Jump to content

Recommended Posts

Posted

Hey all

 

I have been setting up my on premises server to sync with office 365 for single sign on. I have come across a bit of an issue and spent around 20 hours on the phone to Microsoft. Now I either don't understand fully or something gone wrong.

 

I sync all my staff member up to with azure ad connect at this point I thought great that seemed easy. I then seen that all my users had an email alias [email protected] so I thought I had done something wrong here. Some of my users are saying when they go to sign they there username come up with onmicrosoft.com user, some users also have duplicate emails accounts as well.

 

So my question should all users have alias [email protected].

 

Secondly not all users passwords have synced from on prem to office 365, I have only turned on password hash something I forgot what it's called :).

 

Thanks

Posted

Without knowing what you and Microsoft have been talking about, current set up (e.g. are you migrating from on premise Exchange) it’s hard to say much, but broadly speaking.

 

You have an O365 tenant. Let’s say it’s called tenant.sch.uk.

You have an AD domain. Let’s say that’s called ad.tenant.sch.uk

At this point, you need to have your public domain (e.g. Tenant.sch.uk) configured in O365 as a validated domain. prior to that, your O365 tenant will use the tenant name + onmicrosoft.com as your default name, e.g. tenant.sch.uk would have tenant.onmicrosoft.com. This address will stick with your o365 tenant and is nothing to worry about.

 

At this point, you need to have your public domain (e.g. school.sch.uk) configured in O365 as a validated domain

 

You’ve linked the two with AD connec and turned on Password Hash Sync, all good so far. You’ve hopefully got a unique identifier shared between the two for each user account, which should be immutableid on the o365 side and objectGUID or (going from memory, cba to look it up) ms-ds-consistencyguid in AD.

 

This should ensure that all your accounts in AD and O365 are properly linked. If this isn’t the case I’d expect to see either a complete set of duplicate accounts in O365 or a lot of errors in AD Connect.

 

At this point you should be able to create a mailbox in O365 based on your accounts in AD. If you don’t have an exchange hybrid setup, you may have fun associating the AD user with the cloud mailbox but it’s doable.

 

So what exactly do you see in AD Connect? And what do you see in O365 for each user, exactly?

 

What have Microsoft suggested you do?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...