AAD Connect Migration and Configuration Documenter Results

%3CLINGO-SUB%20id%3D%22lingo-sub-1045926%22%20slang%3D%22en-US%22%3ERe%3A%20AAD%20Connect%20Migration%20and%20Configuration%20Documenter%20Results%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1045926%22%20slang%3D%22en-US%22%3E%3CP%3EThose%20are%20standard%20attributes%20that%20should%20be%20covered%20by%20the%20default%20rules.%20I%20cannot%20speak%20for%20the%20documenter%2C%20but%20you%20can%20simply%20run%20the%20new%20instance%20in%20staging%20mode%20and%20verify%20that%20the%20attributes%20in%20question%20flow%20to%20the%20metaverse.%20Similarly%2C%20you%20can%20run%20a%20Preview%20from%20the%20connector%20space%20object's%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1046621%22%20slang%3D%22en-US%22%3ERe%3A%20AAD%20Connect%20Migration%20and%20Configuration%20Documenter%20Results%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1046621%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20appreciate%20your%20feedback!%3C%2FP%3E%3CP%3EI%20will%20look%20into%20using%20the%20metaverse%20to%20accomplish%20this.%3C%2FP%3E%3CP%3EI%20haven't%20used%20the%20metaverse%20before%20so%20I%20am%20not%20super%20familiar%20with%20it.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20did%20know%20that%20we%20could%20run%20a%20%22staging%20sync%22.%20I%20just%20wasn't%20sure%20how%20hard%20it%20would%20be%20to%20interpret%20the%20data%20accurately.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1047325%22%20slang%3D%22en-US%22%3ERe%3A%20AAD%20Connect%20Migration%20and%20Configuration%20Documenter%20Results%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1047325%22%20slang%3D%22en-US%22%3E%3CP%3EHere's%20a%20sample%20article%20that%20walks%20you%20trough%20the%20process%20of%20searching%20the%20metaverse%20or%20given%20connector%20space%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Ftshoot-connect-object-not-syncing%23connector-space-object-properties%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Ftshoot-connect-object-not-syncing%23connector-space-object-properties%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1047644%22%20slang%3D%22en-US%22%3ERe%3A%20AAD%20Connect%20Migration%20and%20Configuration%20Documenter%20Results%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1047644%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20for%20the%20link.%20I%20had%20actually%20come%20across%20that%20link%20and%20was%20testing%20it%20out.%20The%20problem%20was%20that%20we%20had%20not%20performed%20any%20sync%20so%20there%20was%20no%20data%20to%20search%20through%20in%20the%20metaverse.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20managed%20to%20get%20on%20the%20phone%20with%20MS%20support%20and%20we%20went%20through%20our%20configuration.%20After%20reviewing%20the%20Configuration%20Documenter%20results%20we%20were%20essentially%20told%20to%20ignore%20and%20that%20based%20on%20what%20we%20had%20configured%2C%20everything%20should%20go%20through%20smoothly.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20took%20a%20little%20convincing%20but%20we%20eventually%20agreed%20to%20move%20forward%20with%20our%20initial%20sync.%20We%20first%20set%20the%20current%20production%20server%20to%20Staging%20Mode.%20We%20then%20take%20the%20new%20server%20out%20of%20Staging%20Mode%20and%20ran%20our%20initial%20sync.%20Everything%20appeared%20to%20go%20through%20correctly.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20suspect%20that%20perhaps%20the%20Configure%20Documenter%20was%20reporting%20incorrectly%20possibly%20due%20to%20the%20super%20old%20version%20of%20AAD%20Connect%20we%20were%20running%20prior%20to%20the%20upgrade.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20run%20into%20a%20few%20issues%20after%20the%20upgrade%2C%20just%20related%20to%20the%20permissions%20of%20the%20account%20we%20created%20to%20handle%20the%20connection%20to%20AD.%20We%20didn't%20know%20it%20couldn't%20be%20Enterprise%20Admin%20or%20Domain%20Admin%2C%20so%20we%20need%20to%20grant%20the%20necessary%20permission%20to%20this%20user.%20We%20likely%20should%20have%20just%20allowed%20the%20AAD%20Connect%20installation%20wizard%20to%20create%20the%20MSOL_%20user%20account%20and%20be%20done%20with%20it.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnyway%2C%20it%20seems%20things%20are%20okay.%20We%20are%20continuing%20to%20monitor%20though!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECheers%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETodd%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1044950%22%20slang%3D%22en-US%22%3EAAD%20Connect%20Migration%20and%20Configuration%20Documenter%20Results%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1044950%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20currently%20in%20the%20process%20of%20migrating%20from%20a%20very%20old%20version%20of%20AAD%20Connect%20(1.1.614.0)%20to%20the%20latest%20version.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20everything%20installed%20on%20the%20new%20server%20(in%20staging%20mode)%20and%20are%20just%20in%20the%20process%20of%20comparing%20the%20configurations%20between%20the%20two%20servers%20using%20Microsoft's%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2Fmicrosoft%2FAADConnectConfigDocumenter%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20AD%20Connect%20Configuration%20Documenter.%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20the%20report%20under%20the%20section%20for%20our%20on-premise%20domain%20there%20is%20a%20section%20for%20%22Selected%20Attributes%22.%20This%20section%20is%20showing%20a%20bunch%20of%20%22deleted%2Fupdate%22%20status's%20under%20the%20%22Flows%20Configured%22%20column.%3C%2FP%3E%3CP%3EFor%20example%2C%20it%20shows%20that%20%22displayName%22%20used%20to%20be%20set%20for%20%22Import%20%2F%20Export%22%20but%20is%20now%20just%20set%20to%20%22No%22.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20can't%20find%20anything%20in%20either%20server%20that%20might%20explain%20why%20we%20are%20seeing%20these%20results.%20We%20only%20had%20to%20import%20a%20few%20custom%20sync%20rules%20from%20the%20old%20server%20to%20the%20new%20server.%20We%20aren't%20sure%20if%20perhaps%20we%20have%20missed%20something%20there.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBelow%20is%20screenshot%20of%20what%20we%20are%20seeing%20in%20the%20report.%20We%20are%20concerned%20as%20these%20are%20important%20attributes%20that%20definitely%20need%20to%20be%20synced.%20But%20we%20don't%20know%20what%20is%20different%20or%20where%20to%20check%20between%20the%20old%20server%20and%20the%20new%20server.%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-left%22%20image-alt%3D%222019-12-03_14h23_03.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F159858i28DC0A6697FC5273%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%222019-12-03_14h23_03.png%22%20alt%3D%222019-12-03_14h23_03.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20help%20or%20suggestions%20would%20be%20greatly%20appreciated!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECheers%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETodd%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1044950%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%20Connect%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Occasional Contributor

Hi,

 

We are currently in the process of migrating from a very old version of AAD Connect (1.1.614.0) to the latest version.

 

We have everything installed on the new server (in staging mode) and are just in the process of comparing the configurations between the two servers using Microsoft's Azure AD Connect Configuration Documenter.

 

In the report under the section for our on-premise domain there is a section for "Selected Attributes". This section is showing a bunch of "deleted/update" status's under the "Flows Configured" column.

For example, it shows that "displayName" used to be set for "Import / Export" but is now just set to "No".

 

We can't find anything in either server that might explain why we are seeing these results. We only had to import a few custom sync rules from the old server to the new server. We aren't sure if perhaps we have missed something there.

 

Below is screenshot of what we are seeing in the report. We are concerned as these are important attributes that definitely need to be synced. But we don't know what is different or where to check between the old server and the new server.

2019-12-03_14h23_03.png

 

 

 

 

 

 

 

 

Any help or suggestions would be greatly appreciated!

 

Cheers,

 

Todd

4 Replies

Those are standard attributes that should be covered by the default rules. I cannot speak for the documenter, but you can simply run the new instance in staging mode and verify that the attributes in question flow to the metaverse. Similarly, you can run a Preview from the connector space object's 

@Vasil Michev 

 

I appreciate your feedback!

I will look into using the metaverse to accomplish this.

I haven't used the metaverse before so I am not super familiar with it.

 

We did know that we could run a "staging sync". I just wasn't sure how hard it would be to interpret the data accurately.

Here's a sample article that walks you trough the process of searching the metaverse or given connector space: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/tshoot-connect-object-not-syncing#con...

@Vasil Michev

 

Thank you for the link. I had actually come across that link and was testing it out. The problem was that we had not performed any sync so there was no data to search through in the metaverse.

 

We managed to get on the phone with MS support and we went through our configuration. After reviewing the Configuration Documenter results we were essentially told to ignore and that based on what we had configured, everything should go through smoothly.

 

It took a little convincing but we eventually agreed to move forward with our initial sync. We first set the current production server to Staging Mode. We then take the new server out of Staging Mode and ran our initial sync. Everything appeared to go through correctly.

 

We suspect that perhaps the Configure Documenter was reporting incorrectly possibly due to the super old version of AAD Connect we were running prior to the upgrade.

 

We have run into a few issues after the upgrade, just related to the permissions of the account we created to handle the connection to AD. We didn't know it couldn't be Enterprise Admin or Domain Admin, so we need to grant the necessary permission to this user. We likely should have just allowed the AAD Connect installation wizard to create the MSOL_ user account and be done with it.

 

Anyway, it seems things are okay. We are continuing to monitor though!

 

Cheers,

 

Todd