SOLVED
Home

What happens to locked out on premise account, when synced to O365?

%3CLINGO-SUB%20id%3D%22lingo-sub-10240%22%20slang%3D%22en-US%22%3EWhat%20happens%20to%20locked%20out%20on%20premise%20account%2C%20when%20synced%20to%20O365%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-10240%22%20slang%3D%22en-US%22%3E%3CP%3ECan%20someone%20please%20point%20me%20to%20the%20articles%2C%20i%20cannot%20find%20them%20online.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20happens%20to%20locked%20out%20on%20premise%20account%2C%20when%20synced%20to%20O365%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20the%20user%20continue%20to%20login%20to%20O365%2C%20send%2Freceive%20email%20etc%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-10240%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIdentity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOn%20Premise%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-11679%22%20slang%3D%22en-US%22%3ERE%3A%20What%20happens%20to%20locked%20out%20on%20premise%20account%2C%20when%20synced%20to%20O365%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-11679%22%20slang%3D%22en-US%22%3EAre%20you%20using%20Password%20sync%20or%20ADFS%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-11663%22%20slang%3D%22en-US%22%3ERe%3A%20What%20happens%20to%20locked%20out%20on%20premise%20account%2C%20when%20synced%20to%20O365%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-11663%22%20slang%3D%22en-US%22%3EHi%20Peter%3CBR%20%2F%3E%3CBR%20%2F%3EWell%20i%20confirm%20that%20it%20works%20as%20expected.%20A%20locked%20on-premise%20account%20had%20no%20impact%20on%20the%20synced%20O365%20account%2C%20as%20the%20relevant%20attribute%20is%20not%20also%20synced.%3CBR%20%2F%3E%3CBR%20%2F%3ERegarding%20the%20rule%20to%20transform%20the%20attribute%20to%20block%20O365%20sign-in%2C%20I%20have%20not%20yet%20tried%20this%2C%20but%20there%20is%20no%20reason%20why%20it%20would%20not%20work.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-11625%22%20slang%3D%22en-US%22%3ERe%3A%20What%20happens%20to%20locked%20out%20on%20premise%20account%2C%20when%20synced%20to%20O365%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-11625%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Andrew%2C%20did%20you%20test%20this%20out%20and%20manage%20to%20get%20it%20working%20successfully%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-10283%22%20slang%3D%22en-US%22%3ERe%3A%20What%20happens%20to%20locked%20out%20on%20premise%20account%2C%20when%20synced%20to%20O365%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-10283%22%20slang%3D%22en-US%22%3EThe%20attribute%20%22lockedouttime%22%20which%20shows%20when%2Fif%20an%20account%20is%20locked%2C%20does%20not%20get%20synced%20to%20o365.%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20we%20WANT%20locked%20on-prem%20users%20to%20not%20be%20allowed%20to%20sign-in%20online%20we%20can%20add%20a%20filter%20rule%20to%20ADConnect%2FADSync.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-10279%22%20slang%3D%22en-US%22%3ERe%3A%20What%20happens%20to%20locked%20out%20on%20premise%20account%2C%20when%20synced%20to%20O365%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-10279%22%20slang%3D%22en-US%22%3E%3CP%3EWhat%20i%20have%20found%20so%20far.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20my%20on%20premise%20directory%2C%20i%20locked%20out%20a%20test%20account%2C%20and%20run%20adsync.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUsing%20the%20test%20account%20i%20can%20still%20authenticate%20to%20office365%20mail%2C%20sharepoint%2C%20onedrive%20etc..%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20this%20expected%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Frequent Contributor

Can someone please point me to the articles, i cannot find them online.

 

What happens to locked out on premise account, when synced to O365?

 

Can the user continue to login to O365, send/receive email etc?

5 Replies

What i have found so far.

 

In my on premise directory, i locked out a test account, and run adsync.

 

Using the test account i can still authenticate to office365 mail, sharepoint, onedrive etc..

 

Is this expected?

Solution
The attribute "lockedouttime" which shows when/if an account is locked, does not get synced to o365.

If we WANT locked on-prem users to not be allowed to sign-in online we can add a filter rule to ADConnect/ADSync.

Hi Andrew, did you test this out and manage to get it working successfully?

Hi Peter

Well i confirm that it works as expected. A locked on-premise account had no impact on the synced O365 account, as the relevant attribute is not also synced.

Regarding the rule to transform the attribute to block O365 sign-in, I have not yet tried this, but there is no reason why it would not work.
Are you using Password sync or ADFS?
Related Conversations
Urgent - Teams and Yealink
reditguy in Microsoft Teams on
4 Replies
Restoring deleted "Files" folder
Daniel Carp in Microsoft Teams on
15 Replies
Quarantine Digest
Jerry Gonzalez in Microsoft 365 on
2 Replies
O365 Multi-Geo & Multi Tenant
Yatin Ramnath Naik in Office 365 on
1 Replies