Lost on premises AD and we want to sync office 365 accounts with the new AD with the same forest

%3CLINGO-SUB%20id%3D%22lingo-sub-1516975%22%20slang%3D%22en-US%22%3ELost%20on%20premises%20AD%20and%20we%20want%20to%20sync%20office%20365%20accounts%20with%20the%20new%20AD%20with%20the%20same%20forest%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1516975%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20had%20a%20disaster%20at%20work%2C%20we%20lost%20all%20VMs%20and%20Backups.%20now%20we%20build%20a%20new%20AD%20om%20premises%26nbsp%3B%20with%20the%20same%20forest%20and%20need%20to%20sync%20again%20with%20office%20365.%20accounts%20were%20syncing%20with%20password%20hash%20synchronization%20so%20now%20users%20can%20login%20on%20clouds%20but%20these%20accounts%20not%20liked%20to%20on%20premises%20accounts.%3C%2FP%3E%3CP%3EHow%20can%20i%20solve%20this%20issue.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1516975%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%20center%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1517062%22%20slang%3D%22en-US%22%3ERe%3A%20Lost%20on%20premises%20AD%20and%20we%20want%20to%20sync%20office%20365%20accounts%20with%20the%20new%20AD%20with%20the%20same%20forest%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1517062%22%20slang%3D%22en-US%22%3EHello%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F726156%22%20target%3D%22_blank%22%3E%40mlotfy%3C%2FA%3E%2C%3CBR%20%2F%3E%3CBR%20%2F%3Eif%20you%20are%20able%20to%20create%20the%20Active%20Directory%20on-premises%20with%20the%20same%20domain%20suffix%20and%20UserPrincipalName%20(UPN)%20for%20the%20users%2C%20a%20soft-match%20with%20the%20cloud%20objects%20should%20not%20be%20a%20problem.%20You%20just%20have%20to%20create%20the%20users%20with%20the%20same%20UPN%20and%20e-mail%20address%20as%20the%20cloud%20users.%20A%20soft%20match%20will%20be%20tried%20by%20the%20next%20sync%20of%20Azure%20AD%20Connect.%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20that%20is%20not%20possible%20or%20in%20your%20plans%2C%20you%20could%20alternate%20proceed%20with%20hard-match%20by%20matching%20the%20on-premises%20with%20the%20cloud%20objects%20by%20using%20the%20Azure%20AD%20anchor%20attribute%2C%20in%20most%20cases%20should%20be%20ms-DS-ConsistencyGuid%3CBR%20%2F%3E%3CBR%20%2F%3EPlease%20let%20me%20know%20if%20you%20need%20detailed%20information%3CBR%20%2F%3E%3CBR%20%2F%3EKind%20regards%3CBR%20%2F%3ESpikar%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1517093%22%20slang%3D%22en-US%22%3ERe%3A%20Lost%20on%20premises%20AD%20and%20we%20want%20to%20sync%20office%20365%20accounts%20with%20the%20new%20AD%20with%20the%20same%20forest%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1517093%22%20slang%3D%22en-US%22%3E%3CP%3EJust%20to%20add%20a%20small%20correction%20-%20soft%20match%20will%20not%20work%20in%20this%20scenario%2C%20as%20it%20requires%20the%20ImmutableID%20to%20be%20null.%20You'll%20either%20have%20to%20disable%20dirsynd%20in%20order%20to%20nullify%20the%20ImmutableId's%20of%20each%20user%2C%20or%20simply%20use%20the%20hard%20match%20method%20instead.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1517130%22%20slang%3D%22en-US%22%3ERe%3A%20Lost%20on%20premises%20AD%20and%20we%20want%20to%20sync%20office%20365%20accounts%20with%20the%20new%20AD%20with%20the%20same%20forest%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1517130%22%20slang%3D%22en-US%22%3E%3CP%3EHello%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3B%2C%20thank%20you%20for%20the%20correction%2C%20nice%20addition.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EI%2C%20maybe%20wrong%2C%20assumed%20that%20as%20his%20AD%20on-premises%20is%20lost%2C%3C%2FP%3E%3CP%3Ehe%20has%20already%20disabled%20DirSync%20to%20be%20able%20to%20manage%20the%20cloud%20objects%2C%20but%20your%20addition%20makes%20everything%20more%20clear%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKind%20regards%3C%2FP%3E%3CP%3ESpiros%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1517327%22%20slang%3D%22en-US%22%3ERe%3A%20Lost%20on%20premises%20AD%20and%20we%20want%20to%20sync%20office%20365%20accounts%20with%20the%20new%20AD%20with%20the%20same%20forest%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1517327%22%20slang%3D%22en-US%22%3EThanks%20all%20for%20replies%2C%20would%20you%20please%20describe%20steps%20as%20now%20there%20is%20no%20Ad%20connect%20installed.%3CBR%20%2F%3Ewhen%20we%20will%20install%20it%20it%20supposed%20to%20sync%20and%20there%20will%20be%20duplication%20of%20account%20on%20cloud%20%2C%20is%20that%20right%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1520445%22%20slang%3D%22en-US%22%3ERe%3A%20Lost%20on%20premises%20AD%20and%20we%20want%20to%20sync%20office%20365%20accounts%20with%20the%20new%20AD%20with%20the%20same%20forest%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1520445%22%20slang%3D%22en-US%22%3E%3CP%3EDo%20I%20have%20to%20disable%20the%20direct%20sync%20as%20it%20will%20take%20up%20to%2072%20hours%20as%20mentioned%20in%20Microsoft%20documentation%3F%3C%2FP%3E%3CP%3Eif%20not%20the%20scenario%20will%20be%20%3A%3C%2FP%3E%3CP%3Eclear%20%3CSPAN%3EImmutableId's%26nbsp%3B%3C%2FSPAN%3E%26nbsp%3Bin%20azure%20objects%20by%20script%26nbsp%3B%3C%2FP%3E%3CP%3ERun%20Direct%20sync%20by%20setting%20email%20as%20source%20anchor.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ewill%20that%20work%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1521195%22%20slang%3D%22en-US%22%3ERe%3A%20Lost%20on%20premises%20AD%20and%20we%20want%20to%20sync%20office%20365%20accounts%20with%20the%20new%20AD%20with%20the%20same%20forest%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1521195%22%20slang%3D%22en-US%22%3E%3CP%3EIn%20order%20to%20clear%20the%20ImmutableID%2C%20you%20need%20to%20disable%20DirSync.%26nbsp%3BOf%20you%20plan%20to%20use%20the%20hard-match%20method%2C%20there's%20no%20need%20to%20disable%20it%20as%20you%20can%20change%20the%20value%20directly%20via%20Set-AzureADUser.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

We had a disaster at work, we lost all VMs and Backups. now we build a new AD om premises  with the same forest and need to sync again with office 365. accounts were syncing with password hash synchronization so now users can login on clouds but these accounts not liked to on premises accounts.

How can i solve this issue. 

6 Replies
Highlighted
Hello @mlotfy,

if you are able to create the Active Directory on-premises with the same domain suffix and UserPrincipalName (UPN) for the users, a soft-match with the cloud objects should not be a problem. You just have to create the users with the same UPN and e-mail address as the cloud users. A soft match will be tried by the next sync of Azure AD Connect.

If that is not possible or in your plans, you could alternate proceed with hard-match by matching the on-premises with the cloud objects by using the Azure AD anchor attribute, in most cases should be ms-DS-ConsistencyGuid

Please let me know if you need detailed information

Kind regards
Spikar
Highlighted

Just to add a small correction - soft match will not work in this scenario, as it requires the ImmutableID to be null. You'll either have to disable dirsynd in order to nullify the ImmutableId's of each user, or simply use the hard match method instead.

Highlighted

Hello @Vasil Michev , thank you for the correction, nice addition.


I, maybe wrong, assumed that as his AD on-premises is lost,

he has already disabled DirSync to be able to manage the cloud objects, but your addition makes everything more clear

 

Kind regards

Spiros

 

 

Highlighted
Thanks all for replies, would you please describe steps as now there is no Ad connect installed.
when we will install it it supposed to sync and there will be duplication of account on cloud , is that right?
Highlighted

Do I have to disable the direct sync as it will take up to 72 hours as mentioned in Microsoft documentation?

if not the scenario will be :

clear ImmutableId's  in azure objects by script 

Run Direct sync by setting email as source anchor.

 

will that work?

 @Vasil Michev 

Highlighted

In order to clear the ImmutableID, you need to disable DirSync. Of you plan to use the hard-match method, there's no need to disable it as you can change the value directly via Set-AzureADUser.