Apr 26 2021 06:14 AM
Hello,
I have some questions regarding Microsoft Edge sync, and specifically the precedence of AD Sync vs Azure AD Sync, given some issues that we are currently experiencing.
Our environment:
Windows 7 workstations (I know!) with ESU Year 2
Windows 10 laptops - version 1909 enterprise X64
Citrix RDS multi-user servers, running on Windows Server 2016 (LTSB)
Most of our users have a Microsoft Office 365 licence, but not all (for various reasons...). I have configured group policies to enable on-premises sync, but even for my own user account, I am seeing the 'sign-in' account for MS Edge being either:
email.address@ourdomain.com (UPN)
or
<NT Domain name>\samAccountName
This means that the profile sync is different; "cloud" or %AppData%\Microsoft\Edge\User Data\profile.pb
It is strange that on different devices, my own account is configured differently on login.
How is the sync priority for the profile for a user determined?
What settings control this?
Is there any way - via script or policy - to switch profiles for users?
Thanks,
Jonathan
Apr 26 2021 04:44 PM
@jdseymour1978 Hi Jonathan! Have you tried the RestrictSigninToPattern policy (https://docs.microsoft.com/en-us/deployedge/microsoft-edge-policies#restrictsignintopattern)?
We've had some other conversations with customers and in addition to the ConfigureOnPremisesAccountAutoSignIn and RoamingProfileSupportEnabled policies, they configured the RestrictSigninToPattern policy so it can be used to force on-premise sign in.
Thanks!
-Kelly
Apr 27 2021 12:43 PM
Apr 27 2021 03:02 PM
@jdseymour1978 Sorry to hear about the issues!
Couple of tips for the RestrictSigninToPattern policy that I've seen others mention:
The required pattern is here "DOMAIN\\.*" (without quotation marks and here DOMAIN is to be replaced with your specific AD domain). Also, reminder that the regex pattern is case sensitive.
Also, if you are still having issues you can reach out to Support and they can work with you directly to troubleshoot your specific case. https://microsoftedgesupport.microsoft.com/hc/en-us
Thanks!
-Kelly