Azure AD sync to on premise AD

%3CLINGO-SUB%20id%3D%22lingo-sub-1472915%22%20slang%3D%22en-US%22%3EAzure%20AD%20sync%20to%20on%20premise%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1472915%22%20slang%3D%22en-US%22%3E%3CP%3EHi%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMy%20company%20has%20Azure%20AD%20with%20users%20using%20Office%20365%20accounts%20sine%20quite%20some%20time.%20now%20we%20deployed%20on%20premises%20Windows%20Server%20Active%20Directory.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMy%20requirement%20is%20to%20sync%20Azure%20AD%20back%20to%20on%20prmises%20Windows%20AD%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20someone%20please%20help%20if%20it%20is%20possible.%20if%20so%2C%20then%20how%20to%20do%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1472915%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1473137%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20sync%20to%20on%20premise%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1473137%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F36190%22%20target%3D%22_blank%22%3E%40Muhammad%20Qasim%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%2C%20so%20the%20process%20of%20Azure%20AD%20connect%20works%20only%20from%20on-premises%20to%20cloud.%26nbsp%3B%20Whilst%20it%20is%20capable%20of%20things%20like%20password%20write%20back%20and%20device%20writeback%2C%20you%20cannot%20create%20users%20in%20Azure%20AD%20and%20sync%20them%20back%20to%20on-premises%20AD.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20you%20will%20need%20to%20do%20is%20as%20follows%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1).%20Ideally%20install%20an%20Exchange%20on-premises%20management%20server%20to%20manage%20attributes%20as%20the%20source%20of%20authority%20is%20going%20to%20be%20on-premises%20AD.%26nbsp%3B%20You%20can%20get%20a%20free%20Exchange%202016%20hybrid%20licence%20key%20if%20you%20have%20Office%20365%20Enterprise%20licences%20for%20your%20users.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E2).%20Setup%20your%20on-premises%20AD%20objects%20with%20the%20same%20UPN%20and%20SMTP%20addresses%20that%20are%20set%20in%20Azure%20AD%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E3).%26nbsp%3B%20Setup%20Azure%20AD%20connect%20to%20use%20SMTP%20matching%20and%20synchronise%20your%20AD%20to%20Azure%20AD.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20can%20find%20further%20information%20on%20the%20process%20below%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-ERR%3AREF-NOT-FOUND-%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-gb%2Fhelp%2F2641663%2Fuse-smtp-matching-to-match-on-premises-user-accounts-to-office-365%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-gb%2Fhelp%2F2641663%2Fuse-smtp-matching-to-match-on-premises-user-accounts-to-office-365%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fgallery.technet.microsoft.com%2Foffice%2FImmutableid-Hard-Match-in-d3518b08%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgallery.technet.microsoft.com%2Foffice%2FImmutableid-Hard-Match-in-d3518b08%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-gb%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-install-existing-tenant%23hard-match-vs-soft-match%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-gb%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-install-existing-tenant%23hard-match-vs-soft-match%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHope%20this%20helps%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Hi

 

My company has Azure AD with users using Office 365 accounts sine quite some time. now we deployed on premises Windows Server Active Directory. 

 

My requirement is to sync Azure AD back to on prmises Windows AD?

 

Can someone please help if it is possible. if so, then how to do,

 

Regards

1 Reply
Highlighted

@Muhammad Qasim 

 

Hi, so the process of Azure AD connect works only from on-premises to cloud.  Whilst it is capable of things like password write back and device writeback, you cannot create users in Azure AD and sync them back to on-premises AD.

 

What you will need to do is as follows;

 

1). Ideally install an Exchange on-premises management server to manage attributes as the source of authority is going to be on-premises AD.  You can get a free Exchange 2016 hybrid licence key if you have Office 365 Enterprise licences for your users.

 

2). Setup your on-premises AD objects with the same UPN and SMTP addresses that are set in Azure AD

 

3).  Setup Azure AD connect to use SMTP matching and synchronise your AD to Azure AD.

 

You can find further information on the process below;

 

https://support.microsoft.com/en-gb/help/2641663/use-smtp-matching-to-match-on-premises-user-account...

 

https://gallery.technet.microsoft.com/office/Immutableid-Hard-Match-in-d3518b08

 

https://docs.microsoft.com/en-gb/azure/active-directory/hybrid/how-to-connect-install-existing-tenan...

 

Hope this helps