Share via

New OnPrem AD Sync

Kent Söderlund 21 Reputation points
2023-09-02T13:07:23.5066667+00:00

OK! I screwed up....

I have a demo environment with OnPrem AD and AAD.

Now I will totally rebuild the OnPrem environment with a new AD. The issue is that I want to sync that with my old AAD so I dont have build a new one, and they also have to same domain name

Can I delete my old AD domain from AAD and sync AAD to my new AD domain. Have search like a idiot but dont find a solution :( Any help very appreciated

/kent

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Answer accepted by question author
  1. Shweta Mathur 30,451 Reputation points Microsoft Employee Moderator
    2023-09-05T06:42:40.1466667+00:00

    Hi @Kent Söderlund ,

    I'm glad that you were able to resolve your issue and thank you for posting your solution so that others experiencing the same thing can easily reference this! Since the Microsoft Q&A community has a policy that "The question author cannot accept their own answer. They can only accept answers by others", I'll repost your solution in case you'd like to "Accept" the answer.

    User's image

    1 person found this answer helpful.
    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Kent Söderlund 21 Reputation points
    2023-09-03T10:43:27.3266667+00:00

    SOLVED!

    The user that AD Sync creates gets automatically MFA requirements. That policy have to be disabled during the installation

    0 comments No comments

  2. JimmySalian-2011 45,231 Reputation points
    2023-09-02T17:59:14.9233333+00:00

    Hi,

    This is known as multiple forest and single AAD Connect configuration - so in your case you can add new AD Domain that you are rebuilding and sync it across to AAD, remove the old AD Domain from the configuration.

    https://learn.microsoft.com/en-us/azure/active-directory/hybrid/connect/plan-connect-topologies

    Sync back is only for attributes and passwords, you can setup local AD with users and groups from AAD, the reason you cannot find solution is that it is not available to rebuild the AD Domain from AAD, you should have backup and snapshot of the AD as this is proper way to restore AD.

    Hope this helps.

    JS

    ==

    Please accept as answer and do a Thumbs-up to upvote this response if you are satisfied with the community help. Your upvote will be beneficial for the community users facing similar issues.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.