MSOL account is the subject user for an AD password change

Ganesan I 0 Reputation points
2024-07-15T10:36:46.1533333+00:00

Hi all,

I have a Entra connect AD setup. In this setup, Azure is only a backup server, where it synchronizes the objects from on-prem AD to Azure AD at a regular frequency.

Whenever I change my password, subject username was "ANONYMOUS LOGON". But recently I noticed MSOL_xxxx account in subject username.

Up to my knowledge, even though this MSOL account has high privileges, it was configured to sync objects alone.

I would be much obliged if anyone explain why this happened?

Thanks in advance.

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,799 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,655 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,161 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Raja Pothuraju 8,085 Reputation points Microsoft Vendor
    2024-07-19T22:55:20.43+00:00

    Hello @Ganesan I,

    Thank you for posting your query on Microsoft Q&A.

    You are correct that when an attempt is made from Entra to change a user password, the MSOL_ account is used to write back these changes to on-premises. This is why you are seeing an audit log with that account name.

    SSPR and password writeback are indeed enabled, which allows successful password writeback to on-premises. You can verify this through the Azure Portal as well. Please refer to the following documents for more information:

    Tutorial: Enable self-service password reset

    Tutorial: Enable password writeback for SSPR

    I hope this information is helpful. Please feel free to reach out if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    Thanks,
    Raja Pothuraju.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.