Jump to content

Removing Dir-sync Azure Ad connect from O365


Recommended Posts

Posted

Hi All I wonder if anyone can help or advise.

 

We currently have sync between O365 and on-premise AD using Azure AD connect. We will soon be having a new server and system set up, so I am wondering if it will be good time to disconnect the dir-sync, on a permanent basis. We are only a small school so creating new users twice, once in AD then 0365 is not a problem, same with any password syncing. My question is , is it straight forward to remove/disconnect AD sync ? I have done a google search which seems to show it is. However if anyone has any advice , eg are there any 'gotchas' I need to be aware of .

 

Thanks in advance.

Posted

If you've already got dirsync automatically provisioning accounts, which is the ideal setup then I don't really see why you'd want to get rid of it?

 

Don't forget everyone has two sets of passwords then possibly with different complexity rules, it becomes more messy if you go the manual route.

Posted

Ditto, not really sure why you would want to get rid assuming it is running already without issues.

 

But removing is very easy. Just disable via the web gui and then that its. Even the client can stay installed it will just give errors

Posted
The way 0365 was set up here means I have to do a few manual tasks for each newly created user in AD Eg set SMTP: proxy adddress in attribute editor in AD, also set the account to the email@address rather than .internal. Also I thought if there is ever a problem with Azure Ad connect I wouldn't need to worry if there is no sync.
Posted
I would keep using AD Connect. With the new updates coming to AD Connect you will be able to allow sso for your domain joined computers without ADFS and your users will not need to remember two passwords. If you ever have an issue with Azure AD Connect it is easy enough to reinstall or install it on another machine and start syncing again.
  • Thanks 1
Posted
Another vote to keep the Sync, one less think to worry about. It will be a PITA for the users to have to remember 2 passwords, it will only end extra admin work for you.
  • Thanks 1
Posted

The tasks you are doing manually, have you thought of creating a PowerShell script that runs at regular intervals to search for users that don't have the attributes set correctly and then correcting the attributes for you?

 

With a touchless system that just works you might like DIR Sync more and see the point of it?

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...