Jump to content

Recommended Posts

Posted (edited)

Hi all,

Hope you are all well.

I have a gap in my knowledge and before I move any further forward, I have a few questions I need to be sure of the answers to before proceeding. I’ve trawled forums and help documents but I want to be clear before pushing this change on the users at school.

I am wanting to use Azure AD Connect, the school I manage looks to have been connected years ago but this has not been used for a long time. This would be initially to use features such as password hash sync and seamless SSO. Then in the future I’d like to progress down the Intune route and Autopilot but that is another story for now.

After enabling Azure AD Connect, which password is used when using password hash sync, does the current AD password overwrite the M365 one or does the M365 one overwrite the AD password?

Following the change, does the user need to sign in to the computer with their email address or can they use their normal AD credentials as normal? I’d already changed the routable domain for some users however this is the next step to change the UPN suffix for all users.

Regarding SSO for office, do the devices have to be hybrid azure ad joined for this to work or will this work without being hybrid joined? We are using Office 2021 at the moment but I’d like to move to M365 Office for all with new features etc.

I think this is everything I can think of for now haha, thanks in advance everyone.

Kind Regards,

Tom

Edited by tomsam22
Posted (edited)

Azure password hash sync is going from AD to M365 first then after you can enable M365 to AD write back but this needs a licence with a Password write back option, and you have to enable it on the Azure Ad Connect wizard.

 

for the UPN question they login normally on a computer but when they login via Office 365 they have to use their email address unless you are on site with Seamless SSO when it will auto sign in the user. Don't forgot to use smart sso links to link to office 365 services on the web: https://jackstromberg.com/o365-smart-linksso-link-generator/ this helps trigger seamless SSO

Edited by willtech
  • Thanks 1
Posted

Thanks Will, that’s a big help.

 

I’ve got Azure P1 License so I could do password write back I believe. Would it be the case that if I enabled password hash sync, it would then overwrite the M365 passwords from AD but then they could set a new password from M365 which would then write back? Either way, I’m losing my current M365 passwords? It wouldn’t be an issue normally but Y11s get their results via email so obviously don’t wanna change these really, at least right now.

 

Kind Regards,

 

Tom

Posted

You could use “PHSFiltered“ and set that on Year 11 so it bypasses them for sync

 

Then either re-enable it after if they’re 6th form or don’t care when they get deleted

 

Steve

  • Thanks 1
Posted
Thanks all, I’m going to look at matching the O365 uses with AD now before going any further. Don’t want any duplicate users in Azure!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...