Why a different username format?

%3CLINGO-SUB%20id%3D%22lingo-sub-2773954%22%20slang%3D%22en-US%22%3EWhy%20a%20different%20username%20format%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2773954%22%20slang%3D%22en-US%22%3E%3CP%3EWhen%20our%20on%20premises%20AD%20users%20sync%20with%20AzureAD%2C%20almost%20every%20one%20of%20them%20get%20a%20username%20in%20Azure%20in%20the%20format%20of%20their%20email%20address%2C%20which%20would%20be%20%3CON-PREMADACCOUNT%3E%40mycorp.com.%26nbsp%3B%20However%2C%20one%20user%20after%20synchronization%20has%20been%20given%20an%20AzureAD%20account%20with%20a%20modified%20username%20and%20the%20tenant%20domain.%26nbsp%3B%20Instead%20of%20a%20normal%20%3CA%20href%3D%22mailto%3Ajdoe%40mycorp.com%2C%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ejdoe%40mycorp.com%2C%3C%2FA%3E%20it%20is%20%3CA%20href%3D%22mailto%3Ajdoe0365%40mycorptenant.onmicrosoft.com%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ejdoe0365%40mycorptenant.onmicrosoft.com%3C%2FA%3E.%26nbsp%3B%20Clicking%20%22manage%20username%20of%20course%20tells%20me%20that%20it%20is%20synced%20with%20the%20local%20AD%20and%20has%20to%20be%20edited%20there.%26nbsp%3B%20Looking%20through%20the%20attribute%20editor%20for%20this%20user%20in%20AD%2C%20I%20saw%20nothing%20like%20%22jdoe0365%22%2C%20nor%20did%20I%20see%20that%20anywhere%20else%20on%20his%20account%20in%20ADUC.%3C%2FON-PREMADACCOUNT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20user%20account%20was%20different%20in%20one%20respect.%26nbsp%3B%20He%20previously%20had%20an%20account%20created%20directly%20in%20Azure%2C%20and%20its%20username%20was%20%3CA%20href%3D%22mailto%3Ajdoe%40mycorptenant.onmicrosoft.com%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ejdoe%40mycorptenant.onmicrosoft.com%3C%2FA%3E.%26nbsp%3B%20It%20was%20a%20Global%20Administrator.%26nbsp%3B%20I%20deleted%20this%20account%2C%20waited%20more%20than%2015%20minutes%2C%20and%20verified%20it%20was%20no%20longer%20in%20AzureAD%20before%20moving%20the%20on%20premises%20AD%20account%20to%20a%20synchronized%20container.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20there%20any%20way%20to%20get%20this%20AzureAD%20account%20set%20to%20our%20normal%20%3CA%20href%3D%22mailto%3Ajdoe%40mycorp.com%3F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ejdoe%40mycorp.com%3F%3C%2FA%3E%26nbsp%3B%20Or%20is%20this%20user%20stuck%20with%20this%20whenever%20he%20has%20to%20log%20into%20Azure%20or%20O365%20to%20perform%20admin%20functions%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20very%20much%20for%20your%20help%20with%20this.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2773954%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
New Contributor

When our on premises AD users sync with AzureAD, almost every one of them get a username in Azure in the format of their email address, which would be <on-premADaccount>@mycorp.com.  However, one user after synchronization has been given an AzureAD account with a modified username and the tenant domain.  Instead of a normal jdoe@mycorp.com, it is jdoe0365@mycorptenant.onmicrosoft.com.  Clicking "manage username of course tells me that it is synced with the local AD and has to be edited there.  Looking through the attribute editor for this user in AD, I saw nothing like "jdoe0365", nor did I see that anywhere else on his account in ADUC.

 

This user account was different in one respect.  He previously had an account created directly in Azure, and its username was jdoe@mycorptenant.onmicrosoft.com.  It was a Global Administrator.  I deleted this account, waited more than 15 minutes, and verified it was no longer in AzureAD before moving the on premises AD account to a synchronized container.

 

Is there any way to get this AzureAD account set to our normal jdoe@mycorp.com?  Or is this user stuck with this whenever he has to log into Azure or O365 to perform admin functions?

 

Thank you very much for your help with this.

 

 

3 Replies
The user name format you see (usernameXXXX where XXXX is a 4 digit number) is usually due to a sync conflict with an existing account - which based on your feedback seems to have happened. I would suggest deleting the existing cloud only account and force it to be removed from the ‘recycle bin’. You can change the existing UPN using PowerShell, or alternatively force the account to be recreated in Azure AD.

For future reference you can check sync conflicts (with instructions to correct them) from the Azure AD Connect Health -> Sync Errors blade in de Azure AD portal.

Thanks very much for your reply.

 

You're exactly right about the conflict.  I had overlooked a contact we had created for this user so that users whose mailboxes were migrated to the cloud would be able to send mail to this person's regular Exchange (on prem) mailbox.  (Since he had a account created directly in Azure, we left him in an unsynchronized OU, which meant that his name in the O365 GAL pointed to the mailbox associated with the Azure account's mailbox in Exchange Online.)

 

I'll have to delete that contact.  Would the most straightforward thing be to move him back to an unsyncronized OU in AD and let that new account be removed from AzureAD, then move the AD account back to a synchronized OU so that it would be recreated?  Or would it be better to modify the existing Azure account?  If the latter, what would I change in AD in order to change the account name in Azure since I can't make that change directly in Azure?

 

Thank you again for your help.

That would be one way. Alternatively you can delete the user from Azure AD. It will then first be soft deleted and you will need to do a hard sleet after that to remove the user completely from Azure AD. Then trigger the on prem account to be synced again.