azure ad connect
132 TopicsAzure AD Connect is not synchronizing Computer objects
Hi, I installed and configured Azure AD Connect like a few times before but now Computer objects are not synchronizing. They are included in filtering but there is not export to Azure AD, no error or warning, nothing. Azure AD Connect Troubleshooter just saying "Object is not available in AAD Connector Space" (everything else is green/ok). I just reinstalled it but without success. Any ideas? Kind regards PatrickSolved97KViews0likes15CommentsAD Connect Multiple Tenants Single AD
Hi, Wonder if this is possible? We have a client that wants to keep his two domains separate and in different tenants and then sync on prem AD to the two tenants. The on prem AD would have both domains UPN suffix's added to their accounts in on prem AD as the users in both tenants would be the same. Thanks66KViews0likes6CommentsExchange Online and Azure AD Connect
Hi everyone, We are planning to implement Azure AD Connect in a Password Hash Synchronization with Seamless Sign On scenario, hosted on Azure B1ms Windows Server 2016 AD DC connect to on-prem AD via S2S VPN. My company of around 100 users have had O365 for several years and the on-prem and AAD environments are totally separate for now. One thing that has come up in my research is with Azure AD Connect in place, on-prem AD must be the source of all objects, attributes, and changes - makes sense. Where there is confusion is Exchange Online attributes. Several older threads on Tech Community and other forums state you cannot change EXO attributes, in an AAD Connect environment, without on-prem Exchange installed or at least its schema changes. On review, the only EXO attributes we would change that aren't in the default AD schema are mailbox delegation (SendAs, AccessRights, etc) and email addresses (multiple SMTP addresses). Other attributes that show in EXO such as Job Title, Address, and Tel Numbers are all available in the default schema via AD Users & Computers, so my presumption is they're not of concern. Can anyone shed some light on this and confirm how we'd manage things like multiple SMTP addresses without the Exchange scheme in our on-prem AD? Does this differ depending on where the object is managed (cloud only vs hybrid) or user mailbox vs shared? Thank you, Ruairidh56KViews1like30CommentsPassword Expiration notification
I have a number of users who have recently transitioned to Azure joined devices and are authenticating directly through AAD, though their accounts were originated in On-prem AD. When their passwords expire, they aren't getting notification but finding out when certain on-prem services aren't connecting. We are using AD Sync and it's going both ways AAD to OP and OP to AAD . I guess my question is 2 fold: Is it possible that AD is still expiring the password and if not, where can I find where it is expiring? Is there any way to turn on expiration notification for Azure AD users? Thanks,34KViews0likes2CommentsAzure AD Connect -- Attribute Value Must Be Unique
-- Updating from my previous message -- I managed to get syncing attempts happening by removing the group filter. As my test group, I made a special OU for the test user and am applying the sync only to this OU. I am now a bit further, but stumped again. Both AD accounts and AAD accounts are pre-existing: AD Account: mailto:j.smith@domain.com (actually a .local account, but UPN added to AD) AAD Account: mailto:john.smith@domain.com When the sync happens, I am getting "Error: Attribute Value Must Be Unique" Looking deeper at the error, it is mentioning the error is in relation to the ProxyAddress. I have already defined the following in AD for the j.smith user: email (General Tab): mailto:john.smith@domain.com Proxy Address (Attribute Editor): SMTP:john.smith@domain.com this does not seem to help though. I have tested also by removing Proxy Address and still no go. any thoughts?27KViews1like2CommentsAzure AD Connect service critical alert reported: dn-attributes-failure
[I sent an email to askaadconnecthealth@microsoft.com with the below content a few days ago but haven't heard back so decided to start a conversation here] As per the below synchronization errors email I have been receiving, there are three cloud-only Office 365 users with “Sign in blocked” that were previously synched using Azure AD Connect. The accounts were previously moved out of the sync OU and when they appeared as deleted users in Office 365, were restored to keep their data intact. The AD users have since been deleted and cannot be restored. https://aad.portal.azure.com/#blade/Microsoft_Azure_ADHybridHealth/AadHealthMenuBlade/SyncErros There are no further error details other than the type: dn-attributes-failure There are no other sync errors and Azure AD Connect is showing success on all connector operations. I do not want to delete these accounts from Office 365. Could anyone please advise me to know which steps to take to resolve the issue causing these three accounts to be included in the report for synchronization errors? They are cloud-only and do not need to be synched with AD. Is it necessary to re-create the AD users in the sync OU and set their Office 365 account ImmutableID to sync and match their AD account (source anchor is objectGUID) so they do not get reported as sync errors? ----- From: Microsoft Azure [mailto:azure-noreply@microsoft.com] Sent: 02 September 2019 11:10 Subject: We detected synchronization errors in your directory There are synchronization errors in your directory. Azure AD Connect Sync errors detected You’re receiving this email because we have detected a critical alert on your Azure AD Connect service for errors that occurred while data was while synchronizing between your on- premises active directory and your Azure Active Directory. Title: Sync errors detected on your Azure AD Connect service Last export time: August 13, 2019 15:25 UTC Error count: 3 sync errors Service: [tenant].onmicrosoft.com Tenant: John Hanson School Report: To get more details, see Sync Error Report. To learn how to fix sync errors, see https://azure.microsoft.com/email/?destination=https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconnect%2Factive-directory-aadconnect-troubleshoot-sync-errors&p=bT0zMTQ2MjExOS1hZjlmLTQ0NzEtODljOC04YzZjNmJlOTAyN2EmdT1hZW8mbD1kb2NzJTNBdHJvdWJsZXNob290LXN5bmMtZXJyb3Jz. If you have any feedback, please post it to the https://azure.microsoft.com/email/?destination=http%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3FLinkId%3D519357&p=bT0zMTQ2MjExOS1hZjlmLTQ0NzEtODljOC04YzZjNmJlOTAyN2EmdT1hZW8mbD1md2xpbms%3D or mailto:askaadconnecthealth@microsoft.com for any questions. https://azure.microsoft.com/email/?destination=https%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3FLinkId%3D521839&p=bT0zMTQ2MjExOS1hZjlmLTQ0NzEtODljOC04YzZjNmJlOTAyN2EmdT1hZW8mbD1wcml2YWN5LXN0YXRlbWVudA%3D%3D Microsoft Corporation, One Microsoft Way, Redmond, WA 9805218KViews0likes1CommentAzure AD Connect: Filtering out local AD users not working
Hello, we have users in local AD that could be absent for a while and we have to disable their local AD accouns for compliance reasons. Now, due to an active Azure AD sync this will also delete their account in Azure AD / Office 365. I found a neat guide how to exclude users from the AD -> AAD sync by setting a value in a free extensionAttribute and configuring a synchronization rule to set the property "cloudFiltered" to true. This is all explained in this guide https://www.checkyourlogs.net/?p=66483 However, when testing it, as soon as I set the extension attribute and perform a delta import, and delta sync on the AD connector in the AAD Synchronization Service it will attempt to completeley delete the persons cloud object. I found out that this is because the "ms-DS-ConsistencyGUID"'s value is removed. I can't figure out why that synchronization rules causes this to occurr. I verified that it must be this rule since I can change any other attribute of the person object and it will update properly. Only when I populate the extensionAttribute configured in the sync rule will the rmoval of the "ms-DS-ConsistencyGUID"'s value be triggered. Any ideas? Thanks.Solved18KViews0likes9CommentsAD Connect Start-ConnectivityValidation - GetDomain failing error while running adding directories
We have some 40 countries i.e. 40 local forests in our environment separated by firewalls. We are trying to onboard all our local forests on AD Connect and decommission MIM. We have this issue where the Start-ConnectivityValidation command of the ADConnectivityTool PS module, fails with the error “GetDomain failed. The specified domain does not exist or cannot be contacted”. The AD Connect servers are in a different forest than the country forests. Here are the configuration details:- ADC Architecture: Multi-forest, single tenant. Country Forests Network Architecture: All forests have a DMZ, that contains an additional DC with which AD Connect has connectivity. Local forest network doesn't have direct network connectivity with ADC forest. Firewall Settings: ADC Staging & Prod servers IP ranges are allowed in country forest's firewall. ADC forest firewall allows all traffic to & from all forest networks. Ports: 53, 88, 389 & 3268 are open for both TC & UDP protocols. DNS Request Routing: AD Connect uses Conditional Forwarders, MIM uses Hosts file or Fwd Zones. SRV Records: Configured for both LDAP & Kerberos on the country forest's local DNS for the DMZ ADC. Test-NetConnectivity: Successful for above mentioned ports. NSLookup/Ping: Successfully resolves the DCs, DMZ ADC also listed in the output. Confirm-DnsConnectivity: Successful Connectivity Validation: Start-ConnectivityValidation -Forest "contoso.com" -AutoCreateConnectorAccount $False -Username "contoso.com\username" fails with the above mentioned error. Even tried the Netbios name format, but still no success. MS Premier Support Directory Services, Network(DNS) & Identity support guys have all tried but can't resolve this issue. Any help will be highly appreciated.18KViews0likes17CommentsFind ENABLED Users that need MFA
So, I am thinking maybe I am asking the wrong question... What I want is to find with PowerShell is All enabled user accounts that do not have MFA turned on I have been shocked how hard it is. Firstly I can't use powershell 7 because connect-azuread is not supported Then, when I do get connected, the get-azureaduser does not have the MFA status Now I find the MSol commands are deprecated, and do not show the enabled status I have found an AWESOME script that tells me ALL the users and their MFA Status (Not my script) ((Get-MsolUser -all | select DisplayName,UserPrincipalName,@{Name="MFA Status"; Expression={ if( $_.StrongAuthenticationMethods.IsDefault -eq $true) {($_.StrongAuthenticationMethods | Where IsDefault -eq $True).MethodType} else { "Disabled"}}}) But I can't filter out the thousands that are not enabled I feel I am missing something bigger here, like I am going about this the wrong way. what am I missing???17KViews0likes2Comments