Azure AD Connect: Synchronize online to on-prem

RELIANET 1 Reputation point


I have the following situation, I have an customer that already has office 365 and a new active directory on Prem will be setup.
I already know that the AD connect only synchronizes on-way.

And most likely will have to do something like the above(maybe powershelgl scripts)

Is there another way to accomplish this using AD connect tool?


Azure Active Directory
Azure Active Directory
An Azure enterprise identity service that provides single sign-on and multi-factor authentication.
13,496 questions
{count} votes

1 answer

Sort by: Most helpful
  1. James Hamil 12,901 Reputation points Microsoft Employee

    From @Vasil Michev :

    synchronization is one-way, from AD to Azure AD/Office 365. There are only few attributes that can be written back, and that's mostly for Hybrid configurations, and passwords if you have the corresponding feature (and licenses) enabled.

    There is no built-in functionality that syncs users from Azure AD to on-premises AD. If that's what you are after, you can simply export the list of users via PowerShell (Get-MsolUser/Get-AzureADUser) or the Graph API, along with any relevant attributes, then use the exported data to recreate them in AD (again, PowerShell helps). You cannot export passwords. Once the export/import is done, you can "match" the on-premises users with the cloud ones and give them the SSO experience. The process is known as soft-match:

    Hope this helps!