SOLVED

New User accounts replication issue between AD and AAD

%3CLINGO-SUB%20id%3D%22lingo-sub-1581182%22%20slang%3D%22en-US%22%3ENew%20User%20accounts%20replication%20issue%20between%20AD%20and%20AAD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1581182%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20provision%20all%20our%20new%20user%20accounts%20in%20on-premise%20AD.%20we%20have%20AAD%20connect%20configured%20with%20password%20hash%20synchronization.%20Our%20devices%20are%20Azure%20AD%20Joined%20only.%3C%2FP%3E%3CP%3EWhen%20we%20create%20a%20new%20user%20account%20with%20the%20following%20option%20ticked%3A%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22AAD1.png%22%20style%3D%22width%3A%20368px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F211759i28361DC8BD44DD5B%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22AAD1.png%22%20alt%3D%22AAD1.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3Eand%20when%20that%20user%20logs%20in%20to%20the%20device%20which%20is%20Azure%20AD%20joined%20only%2C%20he%20gets%20an%20error%20message%20(password%20incorrect).%20However%2C%20if%20we%20don't%20tick%20that%20option%2C%20the%20user%20can%20login%20fine.%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20addition%2C%20i%20should%20say%20that%20password%20changes%20done%20on-premise%20are%20replicating%20to%20Azure%20AD%20and%20vice%20versa%20without%20any%20issues.%3C%2FP%3E%3CP%3ESo%2C%20my%20question%20is%20to%20those%20who%20manage%20user%20identities%20on-premise%20and%20sync%20them%20to%20AAD%2C%20how%20are%20they%20dealing%20with%20this%20situation%20when%20they%20provision%20new%20user%20accounts%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance%20everyone.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1581182%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIdentity%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1581712%22%20slang%3D%22en-US%22%3ERe%3A%20New%20User%20accounts%20replication%20issue%20between%20AD%20and%20AAD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1581712%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F318231%22%20target%3D%22_blank%22%3E%40ShehzadUIT%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%2C%20check%20out%20this%20for%20further%20information%20-%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-password-hash-synchronization%23synchronizing-temporary-passwords-and-force-password-change-on-next-logon%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-password-hash-synchronization%23synchronizing-temporary-passwords-and-force-password-change-on-next-logon%3C%2FA%3E%26nbsp%3B-%20you%20can%20use%20PowerShell%20to%20set%20this%20functionality.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%2C%20please%20note%20the%20caution%20in%20the%20article%20as%20shown%20below%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Screenshot%202020-08-11%20at%2016.16.09.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F211791i7C0F3CA28E6042B7%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22Screenshot%202020-08-11%20at%2016.16.09.png%22%20alt%3D%22Screenshot%202020-08-11%20at%2016.16.09.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1583464%22%20slang%3D%22en-US%22%3ERe%3A%20New%20User%20accounts%20replication%20issue%20between%20AD%20and%20AAD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1583464%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3BThank%20you%20for%20guiding%20me%20to%20the%20right%20link.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAll%20i%20want%20to%20add%20for%20future%20viewers%20is%20that%20once%20you%20enable%20this%2C%20the%20password%20reset%20option%20doesn't%20appear%20on%20the%20device%20logon%20but%20appears%20when%20you%20try%20accessing%20SharePoint%20Online%20or%20OutLook%20(exchange%20online)%3A%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22AAD3.png%22%20style%3D%22width%3A%20365px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F211970iD2DF140EC8102C28%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22AAD3.png%22%20alt%3D%22AAD3.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Hi, 

We provision all our new user accounts in on-premise AD. we have AAD connect configured with password hash synchronization. Our devices are Azure AD Joined only.

When we create a new user account with the following option ticked: 

 

AAD1.png

and when that user logs in to the device which is Azure AD joined only, he gets an error message (password incorrect). However, if we don't tick that option, the user can login fine. 

In addition, i should say that password changes done on-premise are replicating to Azure AD and vice versa without any issues.

So, my question is to those who manage user identities on-premise and sync them to AAD, how are they dealing with this situation when they provision new user accounts? 

 

Thanks in advance everyone.

2 Replies
best response confirmed by ShehzadUIT (Contributor)
Solution

@ShehzadUIT 

 

Hi, check out this for further information - https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-password-hash-synchron... - you can use PowerShell to set this functionality.

 

However, please note the caution in the article as shown below;

 

Screenshot 2020-08-11 at 16.16.09.png

@PeterRising Thank you for guiding me to the right link.

 

All i want to add for future viewers is that once you enable this, the password reset option doesn't appear on the device logon but appears when you try accessing SharePoint Online or OutLook (exchange online):

AAD3.png