Home

Change ADconnect to disable Alternate Login ID

%3CLINGO-SUB%20id%3D%22lingo-sub-3377%22%20slang%3D%22en-US%22%3EChange%20ADconnect%20to%20disable%20Alternate%20Login%20ID%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3377%22%20slang%3D%22en-US%22%3E%3CP%3EGood%20morning.%20We%20have%20a%20client%20that%20implemented%20ADConnect%20using%20Alternate%20Login%20ID%20because%20he%20was%20unwilling%20to%20change.%20Now%20after%20he%20recognized%20the%20drawbacks%20he%20changed%20the%20UPN.%20Now%20my%20question%20is%20can%20I%20easily%20change%20ADConnect%20and%20ADFS%20back%20to%20use%20the%20standard%20UPN%20mapping%20or%20do%20I%20have%20to%20completely%20remove%20the%20existing%20connection.%20If%20so%2C%20what%20will%20this%20do%20to%20the%20120%20migrated%20mailboxes%2C%20etc.%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3377%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAuthentication%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-32353%22%20slang%3D%22en-US%22%3ERe%3A%20Change%20ADconnect%20to%20disable%20Alternate%20Login%20ID%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-32353%22%20slang%3D%22en-US%22%3E%3CP%3Esource%20anchor%20will%20not%20change%20and%20will%20still%20be%20the%20objectguid%20-%20I%20condier%20using%20a%20staging%20adconnect%20server%20to%20test%20those%20changes%20and%20then%20switch%20over%20to%20this%20one%20if%20synchronisation%20is%20fine%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-32352%22%20slang%3D%22en-US%22%3ERe%3A%20Change%20ADconnect%20to%20disable%20Alternate%20Login%20ID%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-32352%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Stefan%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20are%20in%20production%20and%20want%20to%20make%20sure%20that%20you%20are%20not%20running%20into%20issues%20then%20I%20suggest%20that%20you%20first%20check%20the%20current%20source%20anchor%20as%20I%20mentioned%20in%20my%20earlier%20post.%20If%20that%20is%20ObjectGUID%20and%20you%20don't%20want%20to%20have%20any%20downtime%20then%20you%20could%20spin%20up%20a%20VM%20either%20on%20Azure%20or%20locally%20and%20install%20AD%20Connect%20on%20it.%20Run%20the%20installer%20(make%20sure%20to%20also%20use%20the%20ObjectgUID%20as%20a%20source%20anchor)%20%26nbsp%3Band%20be%20sure%20not%20to%20run%20a%20sync%20at%20the%20end.%20When%20users%20are%20not%20connected%20(for%20example%20tonight)%20then%20run%20a%20sync%20from%20the%20newly%20installed%20machine.%20Check%20the%20results.%20If%20all%20is%20fine%20then%20you%20can%20either%20choose%20to%20keep%20using%20this%20installation%20or%20rerun%20the%20same%20process%20on%20the%20production%20AD%20Connect%20machine.%20If%20all%20is%20not%20fine%20then%20stop%20the%20newly%20installed%20machine%20and%20run%20a%20full%20sync%20from%20your%20production%20AD%20Connect%20machine%20to%20restore%20the%20current%20setup.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-32351%22%20slang%3D%22en-US%22%3ERe%3A%20Change%20ADconnect%20to%20disable%20Alternate%20Login%20ID%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-32351%22%20slang%3D%22en-US%22%3E%3CP%3EGood%20morning%2C%20thanks%20for%20the%20reply%2C%20I%20have%20just%20received%20same%20information%20from%20MS%2C%20no%20way%20tro%20change%20afterwards%2C%20plainly%20need%20to%20reinstall%20or%20use%20a%20second%20AD%20Connect%20machine%20and%20use%20staging%20to%20change.%20Will%20keep%20u%20posted%20ones%20completed%2C%20will%20need%20to%20evaluate%20first%20as%20we%20are%20in%20production%20already%20%3A(%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-32350%22%20slang%3D%22en-US%22%3ERe%3A%20Change%20ADconnect%20to%20disable%20Alternate%20Login%20ID%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-32350%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Stefan%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAD%20Connect%20uses%20a%20couple%20of%20ways%20to%20mactch%20users%20from%20AD%20with%20AAD%2C%20even%20when%20reinstalling%20the%20product%20it%20tries%20to%20match%20users%20again%20with%20users%20that%20already%20have%20been%20synced%20previously.%20This%20is%20usually%20done%20with%20the%20immutable%20ID%20from%20AD%20which%20is%20by%20default%20the%20ObjectGUID%20as%20SourceAnchor%20from%20AD.%20If%20you%20need%20to%20change%20the%20setup%20then%20I%20would%20recommend%20to%20uninstall%20AD%20Connect%20competely%26nbsp%3Band%20then%20reinstall%20it%20using%20the%20needed%20settings.%26nbsp%3BBe%20sure%20to%20first%20check%20the%20current%20configuration%20first%20and%20verify%20that%26nbsp%3Bthe%20ObjectGUID%26nbsp%3Bis%20indeed%20the%20SourceAnchor.%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20703px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F8884i27C46A58697CCAA0%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%222016-11-29_0804.png%22%20title%3D%222016-11-29_0804.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20that%20is%20the%20case%20then%20you%20can%20proceed%20and%20uninstall%20AD%20Connect%2C%20then%20reinstall%26nbsp%3Bit%20again%20and%20select%20the%20needed%20Login%20ID%20settings.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-32235%22%20slang%3D%22en-US%22%3ERe%3A%20Change%20ADconnect%20to%20disable%20Alternate%20Login%20ID%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-32235%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Mike%2C%3C%2FP%3E%3CP%3Esorry%20to%20bring%20this%20threat%20up%20again.%20I%20am%20not%20only%20talking%20about%20the%20ADFS%20part%20but%20mainly%20the%20Azure%20AD%20Connect%20setting%20which%20can%20only%20be%20specified%20during%20initial%20installation%20as%20it%20seems.%20Any%20idea%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EStefan%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3422%22%20slang%3D%22en-US%22%3ERe%3A%20Change%20ADconnect%20to%20disable%20Alternate%20Login%20ID%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3422%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Stefan%2C%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20I%20understand%20correctly%20then%20the%20required%20settings%20for%20UPN%20are%20set%20as%20well%20(%40contoso.com)%20and%20you%20should%20be%20able%20to%20disable%20the%20alternate%20ID%20by%20running%20the%20following%20command%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESet-AdfsClaimsProviderTrust%20-Target%20Identifier%20%22AD%20AUTHORITY%22%20-AlternateLoginID%20%24NULL%20-LookupForests%20%24NULL%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENo%20additional%20settings%20are%20needed%20for%20ADConnect%20when%20disabling%20the%20Alternate%20ID.%3C%2FP%3E%3CP%3ESee%20also%20%3CA%20href%3D%22https%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fdn659436.aspx%26nbsp%3B%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fdn659436.aspx%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Stefan Baumgarten
Occasional Contributor

Good morning. We have a client that implemented ADConnect using Alternate Login ID because he was unwilling to change. Now after he recognized the drawbacks he changed the UPN. Now my question is can I easily change ADConnect and ADFS back to use the standard UPN mapping or do I have to completely remove the existing connection. If so, what will this do to the 120 migrated mailboxes, etc.?

6 Replies

Hi Stefan,

If I understand correctly then the required settings for UPN are set as well (@contoso.com) and you should be able to disable the alternate ID by running the following command:

 

Set-AdfsClaimsProviderTrust -Target Identifier "AD AUTHORITY" -AlternateLoginID $NULL -LookupForests $NULL

 

No additional settings are needed for ADConnect when disabling the Alternate ID.

See also https://technet.microsoft.com/en-us/library/dn659436.aspx 

Hi Mike,

sorry to bring this threat up again. I am not only talking about the ADFS part but mainly the Azure AD Connect setting which can only be specified during initial installation as it seems. Any idea?

 

Stefan

Hi Stefan,

 

AD Connect uses a couple of ways to mactch users from AD with AAD, even when reinstalling the product it tries to match users again with users that already have been synced previously. This is usually done with the immutable ID from AD which is by default the ObjectGUID as SourceAnchor from AD. If you need to change the setup then I would recommend to uninstall AD Connect competely and then reinstall it using the needed settings. Be sure to first check the current configuration first and verify that the ObjectGUID is indeed the SourceAnchor.

2016-11-29_0804.png

 

If that is the case then you can proceed and uninstall AD Connect, then reinstall it again and select the needed Login ID settings. 

Good morning, thanks for the reply, I have just received same information from MS, no way tro change afterwards, plainly need to reinstall or use a second AD Connect machine and use staging to change. Will keep u posted ones completed, will need to evaluate first as we are in production already :(

Hi Stefan,

 

If you are in production and want to make sure that you are not running into issues then I suggest that you first check the current source anchor as I mentioned in my earlier post. If that is ObjectGUID and you don't want to have any downtime then you could spin up a VM either on Azure or locally and install AD Connect on it. Run the installer (make sure to also use the ObjectgUID as a source anchor)  and be sure not to run a sync at the end. When users are not connected (for example tonight) then run a sync from the newly installed machine. Check the results. If all is fine then you can either choose to keep using this installation or rerun the same process on the production AD Connect machine. If all is not fine then stop the newly installed machine and run a full sync from your production AD Connect machine to restore the current setup.

source anchor will not change and will still be the objectguid - I condier using a staging adconnect server to test those changes and then switch over to this one if synchronisation is fine

Related Conversations
A problem with the Zoom level of a Tab
Tavory in Discussions on
9 Replies
Modern Authentication Issue
cvincent in Microsoft Teams on
1 Replies
Login prompting for more information
Bruce Burge in Office 365 on
5 Replies
PWA fullscreen like IE11 kiosk mode
rogihee in Discussions on
5 Replies
Cannot disable touchpad
sailho in Windows 10 on
2 Replies