New OnPrem AD Sync

Kent Söderlund 21 Reputation points

OK! I screwed up....

I have a demo environment with OnPrem AD and AAD.

Now I will totally rebuild the OnPrem environment with a new AD. The issue is that I want to sync that with my old AAD so I dont have build a new one, and they also have to same domain name

Can I delete my old AD domain from AAD and sync AAD to my new AD domain. Have search like a idiot but dont find a solution :( Any help very appreciated


Azure Active Directory
Azure Active Directory
An Azure enterprise identity service that provides single sign-on and multi-factor authentication.
16,535 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
4,843 questions
0 comments No comments
{count} votes

Accepted answer
  1. Shweta Mathur 19,546 Reputation points Microsoft Employee

    Hi @Kent Söderlund ,

    I'm glad that you were able to resolve your issue and thank you for posting your solution so that others experiencing the same thing can easily reference this! Since the Microsoft Q&A community has a policy that "The question author cannot accept their own answer. They can only accept answers by others", I'll repost your solution in case you'd like to "Accept" the answer.

    User's image

    1 person found this answer helpful.
    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. JimmySalian-2011 36,371 Reputation points


    This is known as multiple forest and single AAD Connect configuration - so in your case you can add new AD Domain that you are rebuilding and sync it across to AAD, remove the old AD Domain from the configuration.

    Sync back is only for attributes and passwords, you can setup local AD with users and groups from AAD, the reason you cannot find solution is that it is not available to rebuild the AD Domain from AAD, you should have backup and snapshot of the AD as this is proper way to restore AD.

    Hope this helps.



    Please accept as answer and do a Thumbs-up to upvote this response if you are satisfied with the community help. Your upvote will be beneficial for the community users facing similar issues.

  2. Kent Söderlund 21 Reputation points


    The user that AD Sync creates gets automatically MFA requirements. That policy have to be disabled during the installation

    0 comments No comments