o365 sync, merge users

%3CLINGO-SUB%20id%3D%22lingo-sub-1540591%22%20slang%3D%22en-US%22%3Eo365%20sync%2C%20merge%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1540591%22%20slang%3D%22en-US%22%3E%3CP%3EDear%20Microsoft%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20hope%20I%20can%20ask%20your%20help%20for%20further%20information%20about%20O365.%3C%2FP%3E%3CP%3Ewe%20have%20a%20(academic%2Funiversity)%20tenant%2C%20we%20use%20it%20with%20a%20%E2%80%9Efake%E2%80%9D%20subdomain%20(cl.domain)%2C%20have%20a%20lot%20of%20user%20who%20use%20Teams%20and%20Onedrive%20(and%20many%20other%20application)%3C%2FP%3E%3CP%3EIn%20parallel%20We%20have%20an%20on-premise%20AD%20and%20Exchange%20system.%3C%2FP%3E%3CP%3EWe%20would%20like%20to%20do%20a%20Password%20Hash%20Sync%20between%20the%20on-premise%20AD%20and%20O365%2C%20and%20have%20a%20few%20question%20about%20it%3A%3C%2FP%3E%3COL%3E%3CLI%3E%26nbsp%3BWhich%20DNS%20record%20is%20the%20basic%20%26nbsp%3Bwe%20definitely%20need%3F%20TXT%3F%20We%20don%E2%80%99t%20want%20to%20use%20Exchange%20online.%20We%20want%20an%20single%2Funified%20directory%20so%20our%20users%20can%20use%20system%20with%20the%20same%20username.%20Currently%20every%20user%20has%20an%20on-premise%20username%20and%20a%20%E2%80%9Ecloud%E2%80%9D%20username.%3C%2FLI%3E%3CLI%3EAfter%20the%20sync%20can%20we%20merge%20the%20users%3F%20%26nbsp%3BEach%20user%20is%20member%2Fowner%20of%20many%20Teams%20and%20they%20store%20a%20lot%20of%20files%20in%20Onedrive%3C%2FLI%3E%3CLI%3EIs%20it%20enough%20not%20to%20set%20the%20mx%20dns%20record%20or%20rather%20not%20give%20users%20the%20Exchange%20online%20license%3F%3C%2FLI%3E%3C%2FOL%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1540591%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%20center%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%20Administration%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1542785%22%20slang%3D%22en-US%22%3ERe%3A%20o365%20sync%2C%20merge%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1542785%22%20slang%3D%22en-US%22%3E%3CP%3EHey%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F570036%22%20target%3D%22_blank%22%3E%40Icsab%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20are%20a%20quite%20few%20things%20which%20you%20need%20to%20consider%20here%20in%20order%20to%20achieve%20this%2C%20although%20it%20calls%20for%20a%20more%20detailed%20discussion%2C%20i%20will%20try%20to%20summarize%20best%20i%20can%2C%20the%20overall%20strategy%20would%20look%20somewhat%20like%20this%3A%3C%2FP%3E%3CP%3E1.%20Add%20the%20production%20domain%20in%20office%20365%2C%20you%20just%20have%20to%20update%20the%20txt%20record%2C%20nothing%20more.%20Also%20set%20the%20domain%20to%20internal%20relay%20via%20exchange.%3C%2FP%3E%3CP%3E2.%20Change%20users'%20User%20principal%20name%20and%20primary%20SMTP%20in%20office%20365%3B%20match%20it%20to%20your%20on-premises%20user%20principal%20name%20for%20respective%20users.%20Make%20sure%20UPN%20matches%20primary%20SMTP.%20Changing%20the%20UPN%20won't%20delete%20the%20data%20present%20in%20OneDrive.%3C%2FP%3E%3CP%3E3.%20Remove%20exchange%20online%20license%20from%20the%20users.%20Hopefully%20you%20don't%20need%20the%20data%20already%20present%20in%20office%20365%20mailboxes%20%3F%3C%2FP%3E%3CP%3E4.%20Next%20you%20need%20to%20setup%20AADConnect%20to%20synchronize%20identities%20from%20on-premises%2C%20for%20the%20accounts%20to%20merge%20automatically%20(Also%20referred%20to%20as%20soft%20match)%2C%20you%20need%20to%20ensure%20that%20UPN%20in%20office%20365%20matches%20the%20UPN%20and%20primary%20SMTP%20address%20on-premises.%20You%20can%20also%20populate%20the%20'mail'%20attribute%20with%20the%20same%20as%20well.%20Run%20a%20full%20sync.%3C%2FP%3E%3CP%3EThis%20is%20a%20automated%20process%20and%20there%20can%20be%20misses%20often%2C%20what%20that%20would%20mean%20is%20you%20might%20see%20two%20different%20accounts%20in%20office%20365%20for%20same%20user%2C%20i.e%20if%20the%20merger%20fails.%20There%20is%20a%20manual%20method%20to%20match%20the%20users%20as%20well%20(Hard%20Match)%2C%20but%20it%20has%20to%20be%20employed%20with%20caution%20and%20only%20when%20you%20have%20verified%20the%20above%20conditions.%20Hard%20Match%20%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Farchive%2Fblogs%2Fpraveenkumar%2Fhow-to-do-hard-match-part-2%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Farchive%2Fblogs%2Fpraveenkumar%2Fhow-to-do-hard-match-part-2%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELooks%20scary%20%3F%20Try%20it%20with%20a%20dummy%20user%20first%2C%20create%20a%20dummy%20user%20in%20office%20365%20and%20on-premises%2C%20synchronize%20only%20the%20dummy%20user%20from%20on-premises%20(%20You%20can%20create%20an%20OU%20and%20have%20only%20the%20Dummy%20user%20in%20it%2C%20and%20sync%20this%20OU%20only%20using%20AADconnect.)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3BThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1572288%22%20slang%3D%22en-US%22%3ERe%3A%20o365%20sync%2C%20merge%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1572288%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F67895%22%20target%3D%22_blank%22%3E%40harveer%20singh%3C%2FA%3E%26nbsp%3B%20Thanks!%3C%2FP%3E%3CP%3EI%20needed%20the%20%22hard%20match%22%2C%20but%20everything%20looks%20good.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAfter%20the%20can%20i%20merge%2Fsnyc%20the%20Teams%20(%20they%20used%20it%20with%20the%20aad%20account%20before%20the%20sync)%20calender%20with%20the%20on-premise%20exchange%2Foutlook%20calendar%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethank%20you%20in%20advance%20for%20your%20reply%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1572600%22%20slang%3D%22fr-FR%22%3ERe%3A%20o365%20sync%2C%20merge%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1572600%22%20slang%3D%22fr-FR%22%3EHi%2C%20%3CBR%20%2F%3E%20to%20have%20users'%20calendar%20information%20with%20calendar%20synchronization%20in%20teams%20..%20it%20is%20imperative%20to%20set%20up%20a%20hybrid%20exchange%20infrastructure%20with%20exhange%20online%20..%20and%20of%20course%20as%20you%20wish%2C%20you%20can%20leave%20users'%20mailboxes%20on%20exchange%20on%20promise%20..%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1572612%22%20slang%3D%22en-US%22%3ERe%3A%20o365%20sync%2C%20merge%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1572612%22%20slang%3D%22en-US%22%3E%3CP%3EHey%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F570036%22%20target%3D%22_blank%22%3E%40Icsab%3C%2FA%3E%26nbsp%3B%2C%20Building%20on%20what%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F469815%22%20target%3D%22_blank%22%3E%40Kais_mbarki%3C%2FA%3E%26nbsp%3Bsaid%2C%20you%20would%20require%20an%20exchange%20build%20higher%20than%20Exchange%202016%20CU3.%20Here%20is%20a%20reference%20article%20%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fexchange-team-blog%2Fconfiguring-teams-calendar-access-for-exchange-on-premises%2Fba-p%2F1484009%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fexchange-team-blog%2Fconfiguring-teams-calendar-access-for-exchange-on-premises%2Fba-p%2F1484009%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1572621%22%20slang%3D%22fr-FR%22%3ERe%3A%20o365%20sync%2C%20merge%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1572621%22%20slang%3D%22fr-FR%22%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F67895%22%20target%3D%22_blank%22%3E%40harveer%20singh%3C%2FA%3E%3CBR%20%2F%3E%20I%20confirm%20...%20exactly%20that%3C%2FLINGO-BODY%3E
Occasional Contributor

Dear Microsoft,

 

I hope I can ask your help for further information about O365.

we have a (academic/university) tenant, we use it with a „fake” subdomain (cl.domain), have a lot of user who use Teams and Onedrive (and many other application)

In parallel We have an on-premise AD and Exchange system.

We would like to do a Password Hash Sync between the on-premise AD and O365, and have a few question about it:

  1.  Which DNS record is the basic  we definitely need? TXT? We don’t want to use Exchange online. We want an single/unified directory so our users can use system with the same username. Currently every user has an on-premise username and a „cloud” username.
  2. After the sync can we merge the users?  Each user is member/owner of many Teams and they store a lot of files in Onedrive
  3. Is it enough not to set the mx dns record or rather not give users the Exchange online license?
5 Replies
Highlighted

Hey @Icsab ,

 

There are a quite few things which you need to consider here in order to achieve this, although it calls for a more detailed discussion, i will try to summarize best i can, the overall strategy would look somewhat like this:

1. Add the production domain in office 365, you just have to update the txt record, nothing more. Also set the domain to internal relay via exchange.

2. Change users' User principal name and primary SMTP in office 365; match it to your on-premises user principal name for respective users. Make sure UPN matches primary SMTP. Changing the UPN won't delete the data present in OneDrive.

3. Remove exchange online license from the users. Hopefully you don't need the data already present in office 365 mailboxes ?

4. Next you need to setup AADConnect to synchronize identities from on-premises, for the accounts to merge automatically (Also referred to as soft match), you need to ensure that UPN in office 365 matches the UPN and primary SMTP address on-premises. You can also populate the 'mail' attribute with the same as well. Run a full sync.

This is a automated process and there can be misses often, what that would mean is you might see two different accounts in office 365 for same user, i.e if the merger fails. There is a manual method to match the users as well (Hard Match), but it has to be employed with caution and only when you have verified the above conditions. Hard Match : https://docs.microsoft.com/en-us/archive/blogs/praveenkumar/how-to-do-hard-match-part-2

 

Looks scary ? Try it with a dummy user first, create a dummy user in office 365 and on-premises, synchronize only the dummy user from on-premises ( You can create an OU and have only the Dummy user in it, and sync this OU only using AADconnect.)

 

 Thanks

Highlighted

@harveer singh  Thanks!

I needed the "hard match", but everything looks good.

 

After the can i merge/snyc the Teams ( they used it with the aad account before the sync) calender with the on-premise exchange/outlook calendar?

 

thank you in advance for your reply

 

Highlighted
Hi,
to have users 'calendar information with calendar synchronization in teams .. it is imperative to set up a hybrid exchange infrastructure with exhange online .. and of course as you wish, you can leave users' mailboxes on exchange on promise ..
Highlighted

Hey @Icsab , Building on what @Kais_mbarki said, you would require an exchange build higher than Exchange 2016 CU3. Here is a reference article : https://techcommunity.microsoft.com/t5/exchange-team-blog/configuring-teams-calendar-access-for-exch...

 

Thanks

Highlighted
@harveer singh
I confirm ... exactly that