Hard Match when Source Anchor Attribute = sAMAccountName got changed in AD

%3CLINGO-SUB%20id%3D%22lingo-sub-1252360%22%20slang%3D%22en-US%22%3ERe%3A%20Hard%20Match%20when%20Source%20Anchor%20Attribute%20%3D%20sAMAccountName%20got%20changed%20in%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1252360%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F403577%22%20target%3D%22_blank%22%3E%40rahul2275%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1.%20Check%20PrincipleName%2C%20Mail%2C%20ProxyAddress%20and%20sAMAccount%20in%20attribute%20editor%20(AD)%20for%20that%20user.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E2.%20Run%20the%20CMDLET%20below%20DC%20PowerShell%2F%20Change%20the%20path%3C%2FP%3E%3CP%3Eldifde%20-f%20C%3A%5CUsers%5Cusername%5CDesktop%5Cexport.txt%20-r%20%22(Userprincipalname%3D*)%22%20-l%20%22objectGuid%2C%20userPrincipalName%2CsAMAcocountName%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E3.%20Get%20the%20Object%20Guid%20for%20the%20target%20user%20from%20exported%20file.%3C%2FP%3E%3CP%3ERun%20the%20PS%20in%20ADConnect%20server%20as%20Admin%3C%2FP%3E%3CP%3EConnect-MSOLService%3C%2FP%3E%3CP%3ERun%20the%20CMDLET%20below%3A%3C%2FP%3E%3CP%3ESet-MsolUser%20-UserPrincipalName%20username%20-ImmutableId%20ObjectGUID_VALUE_From_Step2%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E4.%20Force%20Initial%3C%2FP%3E%3CP%3ESync.%3CSPAN%3EStart-ADSyncSyncCycle%20-PolicyType%20Initial%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHope%20this%20helps!%3C%2FP%3E%3CP%3EMoe%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1500556%22%20slang%3D%22en-US%22%3ERe%3A%20Hard%20Match%20when%20Source%20Anchor%20Attribute%20%3D%20sAMAccountName%20got%20changed%20in%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1500556%22%20slang%3D%22en-US%22%3ESource%20Anchor%20attribute%20is%20samaccountname%20not%20ObjectGUID...%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1251108%22%20slang%3D%22en-US%22%3EHard%20Match%20when%20Source%20Anchor%20Attribute%20%3D%20sAMAccountName%20got%20changed%20in%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1251108%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOne%20of%20my%20client%20has%20configured%20sAMAccountName%20as%20a%20source%20anchor%20attribute%20in%20Azure%20AD%20Connect.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUnfortunately%20an%20user%20was%20created%20with%20wrong%20sAMAccountName%20and%20now%20we%20have%20changed%20the%20sAMAccountName%20which%20causes%20the%20user%20not%20getting%20synced%20with%20AD.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20order%20to%20perform%20the%20hard%20match%20could%20you%20please%20let%20me%20know%20what%20steps%20I%20have%20to%20follow%20where%20source%20anchor%20attribute%20is%20set%20to%20sAMAccountName.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%2C%3C%2FP%3E%3CP%3ERahul.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1251108%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
Occasional Contributor

Hello,

 

One of my client has configured sAMAccountName as a source anchor attribute in Azure AD Connect.

 

Unfortunately an user was created with wrong sAMAccountName and now we have changed the sAMAccountName which causes the user not getting synced with AD.

 

In order to perform the hard match could you please let me know what steps I have to follow where source anchor attribute is set to sAMAccountName.

 

Thank you,

Rahul.

2 Replies
Highlighted

Hi @rahul2275,

 

1. Check PrincipleName, Mail, ProxyAddress and sAMAccount in attribute editor (AD) for that user.

 

2. Run the CMDLET below DC PowerShell/ Change the path

ldifde -f C:\Users\username\Desktop\export.txt -r "(Userprincipalname=*)" -l "objectGuid, userPrincipalName,sAMAcocountName"

 

3. Get the Object Guid for the target user from exported file.

Run the PS in ADConnect server as Admin

Connect-MSOLService

Run the CMDLET below:

Set-MsolUser -UserPrincipalName username -ImmutableId ObjectGUID_VALUE_From_Step2

 

4. Force Initial

Sync.Start-ADSyncSyncCycle -PolicyType Initial

 

Hope this helps!

Moe

 

 

Highlighted
Source Anchor attribute is samaccountname not ObjectGUID...