Azure AD Connect - procedure to change source of anchor from ObjectSID to Ms-DS-ConsistencyGUID

G.W 51 Reputation points
2020-10-13T07:25:27.08+00:00

Hello,

We are an organization of + 1000 users with ADs (domain and subdomains) linked to Azure AD via Azure Ad Connect.

Currently the anchor source is ObjectSID, UPN = mail and Hybrid Exchange.

We would like to change it to MS-DS-ConsistencyGUID in order to be able to move objects easily between ADs without impacting the Azure AD accounts.

We have found documentation about changing the anchor source for ObjectGUID attributes to MS-DS-ConsistencyGUID but not much for attributes other than ObjectGUID.

I have read and tested several ideas but nothing is 100% risk free.

For you, what is the best procedure to change this anchor source without loss of connection/identification for the end user (on Office 365 for example)?

Microsoft Security Microsoft Entra Microsoft Entra ID
{count} votes

Accepted answer
  1. Danny Zollner 10,801 Reputation points Microsoft Employee Moderator
    2020-10-28T18:42:18.21+00:00

    It isn't possible to change the sourceAnchor designation without reinstalling AAD Connect, except when doing the predefined path of ObjectGUID to mS-DS-ConsistencyGUID.

    To accomplish this with zero risk, it won't be a simple task, unfortunately. As Alfredo said, your best bet here is to open a support case via portal.azure.com and someone can walk through the options with you.

    1 person found this answer helpful.
    0 comments No comments

3 additional answers

Sort by: Most helpful
  1. Alfredo Revilla - Upwork Top Talent | IAM SWE SWA 27,526 Reputation points Moderator
    2020-10-16T15:27:44.63+00:00

    @G.W to better address your scenario please create a support request.

    1 person found this answer helpful.
    0 comments No comments

  2. G.W 51 Reputation points
    2020-10-15T06:33:13.087+00:00
    0 comments No comments

  3. G.W 51 Reputation points
    2020-11-28T22:04:51.96+00:00

    Thank you for your answers.
    Indeed, it is not possible to change the source without reinstalling the Azure Ad connect on another server.
    I therefore opted for another solution to migrate my users by changing the immutable IDs by scripting.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.