AD sync question

%3CLINGO-SUB%20id%3D%22lingo-sub-2135611%22%20slang%3D%22en-US%22%3EAD%20sync%20question%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2135611%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20have%20a%20customer%20that%20has%20activated%20a%20tenant%20with%20office%20365%20business%20licenses.%3C%2FP%3E%3CP%3EThe%20tenant%20is%20not%20yet%20connected%20to%20AD%20.%3C%2FP%3E%3CP%3EOn%20the%20tenant%20several%20users%20are%20already%20been%20created%20and%20assigned%20an%20office%26nbsp%3B%20license%3C%2FP%3E%3CP%3EThe%20users%20login%20are%20in%20the%20form%20%3CA%20href%3D%22mailto%3Az.user%40company.onmicrosoft.com%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ez.user%40company.onmicrosoft.com%3C%2FA%3E%20and%20used%20when%20the%20office%20application%20have%20been%20installed%20locally%20on%20the%20PC%20.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENow%20we're%20going%20to%20set%20up%26nbsp%3B%20the%20AD%20Sync%20and%20wondered%20about%20the%20%22duplication%22%20of%20the%20users%20.%3C%2FP%3E%3CP%3EThe%20AD%20users%20will%20be%20replicated%20with%20their%20UPN%20%3CA%20href%3D%22mailto%3Ar.user%40company.com%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Er.user%40company.com%3C%2FA%3E%20but%20also%20with%20their%20tenant%20email%20address%20which%20will%20be%20the%20same%20as%20the%20one%20already%20present%20.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20what%20happen%20then%20to%20the%20users%20already%20registered%20in%20the%20tenant%20%3F%3C%2FP%3E%3CP%3EWill%20they%20be%20impacted%20%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethanks%3C%2FP%3E%3CP%3EStefano%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2135611%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAdoption%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Ehybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2136822%22%20slang%3D%22en-US%22%3ERe%3A%20AD%20sync%20question%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2136822%22%20slang%3D%22en-US%22%3E%3CP%3EYou%20can%20use%20the%20%22soft%20match%22%20process%20to%20%22link%22%20the%20AD%20user%20with%20an%20existing%20Azure%20AD%20one%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Ftopic%2Fhow-to-use-smtp-matching-to-match-on-premises-user-accounts-to-office-365-user-accounts-for-directory-synchronization-75673b94-e1b8-8a9e-c413-ee5a2a1a6a78%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Ftopic%2Fhow-to-use-smtp-matching-to-match-on-premises-user-accounts-to-office-365-user-accounts-for-directory-synchronization-75673b94-e1b8-8a9e-c413-ee5a2a1a6a78%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

We have a customer that has activated a tenant with office 365 business licenses.

The tenant is not yet connected to AD .

On the tenant several users are already been created and assigned an office  license

The users login are in the form z.user@company.onmicrosoft.com and used when the office application have been installed locally on the PC .

 

Now we're going to set up  the AD Sync and wondered about the "duplication" of the users .

The AD users will be replicated with their UPN r.user@company.com but also with their tenant email address which will be the same as the one already present .

 

So what happen then to the users already registered in the tenant ?

Will they be impacted ?

 

thanks

Stefano

 

3 Replies

You can use the "soft match" process to "link" the AD user with an existing Azure AD one: https://support.microsoft.com/en-us/topic/how-to-use-smtp-matching-to-match-on-premises-user-account...

@Vasil MichevReading the article I see that it works using the smtp address as soft match, it it requires that the users have an active mailbox on exchange online.

Unfortunately the customer has only on-prem exchange

thanks

 

It works on "mail" attribute as well, and if that is not an option, you can use UPN matching: https://docs.microsoft.com/en-us/troubleshoot/azure/active-directory/use-upn-matching-identity-sync

Or use the hard-match method: https://docs.microsoft.com/en-us/archive/blogs/praveenkumar/how-to-do-hard-match-in-dirsync