the%20wirelss%20network%20via%20RADIUS.%20Let's%20say%20the%20local%20domain%20is%20corp.example.com.%20(username%40corp.example.com)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENow%20what%20I%20need%20is%20to%20unify%20the%20usernames%20and%20passwords.%20I%20want%20usernames%20and%20passwords%20that%20are%20in%20Azure%20AD%20to%20be%20used%20on%20prem%20as%20well.%20(So%20we%20let%20go%20of%20corp.example.com%20and%20move%20to%20example.com%20on%20both%20Azure%20AD%20and%20On-Prem%20AD).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EWhat%20is%20the%20process%20to%20achieve%20this%20result%3F%26nbsp%3B%20I%3C%2FSTRONG%3E%20am%20okay%20with%20making%20any%20changes%20to%20local%20or%20Azure%20AD%20as%20long%20as%20I%20get%20to%20use%20username%40example.com%20for%20both%20for%20Azure%20AD%20and%20Local%20AD%20authentication.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EP.S%20%3A%26nbsp%3Bmy%20understanding%20is%20that%20locally%20you%20can't%20use%20a%20domain%20name%20that%20resolves%20to%20a%20website%3F%26nbsp%3B(so%20I%20can't%20remake%20the%20on-prem%20AD%20to%20use%20example.com%20%3F%26nbsp%3B)%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-103196%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-103334%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Sync%20to%20On-Prem%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-103334%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Januka%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20only%20will%20change%20the%20UPN%2C%20not%20the%20public%20domain%20internaly%2C%20just%20the%20way%20the%20user%20login%20on%20Office%20365.%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20AD%20Connect%20will%20softmatch%20the%20password%20is%20from%20AD%2C%20you%20source%20of%20identity%20will%20be%20AD%20not%20Azure%20AD.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20have%20to%20setup%20the%20AD%20Connect%2C%20just%20do%20a%20scope%20to%20a%20few%20test%20users%20and%20after%20you%20see%20how%20it%20works%2C%20send%20communications%20to%20the%20end%20users%20that%20after%20date%2Fhour%20x%20their%20passwords%20on%20Office%20365%20will%20be%20the%20same%20that%20are%20from%20AD.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-103327%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Sync%20to%20On-Prem%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-103327%22%20slang%3D%22en-US%22%3E%22You%20can%20use%20your%20public%20domain%20that%20is%20registered%20on%20Azure%20AD%20in%20your%20on-premises%20AD%20changing%20the%20UPN%20of%20the%20users%20to%20that%20domain%20and%20then%20match%20the%20email.%22%3CBR%20%2F%3E%3CBR%20%2F%3EIs%20it%20okay%20to%20use%20public%20domain%20internally%3F%20My%20understanding%20is%20that%20you%20should%20not%20use%20resolvable%20domain%20names%20internally%3F%3CBR%20%2F%3EIf%20that%20is%20okay%2C%20then%20I%20will%20have%20equal%20usernames%20on%20both%20on-prem%20AD%20and%20Azure%20AD.%3CBR%20%2F%3E%3CBR%20%2F%3EWhen%20I%20use%20AD%20Connect%2C%20will%20it%20automatically%20softmatch%20%3FAnd%20will%20it%20sync%20passwords%20FROM%20Azure%20AD%20to%20On-Prem%20AD%20or%20other%20way%20around%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-103212%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Sync%20to%20On-Prem%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-103212%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Januka%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20can%20use%20your%20public%20domain%20that%20is%20registered%20on%20Azure%20AD%20in%20your%20on-premises%20AD%20changing%20the%20UPN%20of%20the%20users%20to%20that%20domain%20and%20then%20match%20the%20email.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETo%20acomplish%20that%20you%20have%20to%20add%20a%20new%20domain%20in%20%22Active%26nbsp%3BDirectory%20Domains%20and%20Trusts%22%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fcc772007(v%3Dws.11).aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fcc772007(v%3Dws.11).aspx%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAfter%20this%20change%20your%20UPN%20and%20email%20of%20your%20users%20to%20match%20the%20username%20of%20Azure%20AD.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThen%20Install%20AD%20Connect%20and%20when%20you%20enable%20it%20it%20will%20softmatch%20your%20user.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBe%20carfully%20of%20this%20steps%20and%20if%20you%20need%20any%20help%20please%20tell.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Deleted
Not applicable

Hello,

I have Azure AD with about 50 users. These users were made when we purchased Office365. Let's say domain on Azure AD is example.com. (username@example.com)

Locally, we use on-prem AD to authenticate computers as well as the wirelss network via RADIUS. Let's say the local domain is corp.example.com. (username@corp.example.com)

 

Now what I need is to unify the usernames and passwords. I want usernames and passwords that are in Azure AD to be used on prem as well. (So we let go of corp.example.com and move to example.com on both Azure AD and On-Prem AD).

 

What is the process to achieve this result?  I am okay with making any changes to local or Azure AD as long as I get to use username@example.com for both for Azure AD and Local AD authentication. 

 

P.S : my understanding is that locally you can't use a domain name that resolves to a website? (so I can't remake the on-prem AD to use example.com ? ) 

 

 

3 Replies

Hi Januka,

 

You can use your public domain that is registered on Azure AD in your on-premises AD changing the UPN of the users to that domain and then match the email.

 

To acomplish that you have to add a new domain in "Active Directory Domains and Trusts"

https://technet.microsoft.com/en-us/library/cc772007(v=ws.11).aspx

 

After this change your UPN and email of your users to match the username of Azure AD.

 

Then Install AD Connect and when you enable it it will softmatch your user.

 

Be carfully of this steps and if you need any help please tell.

 

 

Highlighted
"You can use your public domain that is registered on Azure AD in your on-premises AD changing the UPN of the users to that domain and then match the email."

Is it okay to use public domain internally? My understanding is that you should not use resolvable domain names internally?
If that is okay, then I will have equal usernames on both on-prem AD and Azure AD.

When I use AD Connect, will it automatically softmatch ?And will it sync passwords FROM Azure AD to On-Prem AD or other way around?

Hi Januka,

 

You only will change the UPN, not the public domain internaly, just the way the user login on Office 365. 

When AD Connect will softmatch the password is from AD, you source of identity will be AD not Azure AD.

 

You have to setup the AD Connect, just do a scope to a few test users and after you see how it works, send communications to the end users that after date/hour x their passwords on Office 365 will be the same that are from AD.

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
30 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies