Fix AD user getting delete when sync on

Tristan Bulteau 0 Reputation points
2023-09-27T13:15:05.3066667+00:00

Hello,

 

For the explication, i've one OU (we'll call it OU A) that's sync (on CloudSync) where i had two users that're sync.

When we have synchronize this two users we've push the sync with there distinguish name.

 

A few weeks later : 

I've moove this two users to another OU (we'll call it OU B) that's sync too (on CloudSync).

But suddently after the auto-sync (the one that pass every 15mn), it delete my two users from Azure AD (as i guess it don't find this two users anymore in the OU A).

So i had to remove my user to the OU A cause every 15mn they were delete from my Azure AD (even though i push the sync with the new distinguish name of the OU B).

 

So my question is, how I move an user from the OU A to the OU B without them being delete on Azure AD ?

 

Thanks.

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
4,355 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,239 questions
Windows 365 Enterprise
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,619 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Marilee Turscak-MSFT 36,411 Reputation points Microsoft Employee
    2023-09-29T00:52:29.4966667+00:00

    @Tristan Bulteau ,

    If your Azure AD Connect is only configured to sync specific OUs, moving the Active Directory account out of a synchronized OU (to a non-synchronized OU) will delete the account in Azure AD. It sounds like your other OU is not synchronized.

    If you move the user to another OU that is synchronized, it should not be deleted.

    You can also restore the deleted user in Azure, and it will restore it to a cloud account.

    See related:

    https://community.spiceworks.com/topic/1976898-move-ad-user-to-non-dir-syned-ou-without-office-365-deleting-mailbox-user

    https://community.spiceworks.com/topic/2074307-moving-ad-users-to-different-ous-deletes-the-exchange-online-mailbox


  2. チャブーン 786 Reputation points MVP
    2023-09-29T07:47:58.2333333+00:00

    Hi, Tristan Bulteau

    This is Chaboon.

    Marilee Turscak-MSFT's answer is right.

    Microsoft Entra CloudSync does not have security group-based synchronization functionality. You can use the entire domain or only OUs to scope the synchronization.

    0 comments No comments