SOLVED

A question about AD Connect Password Sync diagnostic tool

%3CLINGO-SUB%20id%3D%22lingo-sub-107213%22%20slang%3D%22en-US%22%3EA%20question%20about%20AD%20Connect%20Password%20Sync%20diagnostic%20tool%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-107213%22%20slang%3D%22en-US%22%3E%3CP%3EHello%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20just%20installed%20AD%20connect%20and%20sucessfully%20synced%20my%20on%20premise%20AD%20(Azure%20IaaS%20AD%20LAB)%20to%20my%20Azure%20AD%20(default%20directory)%20e.g.%20the%20users%20and%20groups%20synced%20up%20OK.%20During%20the%20configuration%20I%20chose%20the%20use%20Password%20Write%20Back%20(as%20I%20am%20using%20an%20eval%20of%20Azure%20AD%20Premium)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%20the%20password%20write%20back%20is%20not%20working%2C%20for%20example%20if%20I%20change%20reset%20the%20password%20of%20one%20of%20the%20synced%20users%20(e.g.%20synced%20from%20AD%20to%20AAD)%20in%20the%20Azure%20Portal%2C%20the%20AD%20password%20is%20not%20changed.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20run%20the%20'troubleshooting'%20tool%20that%20comes%20with%20AD%20Connect%20and%20chose%20to%20trouble%20shoot%20Password%20sync%20for%20a%20particular%20user%20(to%20see%20what%20information%20I%20could%20get)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20running%20this%20tool%20one%20of%20the%20questions%20it%20asks%20is%3C%2FP%3E%3CP%3E%3CSTRONG%3EPlease%20enter%20AD%20connector%20space%20object%20Distinguished%20Name%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20not%20sure%20which%20Object%20the%20question%20is%20refering%20to%2C%20is%20there%20a%20default%20name%20for%20this%20object%20and%20which%20AD%20OU%20will%20this%20object%20live%20in%20by%20default%20so%20I%20can%20try%20and%20locate%20it%20in%20order%20to%20get%20its%20distinguished%20name%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20All%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E__AAnotherUser%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-107213%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-133409%22%20slang%3D%22en-US%22%3ERe%3A%20A%20question%20about%20AD%20Connect%20Password%20Sync%20diagnostic%20tool%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-133409%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20you%20are%20using%20this%20tool%2C%20you%20probably%20have%20a%20user%20that%20you%20suspect%20is%20not%20having%20their%20password%20synced%20to%20AAD%20-%20the%26nbsp%3B%22ad%20connector%20space%20object%20distinguished%20name%22%20that%20the%20tool%20wants%20is%20the%20on-premise%20users%20%22Distinguished%20Name.%22%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFrom%20%22Active%20Directory%20Users%20and%20Groups%22%20select%20the%20properties%20of%20the%20user%20object%20who%20is%20not%20getting%20their%20password%20synced%20to%20AAD.%26nbsp%3B%20Select%20the%20Attribute%20Editor%20Tab%2C%20and%20scroll%20down%20for%20the%20attribute%20called%20distinguishedName%20-%20enter%20the%20value%20that%20corresponds%20to%20this%20attribute%20into%20the%20AD%20Connect%20Password%20Sync%20diagnostic%20tool%20for%20%22ad%20connector%20space%20object%20distinguished%20name.%22%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks%20-%20Walter%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hello

 

I just installed AD connect and sucessfully synced my on premise AD (Azure IaaS AD LAB) to my Azure AD (default directory) e.g. the users and groups synced up OK. During the configuration I chose the use Password Write Back (as I am using an eval of Azure AD Premium)

 

However the password write back is not working, for example if I change reset the password of one of the synced users (e.g. synced from AD to AAD) in the Azure Portal, the AD password is not changed.

 

I run the 'troubleshooting' tool that comes with AD Connect and chose to trouble shoot Password sync for a particular user (to see what information I could get)

 

When running this tool one of the questions it asks is

Please enter AD connector space object Distinguished Name

 

I am not sure which Object the question is refering to, is there a default name for this object and which AD OU will this object live in by default so I can try and locate it in order to get its distinguished name?

 

Thanks All

 

__AAnotherUser

1 Reply
Best Response confirmed by AUser ZUser (Occasional Contributor)
Solution

Hello,

 

If you are using this tool, you probably have a user that you suspect is not having their password synced to AAD - the "ad connector space object distinguished name" that the tool wants is the on-premise users "Distinguished Name."

 

From "Active Directory Users and Groups" select the properties of the user object who is not getting their password synced to AAD.  Select the Attribute Editor Tab, and scroll down for the attribute called distinguishedName - enter the value that corresponds to this attribute into the AD Connect Password Sync diagnostic tool for "ad connector space object distinguished name."

 

Thanks - Walter