Azure AD Connect Synchronization question

%3CLINGO-SUB%20id%3D%22lingo-sub-1461882%22%20slang%3D%22en-US%22%3EAzure%20AD%20Connect%20Synchronization%20question%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1461882%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20a%20question%20regarding%20to%20Azure%20AD%20Connect%20synchronization%20rules.%20We%20have%20some%20on-premises%20Active%20Directory%20users%20whose%20email%20attribute%20is%20needed%20for%20other%20on-premises%20systems%20and%20these%20users%20also%20need%20to%20sync%20to%20Azure%20AD.%20These%20same%20users%20are%20also%20invited%20as%20guest%20users%20to%20our%20Azure%20AD%20tenant.%20Now%20we%20are%20getting%20syncronization%20errors%20because%20there%20is%20duplicate%20email%20address%20(on-premises%20AD%20user%20and%20external%20guest%20account).%20Is%20it%20possible%20to%20skip%20syncing%20this%20mail%20attribute%20for%20these%20on-premise%20user%20accounts%20or%20what%20to%20do%3F%20Emptying%20mail%20attribute%20from%20on-premises%20account%20is%20not%20an%20option.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1461882%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1461912%22%20slang%3D%22en-US%22%3ERE%3A%20Azure%20AD%20Connect%20Synchronization%20question%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1461912%22%20slang%3D%22en-US%22%3ELaptop%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1462342%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Connect%20Synchronization%20question%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1462342%22%20slang%3D%22en-US%22%3EI%20have%20used%20the%20article%20below%20for%20similar%20scenario%2C%20you%20may%20need%20to%20tweak%20it%20to%20fit%20your%20need.%3CBR%20%2F%3E%3CBR%20%2F%3EYou%20can%E2%80%99t%20Skip%20syncing%20the%20mail%20attribute%20but%20you%20can%20force%20it%20to%20look%20on%20%E2%80%98other%20attributes%E2%80%99%20like%20SAMAccountname%20etc.%3CBR%20%2F%3E%3CBR%20%2F%3EOtherwise%20you%20may%20have%20to%20remove%20the%20duplication.%3CBR%20%2F%3E%3CBR%20%2F%3EHope%20this%20helps%20and%20good%20luck!%3CBR%20%2F%3EMoe%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fwww.google.com%2Famp%2Fs%2Fevotec.xyz%2Fazure-ad-connect-synchronizing-mail-field-with-userprincipalname-in-azure%2Famp%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.google.com%2Famp%2Fs%2Fevotec.xyz%2Fazure-ad-connect-synchronizing-mail-field-with-userprincipalname-in-azure%2Famp%2F%3C%2FA%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hi all,

 

I have a question regarding to Azure AD Connect synchronization rules. We have some on-premises Active Directory users whose email attribute is needed for other on-premises systems and these users also need to sync to Azure AD. These same users are also invited as guest users to our Azure AD tenant. Now we are getting syncronization errors because there is duplicate email address (on-premises AD user and external guest account). Is it possible to skip syncing this mail attribute for these on-premise user accounts or what to do? Emptying mail attribute from on-premises account is not an option. 

1 Reply
I have used the article below for similar scenario, you may need to tweak it to fit your need.

You can’t Skip syncing the mail attribute but you can force it to look on ‘other attributes’ like SAMAccountname etc.

Otherwise you may have to remove the duplication.

Hope this helps and good luck!
Moe

https://www.google.com/amp/s/evotec.xyz/azure-ad-connect-synchronizing-mail-field-with-userprincipal...