What will happen when you turn off directory synchronization for MS 365?

Noctis0791 121 Reputation points
2020-07-24T19:30:42.493+00:00

Hi Experts,

Just a quick confirmation here since I cannot find the answers online thru my searches. What will happen when you turn off directory synchronization for MS 365?

  1. Will all Synced accounts in MS 365 become Cloud Only accounts?
  2. How about the passwords, will it be the cloud password prior to AAD Sync implementation? Or the passwords from the most recent AAD Sync will stick?

Please advise.

Thank you so much!

Logbi

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Sakaldeep Yadav 171 Reputation points MVP
    2020-07-24T19:54:14.437+00:00

    Hi,

    1. No, it won't. You can see the sync error "latest data is not available" but there won't be an impact on account source.
    2. The password from the most recent AAD sync will stick.

    I hope this helps

    Cheers
    Sakaldeep

    1 person found this answer helpful.
    0 comments No comments

  2. VipulSparsh-MSFT 16,311 Reputation points Microsoft Employee
    2020-07-27T10:33:47.79+00:00

    @Noctis0791-8502 If you plan to turn off directory synchronization for MS 365, all users will start showing up as In-Cloud users. And you will be able to delete the synced users just like cloud users.

    For example, this user was a synced user :
    13914-synced-account.png

    Once you disable the synchronization, you will see that this user changed to In-cloud user on Office portal.

    13931-turnedin-cloud.jpg

    Azure AD portal might take upto 72 hours to show this change but office portal is quite quick. You can then test it by deleting the previously synced user from office portal to confirm, just like this screenshot :

    13876-delete-user.jpg
    13922-delete-process.jpg
    13892-account-deleted.jpg

    And for the password, it sticks to the last password which was synchronized from local AD. Hope this helps. Let us know if you have any questions.


    If the suggested response helped you resolve your issue, do click on "Mark as Answer" and "Up-Vote" for the answer that helped you for benefit of the community.


  3. Doug Chandler 2 Reputation points
    2025-02-20T17:08:28.8566667+00:00

    The other thing that happens is the account name gets updated. This is used by Windows as the directory name for the user. All the time this is synced, I believe it can be overridden or uses the ImmutableID, but when you switch off the sync it is forced to be the Account Name without any spaces. This causes a problem if you put any non-standard characters into the account name as it might cause problems with software on a Windows PC.

    Never understood why they use essentially a free text field for the folder name c:\Users...

    0 comments No comments

  4. Stéphane RENAUD 0 Reputation points
    2025-03-18T10:49:29.9733333+00:00

    Hi Thanks for the clarifications. and what about the ImmutableID, is it cleared when all accounts are converted ? and if we reenable the Sync 72h later how it will match all accounts with on-prem ?

    Thanks for your answer


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.