User synced with .onmicrosoft.com instead of default domain as primary AD Connector

Angela McLaughlin | NCTCS 10 Reputation points
2023-04-03T23:34:28.9733333+00:00

New to using the AD Connector to sync on-premise server. One user synced with .onmicrosoft.com instead of the default xyz.com domain as primary and you can't edit that in O365, nor can you change it in Active Directory on-premise because it isn't listed there. How do we resolve this?

Microsoft Security Microsoft Entra Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. Sandeep G-MSFT 20,906 Reputation points Microsoft Employee Moderator
    2023-04-04T09:57:39.62+00:00

    @Angela McLaughlin | NCTCS There are multiple reasons for user syncing with UPN suffix ".onmicrosoft.com". Say for example you have local on-premises domain as contoso.local. You need to have contoso.local as verified domain in Azure AD. Now, say you have added contoso.com as verified domain in Azure AD. If you are syncing the user as contoso.local to Azure AD from on-premises, then the UPN suffix will get set as ".onmicrosoft.com". Because you don't have contoso.local as verified domain in Azure AD. Instead, you have "contoso.com" as verified domain. To fix the above scenario you can follow the document as below, https://learn.microsoft.com/en-us/microsoft-365/enterprise/prepare-a-non-routable-domain-for-directory-synchronization?view=o365-worldwide There are multiple reasons on how UPN is populated in Azure AD. You can refer below article to know more about this, https://learn.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-userprincipalname Let me know if you have any further questions. Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.