MSOL account is the subject user for an AD password change

Ganesan I 5 Reputation points
2024-07-15T10:36:46.1533333+00:00

Hi all,

I have a Entra connect AD setup. In this setup, Azure is only a backup server, where it synchronizes the objects from on-prem AD to Azure AD at a regular frequency.

Whenever I change my password, subject username was "ANONYMOUS LOGON". But recently I noticed MSOL_xxxx account in subject username.

Up to my knowledge, even though this MSOL account has high privileges, it was configured to sync objects alone.

I would be much obliged if anyone explain why this happened?

Thanks in advance.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Windows for business | Windows Server | User experience | Other
{count} votes

1 answer

Sort by: Most helpful
  1. Raja Pothuraju 24,385 Reputation points Microsoft External Staff Moderator
    2024-07-19T22:55:20.43+00:00

    Hello @Ganesan I,

    Thank you for posting your query on Microsoft Q&A.

    You are correct that when an attempt is made from Entra to change a user password, the MSOL_ account is used to write back these changes to on-premises. This is why you are seeing an audit log with that account name.

    SSPR and password writeback are indeed enabled, which allows successful password writeback to on-premises. You can verify this through the Azure Portal as well. Please refer to the following documents for more information:

    Tutorial: Enable self-service password reset

    Tutorial: Enable password writeback for SSPR

    I hope this information is helpful. Please feel free to reach out if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    Thanks,
    Raja Pothuraju.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.