Users sync from Azure Ad to onpremise ad

HASSAN BIN NASIR DAR 391 Reputation points
2022-10-11T23:40:44.933+00:00

Hi

I have 200 users which are created in Azure AD. I want to sync them to onpremise active directory.

Anybody can send me the steps how can we syned users from AZURE AD to On-premise AD?

Second question:

If users are synced from Onpremise to Azure Ad. After 2 days if onpremise AD goes to crashed. What will be in this case? Synced users which are already synced from onpremise to azure ad are still be available and active on Azure AD?

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

2 answers

Sort by: Most helpful
  1. Harpreet Singh Matharoo 8,396 Reputation points Microsoft Employee Moderator
    2022-10-12T04:57:10.847+00:00

    Hello @HASSAN BIN NASIR DAR

    I would like confirm below details with you:

    Question 1: How to Sync Azure AD users to Onpremises?

    • Unforunately as of today we do not support reverse Sync for users or Sync from Azure AD to On-Prem AD for user Objects.
    • If you have exisiting user objects on Azure AD and you would like to have them mapped to On-Prem AD then you can try to create similar user object over On-Prem AD and then perform a Soft match as mentioned on following documentation: Azure AD Connect: When you have an existing tenant

    Question 2: If users are synced from Onpremise to Azure Ad. After 2 days if onpremise AD goes to crashed. What will be in this case? Synced users which are already synced from onpremise to azure ad are still be available and active on Azure AD?

    • If you Sync users from On-Prem AD to Azure AD and if On-Prem AD for some reason goes down then, users on Azure AD would still be available. Once you're On-Prem AD is restored any changes made to user accounts would be sync'd to Azure AD normally. If you are unable to recover On-Prem AD you can Turn off directory synchronization for Microsoft 365/Azure AD and convert all user accounts to cloud only so that they do not lose access to cloud resources like Exchange other cloud applications hosted on Azure AD.
    • Authentication flow for those users can be impacted depending on what "User Sign-in" method you choose when setting up AD Connect.
    • If you setup AD Connect with Password Hash Sync, even when AD is down users would be able to sign-in and access all cloud resources.
    • If you had setup AD Connect with Pass Through Authentication or Federation then users would not be able to sign-in to access any resources as in these methods' user credentials are validated over On-Prem AD.

    I hope this helped to resolve your query.

    ----------

    Please "Accept the answer" if it helped you. This will help us and others in the community as well.

    5 people found this answer helpful.

  2. Umesh Pandit 21 Reputation points
    2023-10-18T01:33:48.6366667+00:00

    You cannot create users in Azure AD and sync them back to on-premises AD.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.