Convert synced On-Prem users to Cloud-Only through attribute filtering

Glenn Vanderborght 0 Reputation points
2024-02-15T09:34:23.3133333+00:00

Hi, Is it possible to convert a synced user to a cloud only user when disabling the account in the on premise environment? in some cases the mailbox will be made available for a certain time as a shared mailbox, but we would like to remove unnecessary on-prem user accounts. But stopping the sync for a single user is (by my knowledge) not that straightforward. if it would be possible when a user is disabled to convert the synced online account to cloud only with logon disabled that would be ideal. Similar question:

https://learn.microsoft.com/en-us/answers/questions/839405/convert-synced-to-cloud?source=docs

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,655 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,163 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Thameur-BOURBITA 33,011 Reputation points
    2024-02-15T10:22:17.7333333+00:00

    Hi @Glenn Vanderborght

    Unfortunately, converting a synced user object to a cloud-only still not supported at this time. The only method to convert a synced object to cloud-only is to disable directory synchronisation, but this action will convert also all synced objects.

    Please don't forget to accept helpful answer


  2. Sandeep G-MSFT 19,761 Reputation points Microsoft Employee
    2024-03-05T06:43:55.8033333+00:00

    @Glenn Vanderborght

    Thank you for posting this in Microsoft Q&A.

    As Thameur mentioned above, changing the user status for particular user to cloud only is not available at this moment.

    However, you can perform below steps which will help you in changing the user status for particular to In Cloud in Azure.

    • Move the user (which you want to disable) to non-sync OU in on-premise AD.
    • Run delta sync in AD connect tool. This will move the user in Azure to deleted container.
    • Now wait for 15-20 mins and move the user from deleted container to user's container in Azure manually.
    • This will change the user status to "In Cloud".

    This method works but incurs a delay of 10-20 minutes per user while Azure processes the restoration.

    Apart from this you can also use the option that Thameur has mentioned above in his answer.

    Let me know if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.