Azure ad Password write back one Ad domain - two Azure tenants?

Tiberiu Baraboi 1 Reputation point
2020-11-09T19:21:37.19+00:00

Hello,

We configured two Azure AD Connect servers synchronising different user OUs to different azure tenants. Each user object is synhronized only once via Ou filtering and based on distinct UPNs.
We want to enable SSPR on both Azure tenants.

Can you please confirm that SSPR from different tenants will work against the single on prem AD domain as long as each Azure connect service account has appropriate permissions on the OUs filtered for each of the tenant ?

Thank you,

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,582 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Tiberiu Baraboi 1 Reputation point
    2020-11-10T09:31:56.4+00:00

    SSO is disabled. Synch for devices only to one tenant.

    According to documentation AD Connect accounts need permissions for (password) writeback:
    Reset password
    Write permissions on lockoutTime
    Write permissions on pwdLastSet
    Extended rights for "Unexpire Password" on the root object of each domain in that forest, if not already set.

    We want to limit each AD connect account to a subset of the OUs as per the filtering configured during AD connect config.

    It should work but if anyone validated already a similar scenario it will be great having feedback.

    0 comments No comments

  2. TM 1 Reputation point
    2022-01-31T08:49:55.26+00:00

    Hi, did this end up working?

    0 comments No comments