How to setup azure ad connect password sync, password write back, and single signon so users only need to change password at on premises domain

frrpd 0 Reputation points
2023-08-25T16:01:09.71+00:00

I have setup Azure AD connect. I have pass through authenication turned on, I have password hash turned on I also have write back turned on. I have troubleshooted some steps with the Azure AD Connect trouble shooter and the connectivity to the local domain and to azure ad checks out just fine. However when i change my password locally from ad for testing purposes I wait the 2 mins and then try the password at office.com and it does not work. Please help.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. Andy David - MVP 159.7K Reputation points MVP Volunteer Moderator
    2023-08-25T16:25:14.19+00:00

    You cant use Password Hash Sync and Pas through Auth at the same time. You would have to disable password pass through and switch to PHS auth via AADConnect

    https://learn.microsoft.com/en-us/azure/active-directory/hybrid/connect/choose-ad-authn

    User's image

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.