Azure AD Connect - procedure to change source of anchor from ObjectSID to Ms-DS-ConsistencyGUID

%3CLINGO-SUB%20id%3D%22lingo-sub-1782331%22%20slang%3D%22fr-FR%22%3EAzure%20AD%20Connect%20-%20procedure%20to%20change%20source%20of%20anchor%20from%20ObjectSID%20to%20Ms-DS-ConsistencyGUID%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1782331%22%20slang%3D%22fr-FR%22%3E%3CP%3EHello%3C%2FP%3E%3CP%3EWe%20are%20an%20organization%20of%20%2B%201000%20users%20with%20ADs%20(domain%20and%20subdomains)%20linked%20to%20Azure%20AD%20via%20Azure%20Ad%20Connect.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECurrently%20the%20anchor%20source%20is%20Object%3CEM%3ESID%3C%2FEM%3E%2C%20UPN%20-%20mail%20and%20Hybrid%20Exchange.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20would%20like%20to%20change%20it%20to%20MS-DS-ConsistencyGUID%20in%20order%20to%20be%20able%20to%20move%20objects%20easily%20between%20ADs%20without%20impacting%20the%20Azure%20AD%20accounts.%20(Or%20find%20a%20tested%20procedure)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20found%20documentation%20about%20changing%20the%20anchor%20source%20for%20ObjectGUID%20attributes%20to%20MS-DS-ConsistencyGUID%20but%20not%20much%20for%20attributes%20other%20than%20ObjectGUID.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20read%20and%20tested%20several%20ideas%20but%20nothing%20is%20100%25%20risk%20free.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFor%20you%2C%20what%20is%20the%20best%20procedure%20to%20change%20this%20anchor%20source%20without%20loss%20of%20connection%2Fidentification%20for%20the%20end%20user%20(on%20Office%20365%20for%20example)%3F%20%3CBR%20%2F%3E%3CEM%3EBTW%20-%20Soft%20Delete%20is%20not%20an%20option%20unless%20we%20have%20no%20choice%3C%2FEM%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1956856%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Connect%20-%20procedure%20to%20change%20source%20of%20anchor%20from%20ObjectSID%20to%20Ms-DS-ConsistencyGUID%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1956856%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F613227%22%20target%3D%22_blank%22%3E%40GaetWalou%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20sourceAnchor%20attribute%20value%20cannot%20be%20changed%20after%20the%20object%20has%20been%20created%20in%20Azure%20AD%20and%20the%20identity%20is%20synchronized.%3C%2FP%3E%3CP%3EThe%20sourceAnchor%20attribute%20can%20only%20be%20set%20during%20initial%20installation.%20If%20you%20rerun%20the%20installation%20wizard%2C%20this%20option%20is%20read-only.%20If%20you%20need%20to%20change%20this%20setting%2C%20then%20you%20must%20uninstall%20and%20reinstall.%20If%20the%20value%20for%20sourceAnchor%20is%20changed%20after%20the%20object%20has%20been%20exported%20to%20Azure%20AD%2C%20then%20Azure%20AD%20Connect%20sync%20throws%20an%20error%20and%20does%20not%20allow%20any%20more%20changes%20on%20that%20object%20before%20the%20issue%20has%20been%20fixed%20and%20the%20sourceAnchor%20is%20changed%20back%20in%20the%20source%20directory.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPlease%20refer%20to%20%3CA%20title%3D%22sourceAnchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fplan-connect-design-concepts%23changing-the-sourceanchor-attribute%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EMSDocument%3C%2FA%3E%20for%20details.%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hello,

We are an organization of + 1000 users with ADs (domain and subdomains) linked to Azure AD via Azure Ad Connect.

 

Currently the anchor source is ObjectSID, UPN = mail and Hybrid Exchange.

 

We would like to change it to MS-DS-ConsistencyGUID in order to be able to move objects easily between ADs without impacting the Azure AD accounts. (Or find a tested procedure)

 

We have found documentation about changing the anchor source for ObjectGUID attributes to MS-DS-ConsistencyGUID but not much for attributes other than ObjectGUID.

 

I have read and tested several ideas but nothing is 100% risk free.

 

For you, what is the best procedure to change this anchor source without loss of connection/identification for the end user (on Office 365 for example)?
BTW = Soft Delete is not an option unless we have no choice

1 Reply

@GaetWalou 

The sourceAnchor attribute value cannot be changed after the object has been created in Azure AD and the identity is synchronized.

The sourceAnchor attribute can only be set during initial installation. If you rerun the installation wizard, this option is read-only. If you need to change this setting, then you must uninstall and reinstall. If the value for sourceAnchor is changed after the object has been exported to Azure AD, then Azure AD Connect sync throws an error and does not allow any more changes on that object before the issue has been fixed and the sourceAnchor is changed back in the source directory.

 

Please refer to MSDocument for details.