SOLVED

Create new user accounts in M365 and merge the user accounts later from On premises AD.

%3CLINGO-SUB%20id%3D%22lingo-sub-2127676%22%20slang%3D%22en-US%22%3ECreate%20new%20user%20accounts%20in%20M365%20and%20merge%20the%20user%20accounts%20later%20from%20On%20premises%20AD.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2127676%22%20slang%3D%22en-US%22%3E%3CP%20class%3D%22x_MsoNormal%22%3ECustomer%20has%20an%20AD%20domain%20(%20CORP%20)%20%26nbsp%3Band%20they%20are%20separating%20from%20the%20company%20with%20new%20domain%20(%20ABC%20)%3C%2FP%3E%3CP%20class%3D%22x_MsoNormal%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22x_MsoNormal%22%3ECurrently%20they%20have%20M365%2C%20SharePoint%20and%20Teams%20access%2C%20As%20they%20are%20separating%20from%20the%20CORP%20domain%20they%20want%20to%20have%20a%20separate%20tenant%20with%20M365%2CSharepoint%20and%20teams%20and%20still%20they%20will%20be%20login%20to%20CORP%20for%20internal%20resources%20access%3C%2FP%3E%3CP%20class%3D%22x_MsoNormal%22%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EWe%20will%20create%20a%20new%20tenant%20and%20enable%20the%20access%20of%20M365%2C%20SharePoint%20and%20Teams%20access%20to%20the%20ABC%20domain%20users%3C%2FLI%3E%3CUL%3E%3CLI%3ECOPR%20domain%20will%20not%20allow%20AD%20connect%20tool%20to%20sync%20ABC%20users%20to%20new%20tenant%3C%2FLI%3E%3CLI%3EManually%20we%20will%20create%20the%20users%20in%20the%20tenant%20and%20allow%20them%20to%20use%20M365%2CSharepoint%20and%20teams%3C%2FLI%3E%3CLI%3EUser%20mailboxes%20are%20linked%20mailboxes%3C%2FLI%3E%3CLI%3EABC%20users%20are%20ok%20to%20use%20two%20credentials%20for%20accessing%20the%20resources%20internally%20and%20externally%3C%2FLI%3E%3C%2FUL%3E%3C%2FUL%3E%3CP%20class%3D%22x_MsoNormal%22%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EOnce%20the%20ABC%20users%20are%20disconnected%20from%20CORP%20can%20we%20move%20and%20merge%20these%20users%20to%20the%20ABC%20tenant%20in%20the%20cloud%20(%20M365)%3C%2FLI%3E%3CLI%3EIf%20we%20are%20syncing%20the%20users%20from%20ABC%20via%20AD%20connect%20tool%20to%20the%20ABC%20tenant%20(%20Will%20the%20same%20user%20objects%20merge%20in%20the%20Tenant%20)%3C%2FLI%3E%3CLI%3EIn%20case%20we%20have%20to%20delete%20the%20users%20in%20the%20M365%20tenant%20what%20happens%20to%20the%20user%20data%20of%20M365%2CSharepoint%20and%20teams%3C%2FLI%3E%3CLI%3ECan%20we%20merge%20the%20same%20ABC%20users%20which%20were%20manually%20created%20in%20the%20cloud%20with%20On%20prem%20AD%20with%20AD%20connect%20tool.%3C%2FLI%3E%3CLI%3ECan%20we%20remap%20the%20users%20data%20if%20we%20delete%20them%20in%20the%20cloud%20and%20sync%20them%20again%20with%20AD%20connect%3C%2FLI%3E%3C%2FUL%3E%3CP%20class%3D%22x_MsoListParagraph%22%3EI%20will%20come%20to%20the%20right%20point.%3C%2FP%3E%3CP%20class%3D%22x_MsoListParagraph%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22x_MsoListParagraph%22%3ECan%20we%20create%20a%20user%20in%20M365%20and%20later%20merge%20the%20same%20user%20from%20on%20premises%20AD%20with%20AD%20connect%20tool%3C%2FP%3E%3CP%20class%3D%22x_MsoListParagraph%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22x_MsoListParagraph%22%3Eif%20above%20option%20is%20not%20possible%20then%20we%20want%20to%20delete%20the%20user%20created%20in%20M365%20and%20sync%20the%20on%20premises%20users%20and%20connect%20them%20back%20to%20the%20same%20applications%20or%20data%20which%20the%20users%20were%20using%20wit%20cloud%20login.%3C%2FP%3E%3CP%20class%3D%22x_MsoListParagraph%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22x_MsoListParagraph%22%3ELet%20me%20folks%20if%20the%20above%20options%20are%20possible.%3C%2FP%3E%3CP%20class%3D%22x_MsoListParagraph%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22x_MsoListParagraph%22%3ERegards%2C%3C%2FP%3E%3CP%20class%3D%22x_MsoListParagraph%22%3EArif%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2127676%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMigration%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOn-Premises%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2127726%22%20slang%3D%22en-US%22%3ERe%3A%20Create%20new%20user%20accounts%20in%20M365%20and%20merge%20the%20user%20accounts%20later%20from%20On%20premises%20AD.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2127726%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F262399%22%20target%3D%22_blank%22%3E%40arifsohail92%3C%2FA%3E%26nbsp%3BIf%20you%20create%20a%20cloud-only%20account%20in%20365%2FAzure%20AD%2C%20and%20later%20connect%20AADConnect%20sync%20to%20it%2C%20it%20will%20merge%20accounts%20that%20it%20thinks%20are%20the%20same.%20Off%20the%20top%20of%20my%20head%20this%20is%20done%20off%20userPrincipalName%20or%20proxyAddresses%20matching.%20Probably%20something%20to%20test%20first%20but%20if%20your%20userPrincipalName%20on-premise%20is%20the%20same%20as%20the%20account%20logon%20name%20in%20365%2C%20or%20the%20proxyAddresses%20contains%20a%20match%20for%20the%20email%20address%20of%20the%20cloud%20account%20(as%20the%20default%20address%2C%20i.e.%20SMTP%3A%20in%20upper%20case)%2C%20it'll%20merge%20them.%20This%20is%20called%20%22soft%20match%22%20-%20there's%20a%20%22hard%20match%22%20which%20uses%20the%20sourceAnchor%2FimmutableID%20but%20in%20your%20case%20I%20would%20expect%20soft%20match%20to%20work.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20explains%20it%20a%20bit%20better%20than%20I%20can%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fraaaimund.github.io%2Ftech%2F2019%2F06%2F13%2Fmerge-on-premise-existing-azure-ad-user%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fraaaimund.github.io%2Ftech%2F2019%2F06%2F13%2Fmerge-on-premise-existing-azure-ad-user%2F%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2128145%22%20slang%3D%22en-US%22%3ERe%3A%20Create%20new%20user%20accounts%20in%20M365%20and%20merge%20the%20user%20accounts%20later%20from%20On%20premises%20AD.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2128145%22%20slang%3D%22en-US%22%3E%3CP%3EHIi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F942392%22%20target%3D%22_blank%22%3E%40CoasterKaty%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20your%20reply%20!!%3C%2FP%3E%3CP%3EI%20have%20also%20reviewed%20the%20below%20links.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Ftopic%2Fhow-to-use-smtp-matching-to-match-on-premises-user-accounts-to-office-365-user-accounts-for-directory-synchronization-75673b94-e1b8-8a9e-c413-ee5a2a1a6a78%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Ftopic%2Fhow-to-use-smtp-matching-to-match-on-premises-user-accounts-to-office-365-user-accounts-for-directory-synchronization-75673b94-e1b8-8a9e-c413-ee5a2a1a6a78%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fchinnychukwudozie.com%2F2015%2F04%2F10%2Fmatching-an-office-365-azure-cloud-user-identity-with-an-on-premise-active-directory-user-object%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fchinnychukwudozie.com%2F2015%2F04%2F10%2Fmatching-an-office-365-azure-cloud-user-identity-with-an-on-premise-active-directory-user-object%2F%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Ftopic%2Fhow-to-use-smtp-matching-to-match-on-premises-user-accounts-to-office-365-user-accounts-for-directory-synchronization-75673b94-e1b8-8a9e-c413-ee5a2a1a6a78%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Ftopic%2Fhow-to-use-smtp-matching-to-match-on-premises-user-accounts-to-office-365-user-accounts-for-directory-synchronization-75673b94-e1b8-8a9e-c413-ee5a2a1a6a78%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-US%2Ftroubleshoot%2Fazure%2Factive-directory%2Fobjects-dont-sync-ad-sync-tool%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-US%2Ftroubleshoot%2Fazure%2Factive-directory%2Fobjects-dont-sync-ad-sync-tool%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Customer has an AD domain ( CORP )  and they are separating from the company with new domain ( ABC )

 

Currently they have M365, SharePoint and Teams access, As they are separating from the CORP domain they want to have a separate tenant with M365,Sharepoint and teams and still they will be login to CORP for internal resources access

 

  • We will create a new tenant and enable the access of M365, SharePoint and Teams access to the ABC domain users
    • COPR domain will not allow AD connect tool to sync ABC users to new tenant
    • Manually we will create the users in the tenant and allow them to use M365,Sharepoint and teams
    • User mailboxes are linked mailboxes
    • ABC users are ok to use two credentials for accessing the resources internally and externally

 

  • Once the ABC users are disconnected from CORP can we move and merge these users to the ABC tenant in the cloud ( M365)
  • If we are syncing the users from ABC via AD connect tool to the ABC tenant ( Will the same user objects merge in the Tenant )
  • In case we have to delete the users in the M365 tenant what happens to the user data of M365,Sharepoint and teams
  • Can we merge the same ABC users which were manually created in the cloud with On prem AD with AD connect tool.
  • Can we remap the users data if we delete them in the cloud and sync them again with AD connect

I will come to the right point.

 

Can we create a user in M365 and later merge the same user from on premises AD with AD connect tool

 

if above option is not possible then we want to delete the user created in M365 and sync the on premises users and connect them back to the same applications or data which the users were using wit cloud login.

 

Let me folks if the above options are possible.

 

Regards,

Arif

4 Replies
Best Response confirmed by arifsohail92 (Occasional Contributor)
Solution

@arifsohail92 If you create a cloud-only account in 365/Azure AD, and later connect AADConnect sync to it, it will merge accounts that it thinks are the same. Off the top of my head this is done off userPrincipalName or proxyAddresses matching. Probably something to test first but if your userPrincipalName on-premise is the same as the account logon name in 365, or the proxyAddresses contains a match for the email address of the cloud account (as the default address, i.e. SMTP: in upper case), it'll merge them. This is called "soft match" - there's a "hard match" which uses the sourceAnchor/immutableID but in your case I would expect soft match to work.

 

This explains it a bit better than I can https://raaaimund.github.io/tech/2019/06/13/merge-on-premise-existing-azure-ad-user/

 

 

@arifsohail92 I've only done it on my home domain with a very small amount of users (at work we created the accounts via AADConnect) but the main thing is to make sure the UPN etc matches before AADConnect runs - once you've run it without them matching it'll make duplicate users and you'll have to spend ages messing with immutableIds etc.

@CoasterKaty
So here the key point , making sure users UPN are correct and the SMTP addresses.
In this situation we must create a users by exporting their details from the On premises AD with UPN and SMTP address and importing them in bulk on M365/AzureAD.

So at the later stage of the migration for the Azure AD configuration we will be able to do soft match and sync all the users.

Appreciate your suggestions if you have any !!

Thanks !!