SOLVED
Home

samAcocuntName issue in Azure AD Domain services

%3CLINGO-SUB%20id%3D%22lingo-sub-35180%22%20slang%3D%22en-US%22%3EsamAcocuntName%20issue%20in%20Azure%20AD%20Domain%20services%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-35180%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20a%20weird%20issue%20with%20user%20object%20synchronization%20where%20samAccountName%20differs%20in%20AAD%20Domain%20Services.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOn%20Prem%20AD%20User%3A%20UPN%3A%20%3CSTRONG%3EfirstName%3C%2FSTRONG%3E%3CSPAN%3E%3CSTRONG%3E%40domain.com%3C%2FSTRONG%3E%20samAccountName%3A%3CSTRONG%3EfirstName%3C%2FSTRONG%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3EAAD%20Domain%20Servcies%20User%3A%20UPN%3A%20%3CSTRONG%3EfirstName%40domain.com%3C%2FSTRONG%3E%20samAccountName%3A%20%3CSTRONG%3EfirstNamelastName%3C%2FSTRONG%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3ESo%20when%20I%20login%20I%20cannot%20use%20domain%5CfirstName%20to%20login%20I%20have%20to%20either%20user%20firstName%40domain.com%20or%20Domain%5CfirstNamelastName%20to%20login.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3EHow%20did%20this%20samAccountName%20in%20the%20AAD%20Domain%20Services%20change%3F%20And%20why%20are%20the%20delta%2Ffull%20sync%20not%20picking%20up%20this%20change%20in%20the%20AAD%20Domain%20Services%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-51432%22%20slang%3D%22en-US%22%3ERe%3A%20samAcocuntName%20issue%20in%20Azure%20AD%20Domain%20services%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-51432%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F17256%22%20target%3D%22_blank%22%3E%40Daniel%20Martins%3C%2FA%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F5031%22%20target%3D%22_blank%22%3E%40Jerry%20Meyer%3C%2FA%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F9288%22%20target%3D%22_blank%22%3E%40Adam%20Fowler%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20issue%20indeed%20had%20nothing%20to%20do%20with%20Azure%20AD%20Domain%20Services%20it%20was%20the%20way%20the%20object%20was%20synced%20to%20the%20Azure%20AD%20in%20the%20first%20place%20due%20to%20a%20duplicate%20item%20created%20long%20back.%20Before%20I%20could%20troubleshoot%20this%20in%20detail%20I%20had%20to%20move%20my%20office%20365%20tenancy%20to%20another%20tenant%20as%20it%20was%20created%20in%20wrong%20country%20ages%20ago%20by%20mistake.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EApologies%20for%20the%20late%20reply%20but%20everything%20you%20guys%20are%20pointing%20out%20makes%20sense%20and%20I%20definitely%20have%20a%20better%20and%20clear%20understanding%20of%20troubleshooting%20and%20approching%20this%20issue%20in%20a%20better%20and%20faster%20way%20in%20future%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-50434%22%20slang%3D%22en-US%22%3ERe%3A%20samAcocuntName%20issue%20in%20Azure%20AD%20Domain%20services%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-50434%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20seen%26nbsp%3B%20this%20issue%20in%20another%20way%2C%20For%20instance%20i%20had%20a%20similar%20issue%20with%20password%20sync%20when%20we%20setup%20a%20new%20Azure%20AD%20sync%20from%20another%20server%20with%20another%20account.%20We%20did%20not%20clean%20up%20the%20old%20sync%20good%20enough%20so%20when%20we%20turned%20on%20the%20new%20Azure%20AD%20sync%20the%20old%20account%20was%20used%20and%20the%20old%20domain%20was%20syncing%20over%20the%20new%20Connectors%20from%20our%20new%20server%20in%20our%20new%20domain.%20So%20apparently%20microsoft%20keeps%20some%20sort%20of%20backup%20of%20you%20setting%20in%20there%20environment%20so%20you%20can%20get%20a%20Azure%20AD%20sync%20up%20and%20running%20really%20quick%20after%20disaster%20recovery.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20can%20check%20these%20kind%20of%20settings%20when%20you%20load%20in%20the%20msol%20service%20with%20powershell%20and%20run%20the%20get-msolcompanyinformation%20Command.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMaybe%20this%20is%20something%20like%20the%20same%20as%20you%20are%20experiencing.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-50344%22%20slang%3D%22en-US%22%3ERe%3A%20samAcocuntName%20issue%20in%20Azure%20AD%20Domain%20services%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-50344%22%20slang%3D%22en-US%22%3E%3CP%3EThis%20should%20just%20come%20down%20to%20the%20Azure%20Active%20Directory%20Connect%20options%20you%20have%20(assuming%20you're%20using%20that%20and%20not%20ADFS).%20First%20image%20on%20this%20article%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconnect%2Factive-directory-aadconnect-user-signin%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconnect%2Factive-directory-aadconnect-user-signin%3C%2FA%3E%20shows%20the%20option%20on%20'select%20the%20on-premises%20attribute%20to%20use%20as%20the%20Azure%20AD%20username'%20which%20may%20have%20just%20had%20'firstname'%20selected.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAzure%20AD%20Domain%20Services%20just%20gets%20given%20what%20it's%20given%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGuessing%20Jasjit%20deleted%20accounts%2FAzure%20AD%20and%20started%20again%2C%20otherwise%20you'd%20have%20to%20change%20them%20manually%20with%20PowerShell%20%3CA%20href%3D%22https%3A%2F%2Fwww.adamfowlerit.com%2F2016%2F05%2Fwrong-domain-users-azure-active-directory%2F%26nbsp%3B%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.adamfowlerit.com%2F2016%2F05%2Fwrong-domain-users-azure-active-directory%2F%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-50239%22%20slang%3D%22en-US%22%3ERe%3A%20samAcocuntName%20issue%20in%20Azure%20AD%20Domain%20services%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-50239%22%20slang%3D%22en-US%22%3E%3CP%3EI%60m%20glad%20you%20made%20it%20work%20afterall.%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F9288%22%20target%3D%22_blank%22%3E%40Adam%20Fowler%3C%2FA%3E%2C%20have%20you%20seen%20this%20before%3F%20If%20Jasjit%20sees%20it%20again%2C%20is%20the%20reset%20the%20only%20option%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-50102%22%20slang%3D%22en-US%22%3ERe%3A%20samAcocuntName%20issue%20in%20Azure%20AD%20Domain%20services%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-50102%22%20slang%3D%22en-US%22%3E%3CP%3ESorry%20for%20the%20late%20reply%20-%20but%20i%20am%20afraid%20I%20was%20not%20able%20to%20resolve%20this.%20I%20simply%20had%20to%20reset%20the%20whole%20setup%20and%20now%20everything%20is%20working%20as%20expected.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-48393%22%20slang%3D%22en-US%22%3ERe%3A%20samAcocuntName%20issue%20in%20Azure%20AD%20Domain%20services%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-48393%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F24559%22%20target%3D%22_blank%22%3E%40Jasjit%20Chopra%3C%2FA%3E%2C%20did%20you%20make%20any%20progress%20investigating%20why%20account%20name%20changed%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Jasjit Chopra
MVP

I have a weird issue with user object synchronization where samAccountName differs in AAD Domain Services.

 

On Prem AD User: UPN: firstName@domain.com samAccountName:firstName

 

AAD Domain Servcies User: UPN: firstName@domain.com samAccountName: firstNamelastName

 

So when I login I cannot use domain\firstName to login I have to either user firstName@domain.com or Domain\firstNamelastName to login.

 

How did this samAccountName in the AAD Domain Services change? And why are the delta/full sync not picking up this change in the AAD Domain Services?

6 Replies

Hello @Jasjit Chopra, did you make any progress investigating why account name changed?

Sorry for the late reply - but i am afraid I was not able to resolve this. I simply had to reset the whole setup and now everything is working as expected.

I`m glad you made it work afterall. @Adam Fowler, have you seen this before? If Jasjit sees it again, is the reset the only option?

Solution

This should just come down to the Azure Active Directory Connect options you have (assuming you're using that and not ADFS). First image on this article: https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-user-sig... shows the option on 'select the on-premises attribute to use as the Azure AD username' which may have just had 'firstname' selected.

 

Azure AD Domain Services just gets given what it's given :)

 

Guessing Jasjit deleted accounts/Azure AD and started again, otherwise you'd have to change them manually with PowerShell https://www.adamfowlerit.com/2016/05/wrong-domain-users-azure-active-directory/ 

I have seen  this issue in another way, For instance i had a similar issue with password sync when we setup a new Azure AD sync from another server with another account. We did not clean up the old sync good enough so when we turned on the new Azure AD sync the old account was used and the old domain was syncing over the new Connectors from our new server in our new domain. So apparently microsoft keeps some sort of backup of you setting in there environment so you can get a Azure AD sync up and running really quick after disaster recovery.

 

You can check these kind of settings when you load in the msol service with powershell and run the get-msolcompanyinformation Command.

 

Maybe this is something like the same as you are experiencing.

 

 

 

Thanks @Daniel Martins @Jerry Meyer @Adam Fowler

 

The issue indeed had nothing to do with Azure AD Domain Services it was the way the object was synced to the Azure AD in the first place due to a duplicate item created long back. Before I could troubleshoot this in detail I had to move my office 365 tenancy to another tenant as it was created in wrong country ages ago by mistake.

 

Apologies for the late reply but everything you guys are pointing out makes sense and I definitely have a better and clear understanding of troubleshooting and approching this issue in a better and faster way in future :)

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies