sloughman Posted February 14, 2017 Posted February 14, 2017 Hi All I wonder if anyone can help or advise. We currently have sync between O365 and on-premise AD using Azure AD connect. We will soon be having a new server and system set up, so I am wondering if it will be good time to disconnect the dir-sync, on a permanent basis. We are only a small school so creating new users twice, once in AD then 0365 is not a problem, same with any password syncing. My question is , is it straight forward to remove/disconnect AD sync ? I have done a google search which seems to show it is. However if anyone has any advice , eg are there any 'gotchas' I need to be aware of . Thanks in advance.
PotNoodleTech Posted February 14, 2017 Posted February 14, 2017 If you've already got dirsync automatically provisioning accounts, which is the ideal setup then I don't really see why you'd want to get rid of it? Don't forget everyone has two sets of passwords then possibly with different complexity rules, it becomes more messy if you go the manual route.
snagrat Posted February 14, 2017 Posted February 14, 2017 Ditto, not really sure why you would want to get rid assuming it is running already without issues. But removing is very easy. Just disable via the web gui and then that its. Even the client can stay installed it will just give errors
sloughman Posted February 14, 2017 Author Posted February 14, 2017 The way 0365 was set up here means I have to do a few manual tasks for each newly created user in AD Eg set SMTP: proxy adddress in attribute editor in AD, also set the account to the email@address rather than .internal. Also I thought if there is ever a problem with Azure Ad connect I wouldn't need to worry if there is no sync.
NicholasEsping Posted February 14, 2017 Posted February 14, 2017 I would keep using AD Connect. With the new updates coming to AD Connect you will be able to allow sso for your domain joined computers without ADFS and your users will not need to remember two passwords. If you ever have an issue with Azure AD Connect it is easy enough to reinstall or install it on another machine and start syncing again. 1
Davit2005 Posted February 15, 2017 Posted February 15, 2017 Another vote to keep the Sync, one less think to worry about. It will be a PITA for the users to have to remember 2 passwords, it will only end extra admin work for you. 1
ThomL Posted February 15, 2017 Posted February 15, 2017 The tasks you are doing manually, have you thought of creating a PowerShell script that runs at regular intervals to search for users that don't have the attributes set correctly and then correcting the attributes for you? With a touchless system that just works you might like DIR Sync more and see the point of it? 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now