SOLVED

Sync Office 365 users to new on premises AD

%3CLINGO-SUB%20id%3D%22lingo-sub-2133710%22%20slang%3D%22en-US%22%3ESync%20Office%20365%20users%20to%20new%20on%20premises%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2133710%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20about%20to%20create%20a%20new%20on%20premises%20AD%20domain%20in%20a%20company%20who%20already%20had%20Office%20365%2C%20and%20now%20they%20want%20to%20manage%20internal%20infrastructure.%20We%20have%20found%20several%20resources%20on%20how%20to%20do%20it%2C%20however%20there%20are%20some%20gray%20areas%3A%3C%2FP%3E%3CP%3E1.%20Is%20there%20a%20way%2C%20when%20syncing%20office%20365%20users%20to%20on%20prem.%20to%20allow%20the%20users%20to%20keep%20their%20(already%20known)%20Office%20365%20password%20to%20login%20to%20their%20workstations%3F%3C%2FP%3E%3CP%3E2.%20What%20do%20we%20need%20to%20do%20after%20to%20have%20Azure%20AD%20sync%20for%20the%20local%20AD%20and%20the%20O365%20(keep%20in%20mind%20that%20we%20are%20looking%20to%20use%20the%20free%20Azure%20AD%2C%20based%20on%20our%20Office%20365%20subscriptions).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%20regards%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EK%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2133710%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EActive%20Directory%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2136914%22%20slang%3D%22en-US%22%3ERe%3A%20Sync%20Office%20365%20users%20to%20new%20on%20premises%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2136914%22%20slang%3D%22en-US%22%3E%3CP%3ESync%20is%20one-directional%20only%2C%20*from*%20on-premises%20AD%20to%20Azure%20AD.%20You%20cannot%20do%20it%20in%20the%20other%20direction.%20The%20usual%20workaround%20is%20to%20export%2Fimport%20the%20objects%20via%20PowerShell%20or%20use%20third-party%20tools%20that%20do%20the%20same.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2157331%22%20slang%3D%22en-US%22%3ERe%3A%20Sync%20Office%20365%20users%20to%20new%20on%20premises%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2157331%22%20slang%3D%22en-US%22%3E%3CP%3EThank%20you%20very%20much%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOne%20area%20of%20concern%3A%20what%20happens%20to%20Office%20365%20users%20that%20I%20choose%20not%20to%20sync%20from%20on%20premises%20AD%20%26gt%3B%20Office%20365%20AD%3F%3C%2FP%3E%3CP%3ETo%20be%20more%20specific%2C%20I%20dont%20need%20all%20the%20users%20of%20the%20Office%20365%20AD%20to%20be%20a%20part%20of%20the%20on%20premises%20AD%2C%20so%20when%20I%20got%20a%20csv%20from%20Office%20365%20AD%2C%20I%20did%20not%20import%20all%20the%20users%20in%20the%20local%20AD.%3C%2FP%3E%3CP%3EWhat%20will%20happen%20to%20those%20users%20after%20the%20first%20initial%20sync%3F%20WIll%20they%20be%20deleted%20from%20Office%20365%20AD%20or%20remain%20%22cloud-only%22%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%20regards%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EK%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hello all,

 

We are about to create a new on premises AD domain in a company who already had Office 365, and now they want to manage internal infrastructure. We have found several resources on how to do it, however there are some gray areas:

1. Is there a way, when syncing office 365 users to on prem. to allow the users to keep their (already known) Office 365 password to login to their workstations?

2. What do we need to do after to have Azure AD sync for the local AD and the O365 (keep in mind that we are looking to use the free Azure AD, based on our Office 365 subscriptions).

 

Thanks in advance

 

Best regards

 

K

6 Replies

Sync is one-directional only, *from* on-premises AD to Azure AD. You cannot do it in the other direction. The usual workaround is to export/import the objects via PowerShell or use third-party tools that do the same.

Thank you very much @Vasil Michev 

One area of concern: what happens to Office 365 users that I choose not to sync from on premises AD > Office 365 AD?

To be more specific, I dont need all the users of the Office 365 AD to be a part of the on premises AD, so when I got a csv from Office 365 AD, I did not import all the users in the local AD.

What will happen to those users after the first initial sync? WIll they be deleted from Office 365 AD or remain "cloud-only"?

 

Best regards

 

K

Nothing will be deleted.

Thank you very much @Vasil Michev 

So those users will remain as "cloud-only"?

 

Best regards

 

K

best response confirmed by costasppc (Occasional Contributor)
Solution

Yes, unless they get matched with an on-premises object (based on Primary SMTP address/UPN).

Thank you @Vasil Michev 

What I noticed is this: when the user is moved to a non-syncing OU, its moved to Deleted Users of Office 365 after next delta sync. When the user is restored, its password need to be changed in order to become cloud-only.

 

Best regards

 

K