SOLVED
Home

Convert a SINGLE user from Federated to Managed Authentication and then BACK to Federated... HOW?

%3CLINGO-SUB%20id%3D%22lingo-sub-892877%22%20slang%3D%22en-US%22%3EConvert%20a%20SINGLE%20user%20from%20Federated%20to%20Managed%20Authentication%20and%20then%20BACK%20to%20Federated...%20HOW%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-892877%22%20slang%3D%22en-US%22%3E%3CDIV%3E%3CFONT%3E%3CBR%20%2F%3EHello!%3CBR%20%2F%3EWe%20are%20troubleshooting%20some%20account%20lockout%20issues.%26nbsp%3B%20We%20have%20O365%20with%20our%20domain%20in%20Federated%20Authentication%20(PingFed).%3CBR%20%2F%3E%26nbsp%3B%3CBR%20%2F%3EWe%20want%20to%20just%20change%201%20user%20from%20federated%20to%20managed%20auth...%20I%20see%20the%20command%20for%20it%20Convert-MSOLFederatedUser%20%E2%80%A6%20but%20I%20don't%20see%20any%20command%20to%20convert%20the%20user%20back%20to%20Federated%3F%3F%3C%2FFONT%3E%3C%2FDIV%3E%3CDIV%3E%3CFONT%3EAny%20suggestions%3F%3F%3C%2FFONT%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-892877%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAuthentication%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-896155%22%20slang%3D%22en-US%22%3ERe%3A%20Convert%20a%20SINGLE%20user%20from%20Federated%20to%20Managed%20Authentication%20and%20then%20BACK%20to%20Federated...%20HOW%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-896155%22%20slang%3D%22en-US%22%3E%3CP%3EFrom%20my%20understanding%20the%20command%20Convert-MsolFederatedUser%20is%20supposed%20to%20be%20used%20after%20the%20conversion%20of%20the%20sign%20in%20domain%20back%20to%20the%20standard%20authentication%20type.%20A%20new%20password%20has%20to%20be%20specified%20for%20the%20user%20as%20well.%20With%20federation%20it%20is%20all%20or%20nothing%20when%20it%20comes%20to%20domain.%20All%20users%20will%20use%20the%20same%20authentication%20method%20federated%20or%20standard.%20I%20have%20however%20successfully%20tested%20sign%20in%20issues%20by%20changing%20the%20UPN%20suffix%20in%20Active%20Directory%20for%20the%20user.%20This%20can%20be%20accomplished%20by%20using%20the%20.onmicrosoft.com%20domain%20or%20if%20your%20company%20owns%20a%20second%20domain%20that%20is%20verified%20in%20Office%20365.%20Let%20me%20know%20if%20I%20can%20assist%20any%20other%20way!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EConvert-MsolFederatedUser%20Doc%20-%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fpowershell%2Fmodule%2Fmsonline%2Fconvert-msolfederateduser%3Fview%3Dazureadps-1.0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fpowershell%2Fmodule%2Fmsonline%2Fconvert-msolfederateduser%3Fview%3Dazureadps-1.0%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F419970%22%20target%3D%22_blank%22%3E%40ch0wd0wn%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-897335%22%20slang%3D%22en-US%22%3ERe%3A%20Convert%20a%20SINGLE%20user%20from%20Federated%20to%20Managed%20Authentication%20and%20then%20BACK%20to%20Federated...%20HOW%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-897335%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Bryan%3C%2FP%3E%3CP%3EYeah%20you're%20right%2C%20I%20believe%20the%20convert-msolfederateuser%20command%20is%20used%20to%20migrate%201%20off%20users%20that%20didn't%20get%20successfully%20converted%20when%20you%20convert%20the%20entire%20domain%20from%20federation%20to%20standard.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThat%20being%20said%2C%20I'm%20just%20trying%20to%20remove%20federation%20authentication%20services%20for%20a%20single%20user%2C%20don't%20want%20to%20switch%20an%20entire%20domain.%26nbsp%3B%20I%20know%20I%20can%20change%20their%20logon%20to%20onmicrosoft.com%20and%20then%20that%20will%20be%20local%20authentication%20%E2%80%A6%20however%20that%20means%20I'd%20have%20to%20make%20the%20user's%20UPN%20to%20onmicrosoft.com%20as%20well%20right%3F%20%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F183000%22%20target%3D%22_blank%22%3E%40Bryan%20Haslip%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-897459%22%20slang%3D%22en-US%22%3ERe%3A%20Convert%20a%20SINGLE%20user%20from%20Federated%20to%20Managed%20Authentication%20and%20then%20BACK%20to%20Federated...%20HOW%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-897459%22%20slang%3D%22en-US%22%3E%3CP%3EI%20assume%20the%20users%20are%20coming%20from%20your%20local%20AD%20through%20AD%20connect%20correct%3F%20If%20that%20is%20the%20case%20you%20can%20just%20change%20the%20UPN%20suffix%20for%20that%20particular%20user%20on%20the%20domain%20controller%20to%20.onmicroosft.com%20or%20another%20domain%20that%20is%20not%20federated%20and%20force%20a%20sync.%20What%20is%20important%20to%20note%20about%20this%20is%20don't%20change%20the%20proxy%20addresses%20in%20the%20attributes%20as%20that%20will%20change%20their%20actual%20email%20address%20and%20could%20make%20mail%20for%20that%20user%20bounce.%20Once%20that%20is%20completed%20you%20should%20see%20that%20the%20users%20sign%20in%20address%20switch%20to%20.onmicrosoft.com%20and%20you%20can%20then%20test%20authentication%20with%20the%20domain%20password.%20There%20is%20one%20more%20method%20you%20could%20try%20if%20this%20does%20not%20work%20for%20you.%20Let%20me%20know%20and%20I%20can%20explain%20the%20second%20method%20if%20needed.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F419970%22%20target%3D%22_blank%22%3E%40ch0wd0wn%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-897600%22%20slang%3D%22en-US%22%3ERe%3A%20Convert%20a%20SINGLE%20user%20from%20Federated%20to%20Managed%20Authentication%20and%20then%20BACK%20to%20Federated...%20HOW%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-897600%22%20slang%3D%22en-US%22%3E%3CP%3EYes%20you%20are%20correct%2C%20on%20prem%20AD%20with%20AAD%20Connect%20with%20password%20sync%20turned%20on%20(eventhough%20we%20are%20using%20federated%20authentication%20through%20PingFederate)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOk%20the%20only%20change%20I'll%20make%20is%20to%20the%20UPN%20for%20the%20user.%26nbsp%3B%20I%20just%20want%20to%20make%20sure%20this%20doesn't%20impact%20his%20day%20to%20day%20activities%20like%20logging%20into%20windows...etc%20which%20it%20shouldn't.%26nbsp%3B%20Do%20I%20need%20to%20recreate%20Outlook%20profile%20or%20should%20I%20just%20let%20it%20prompt%20for%20updated%20credentials%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELet%20me%20try%20this%20method%20first%2C%20its%20easy%20enough.%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F183000%22%20target%3D%22_blank%22%3E%40Bryan%20Haslip%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-897622%22%20slang%3D%22en-US%22%3ERe%3A%20Convert%20a%20SINGLE%20user%20from%20Federated%20to%20Managed%20Authentication%20and%20then%20BACK%20to%20Federated...%20HOW%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-897622%22%20slang%3D%22en-US%22%3E%3CP%3EDo%26nbsp%3Byour%20users%20authenticate%20with%20Domain%5CUsername%3F%20If%20so%20this%20change%20will%20not%20affect%20how%20the%20user%20is%20logging%20on%20to%20their%20local%20machine.%20I%20usually%20just%20let%20Outlook%20prompt%20stating%20that%20it%20is%20no%20longer%20connected%20to%20Microsoft%20Exchange%20and%20prompts%20for%20the%20username%20and%20password.%20Hope%20this%20helps!%26nbsp%3B%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F419970%22%20target%3D%22_blank%22%3E%40ch0wd0wn%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-897687%22%20slang%3D%22en-US%22%3ERe%3A%20Convert%20a%20SINGLE%20user%20from%20Federated%20to%20Managed%20Authentication%20and%20then%20BACK%20to%20Federated...%20HOW%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-897687%22%20slang%3D%22en-US%22%3E%3CP%3EYes%20they%20use%20domain%5Cusername%20for%20the%20most%20part.%26nbsp%3B%20THanks%20so%20much%20for%20the%20tip!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-903748%22%20slang%3D%22en-US%22%3ERe%3A%20Convert%20a%20SINGLE%20user%20from%20Federated%20to%20Managed%20Authentication%20and%20then%20BACK%20to%20Federated...%20HOW%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-903748%22%20slang%3D%22en-US%22%3E%3CP%3EHey%20Bryan%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EChanging%20the%20UPN%20worked%2C%20however%20the%20user%20now%20can't%20get%20into%20Outlook%20and%20authenticate%20or%20his%20mobile%20device...%20he%20basically%20has%20to%20use%20OWA.%26nbsp%3B%20The%20authentication%20keeps%20prompting%20over%20and%20over%20even%20if%20we%20created%20a%20new%20Outlook%20profile.%26nbsp%3B%20I%20thought%20that%20this%20should%20authenticate%20the%20user%20regardless%20of%20the%20application%20he%20was%20using...%20any%20thoughts%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F183000%22%20target%3D%22_blank%22%3E%40Bryan%20Haslip%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-910804%22%20slang%3D%22en-US%22%3ERe%3A%20Convert%20a%20SINGLE%20user%20from%20Federated%20to%20Managed%20Authentication%20and%20then%20BACK%20to%20Federated...%20HOW%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-910804%22%20slang%3D%22en-US%22%3E%3CP%3ESorry%20for%20the%20slow%20response!%20Have%20you%20tried%20clearing%20out%20the%20credential%20manager%20on%20the%20local%20machine%3F%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F419970%22%20target%3D%22_blank%22%3E%40ch0wd0wn%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-910810%22%20slang%3D%22en-US%22%3ERe%3A%20Convert%20a%20SINGLE%20user%20from%20Federated%20to%20Managed%20Authentication%20and%20then%20BACK%20to%20Federated...%20HOW%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-910810%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F419970%22%20target%3D%22_blank%22%3E%40ch0wd0wn%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20may%20be%20an%20issue%20with%20the%20domain%20federation.%20If%20AAD%20detects%20the%20domain%20requires%20to%20sign%20in%20from%20services%20like%20AD%20FS%20etc.%2C%20then%20the%20domain%20will%20be%20redirected%20when%20the%20user%20enters%20the%20email%20address%20into%20M365.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20what%20may%20be%20happening%20is%2C%20when%20the%20user%20connected%20to%20outlook%20on%20the%20device%2C%20it%20performs%20a%20domain%20check.%20If%20the%20domain%20requires%20authentication%20via%20AD%20FS%2C%20then%20the%20user%20would%20be%20redirected%20to%20that%20endpoint%20to%20login.%20At%20this%20point%2C%20the%20claim%20token%20would%20not%20match%20for%20the%20users%20in%20AAD.%20The%20login%20would%20fail.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20can%20not%20switch%20off%20the%20redirection%20for%20the%20domain%20authentication%2C%20try%20getting%20the%20user%20to%20use%20the%20onmicrosoft.com%20address.%20All%20users%20in%20AzureAD%20have%20username%40tenant.onmicrosoft.com%20address.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
ch0wd0wn
Occasional Contributor

Hello!
We are troubleshooting some account lockout issues.  We have O365 with our domain in Federated Authentication (PingFed).
 
We want to just change 1 user from federated to managed auth... I see the command for it Convert-MSOLFederatedUser … but I don't see any command to convert the user back to Federated??
Any suggestions??
9 Replies

From my understanding the command Convert-MsolFederatedUser is supposed to be used after the conversion of the sign in domain back to the standard authentication type. A new password has to be specified for the user as well. With federation it is all or nothing when it comes to domain. All users will use the same authentication method federated or standard. I have however successfully tested sign in issues by changing the UPN suffix in Active Directory for the user. This can be accomplished by using the .onmicrosoft.com domain or if your company owns a second domain that is verified in Office 365. Let me know if I can assist any other way!

 

Convert-MsolFederatedUser Doc - https://docs.microsoft.com/en-us/powershell/module/msonline/convert-msolfederateduser?view=azureadps...

 

 @ch0wd0wn 

Hi Bryan

Yeah you're right, I believe the convert-msolfederateuser command is used to migrate 1 off users that didn't get successfully converted when you convert the entire domain from federation to standard.

 

That being said, I'm just trying to remove federation authentication services for a single user, don't want to switch an entire domain.  I know I can change their logon to onmicrosoft.com and then that will be local authentication … however that means I'd have to make the user's UPN to onmicrosoft.com as well right?  

 

 

@Bryan Haslip 

I assume the users are coming from your local AD through AD connect correct? If that is the case you can just change the UPN suffix for that particular user on the domain controller to .onmicroosft.com or another domain that is not federated and force a sync. What is important to note about this is don't change the proxy addresses in the attributes as that will change their actual email address and could make mail for that user bounce. Once that is completed you should see that the users sign in address switch to .onmicrosoft.com and you can then test authentication with the domain password. There is one more method you could try if this does not work for you. Let me know and I can explain the second method if needed. 

 

 @ch0wd0wn 

Yes you are correct, on prem AD with AAD Connect with password sync turned on (eventhough we are using federated authentication through PingFederate)

 

Ok the only change I'll make is to the UPN for the user.  I just want to make sure this doesn't impact his day to day activities like logging into windows...etc which it shouldn't.  Do I need to recreate Outlook profile or should I just let it prompt for updated credentials?

 

Let me try this method first, its easy enough.

@Bryan Haslip 

Solution

Do your users authenticate with Domain\Username? If so this change will not affect how the user is logging on to their local machine. I usually just let Outlook prompt stating that it is no longer connected to Microsoft Exchange and prompts for the username and password. Hope this helps!  @ch0wd0wn 

Yes they use domain\username for the most part.  THanks so much for the tip!

Hey Bryan

 

Changing the UPN worked, however the user now can't get into Outlook and authenticate or his mobile device... he basically has to use OWA.  The authentication keeps prompting over and over even if we created a new Outlook profile.  I thought that this should authenticate the user regardless of the application he was using... any thoughts?

 

@Bryan Haslip 

Sorry for the slow response! Have you tried clearing out the credential manager on the local machine? @ch0wd0wn 

Hi @ch0wd0wn 

 

It may be an issue with the domain federation. If AAD detects the domain requires to sign in from services like AD FS etc., then the domain will be redirected when the user enters the email address into M365.

 

So what may be happening is, when the user connected to outlook on the device, it performs a domain check. If the domain requires authentication via AD FS, then the user would be redirected to that endpoint to login. At this point, the claim token would not match for the users in AAD. The login would fail.

 

If you can not switch off the redirection for the domain authentication, try getting the user to use the onmicrosoft.com address. All users in AzureAD have username@tenant.onmicrosoft.com address.

 

 

Related Conversations
Extentions Synchronization
ChirmyRam in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies