SFB Hybrid move accounts using onmicrosoft.com account

%3CLINGO-SUB%20id%3D%22lingo-sub-227199%22%20slang%3D%22en-US%22%3ESFB%20Hybrid%20move%20accounts%20using%20onmicrosoft.com%20account%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-227199%22%20slang%3D%22en-US%22%3E%3CP%3Ehi%26nbsp%3B%3C%2FP%3E%3CP%3Ewe%20have%20recently%20setup%20SFB%20hybrid%20in%20the%20LAB%20and%20we%20moved%20some%20users%20across%20using%20on-prem%20csadministrator%20synced%20to%20the%20cloud%20(%20Glob%20Admin%20in%20o365%20).%20After%20that%2C%20we%20tried%20moving%20users%20using%20o365%20Glob%20Admin%20but%20that%20failed.%20Here%20is%20what%20we%20did%3A%3C%2FP%3E%3CP%3EOn-prem%20CsAdminitrator%20logged%20in%20on%20SFB%20FE%20server%20(FE%20has%20access%20to%20o365).%20SkypeOnline%20powershell%20module%20installed%20on%20the%20FE%20server%20%2B%20Sign-In%20assistant.%20It%20is%20possible%20to%20create%20remote%20PSh%20session%20to%20SFBO%20using%20onmicrosoft.com%20account%20(as%20I%20mentioned%20before%20that%20account%20is%20Glob%20Admin).%20MFA%20for%20the%20cloud%20account%20is%20disabled.%20When%20we%20try%20to%20move%20an%20user%20using%20move-csusers%20and%20providing%20-credentials%20of%20the%20o365%20Glob%20Admin%20the%20command%20fails%20with%20the%20following%20error%3A%26nbsp%3B%3C%2FP%3E%3CPRE%3E%3CSPAN%20class%3D%22typ%22%3EGetting%3C%2FSPAN%3E%3CSPAN%20class%3D%22pln%22%3E%20web%20ticket%20%3C%2FSPAN%3E%3CSPAN%20class%3D%22kwd%22%3Efor%3C%2FSPAN%3E%3CSPAN%20class%3D%22pln%22%3E%20the%20given%20user%20%3C%2FSPAN%3E%3CSPAN%20class%3D%22kwd%22%3Eis%3C%2FSPAN%3E%3CSPAN%20class%3D%22pln%22%3E%20failed%3C%2FSPAN%3E%3CSPAN%20class%3D%22pun%22%3E.%3C%2FSPAN%3E%20%3CSPAN%20class%3D%22typ%22%3EError%3C%2FSPAN%3E%20%3CSPAN%20class%3D%22typ%22%3ECode%3C%2FSPAN%3E%3CSPAN%20class%3D%22pun%22%3E%3A%3C%2FSPAN%3E%20%3CSPAN%20class%3D%22lit%22%3E28000%3C%2FSPAN%3E%20%3CSPAN%20class%3D%22pun%22%3E%2C%3C%2FSPAN%3E%20%3CSPAN%20class%3D%22typ%22%3EError%3C%2FSPAN%3E%20%3CSPAN%20class%3D%22typ%22%3EReason%3C%2FSPAN%3E%3CSPAN%20class%3D%22pun%22%3E%3A%3C%2FSPAN%3E%20%3CSPAN%20class%3D%22typ%22%3EUser%3C%2FSPAN%3E%20%3CSPAN%20class%3D%22kwd%22%3Eis%3C%2FSPAN%3E%20%3CSPAN%20class%3D%22kwd%22%3Enot%3C%2FSPAN%3E%3CSPAN%20class%3D%22pln%22%3E%20SIP%20enabled.%20%3C%2FSPAN%3E%26nbsp%3B%3C%2FPRE%3E%3CP%3E%26nbsp%3BAny%20idea%20what%20the%20issue%20might%20be%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-227199%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ESkype%20for%20Business%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-227794%22%20slang%3D%22en-US%22%3ERe%3A%20SFB%20Hybrid%20move%20accounts%20using%20onmicrosoft.com%20account%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-227794%22%20slang%3D%22en-US%22%3E%3CP%3Eok%2C%20problem%20solved%20%3A).%20It%20appeared%20to%20be%20one%20of%20those%20RTFM%20things%20you%20don't%20pay%20too%20much%20attention%20to%20especially%20when%20you%20are%20in%20a%20rush.%20The%20msft%20doc%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fskypeforbusiness%2Fskype-for-business-hybrid-solutions%2Fdeploy-hybrid-connectivity%2Fmove-users-from-skype-for-business-online-to-on-premises%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fskypeforbusiness%2Fskype-for-business-hybrid-solutions%2Fdeploy-hybrid-connectivity%2Fmove-users-from-skype-for-business-online-to-on-premises%3C%2FA%3E%20says%20%3A%3CBR%20%2F%3E%3CBR%20%2F%3E---%3CBR%20%2F%3E%3CBR%20%2F%3Eselect%20and%20copy%20the%20URL%20in%20the%20address%20bar%20up%20to%20lync.com.%20An%20example%20URL%20looks%20similar%20to%20the%20following%3A%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fwebdir0a.online.lync.com%2Flscp%2F%3Flanguage%3Den-US%26amp%3Bamp%3BtenantID%3D%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwebdir0a.online.lync.com%2Flscp%2F%3Flanguage%3Den-US%26amp%3Bamp%3BtenantID%3D%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3E----%3CBR%20%2F%3E%3CBR%20%2F%3Eand%20that%20is%20what%20we%20did%2C%20missing%20the%20next%20step%20that%20says%20%22and%20now%20replace%20webdir%20with%20admin%22%3CBR%20%2F%3E%3CBR%20%2F%3ENow%20the%20funny%20part%20is%20that%20actually%20the%20webdir%20url%20actually%20worked%20when%20we%20used%20the%20sync%20on-prem%20csadmin%20account%2C%20and%20it%20started%20failing%20after%20we%20decided%20to%20use%20onmicrosoft.com%20account%20to%26nbsp%3B%20move%20users%20to%20SFBO.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-756699%22%20slang%3D%22en-US%22%3ERe%3A%20SFB%20Hybrid%20move%20accounts%20using%20xxxxxx.onmicrosoft.com%20account%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-756699%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1609%22%20target%3D%22_blank%22%3E%40Plamen%20Gavrailov%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eso%20correct%20at%20times%20microsoft%20tools%20can%20be%20real%20headache%2C%3C%2FP%3E%3CP%3Eon%20windows%2010%20to%20get%20powershell%20working%20a%20challenge%20if%20you%20ws-manangement%20or%20WinRM%20config%20define%20first%20it%20will%20not%20let%20you%20connect%20if%20BASIC%20auth%20in%20WinRM%20is%20disabled%3C%2FP%3E%3CP%3Ethen%20the%20Move-CSUser%20has%20credential%20parameter%20which%20it%20will%20not%20work%20with%20what%20a%20stupidity%20%3F%20how%20are%20you%20suppose%20to%20get%20this%20stupid%20command%20working%20if%20you%20have%20MFA%20enabled%20on%20this%20user%20%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

hi 

we have recently setup SFB hybrid in the LAB and we moved some users across using on-prem csadministrator synced to the cloud ( Glob Admin in o365 ). After that, we tried moving users using o365 Glob Admin but that failed. Here is what we did:

On-prem CsAdminitrator logged in on SFB FE server (FE has access to o365). SkypeOnline powershell module installed on the FE server + Sign-In assistant. It is possible to create remote PSh session to SFBO using onmicrosoft.com account (as I mentioned before that account is Glob Admin). MFA for the cloud account is disabled. When we try to move an user using move-csusers and providing -credentials of the o365 Glob Admin the command fails with the following error: 

Getting web ticket for the given user is failed. Error Code: 28000 , Error Reason: User is not SIP enabled.  

 Any idea what the issue might be?

 

2 Replies

ok, problem solved :). It appeared to be one of those RTFM things you don't pay too much attention to especially when you are in a rush. The msft doc https://docs.microsoft.com/en-us/skypeforbusiness/skype-for-business-hybrid-solutions/deploy-hybrid-... says :

---

select and copy the URL in the address bar up to lync.com. An example URL looks similar to the following:
https://webdir0a.online.lync.com/lscp/?language=en-US&tenantID=

----

and that is what we did, missing the next step that says "and now replace webdir with admin"

Now the funny part is that actually the webdir url actually worked when we used the sync on-prem csadmin account, and it started failing after we decided to use onmicrosoft.com account to  move users to SFBO.

@Plamen Gavrailov

 

so correct at times microsoft tools can be real headache,

on windows 10 to get powershell working a challenge if you ws-manangement or WinRM config define first it will not let you connect if BASIC auth in WinRM is disabled

then the Move-CSUser has credential parameter which it will not work with what a stupidity ? how are you suppose to get this stupid command working if you have MFA enabled on this user ?