MSOL account is the subject user for an AD password change

Ganesan I 0 Reputation points
2024-07-15T10:36:46.1533333+00:00

Hi all,

I have a Entra connect AD setup. In this setup, Azure is only a backup server, where it synchronizes the objects from on-prem AD to Azure AD at a regular frequency.

Whenever I change my password, subject username was "ANONYMOUS LOGON". But recently I noticed MSOL_xxxx account in subject username.

Up to my knowledge, even though this MSOL account has high privileges, it was configured to sync objects alone.

I would be much obliged if anyone explain why this happened?

Thanks in advance.

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,589 questions
Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,517 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,193 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,470 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 144.8K Reputation points MVP
    2024-07-15T10:43:54.5733333+00:00

    Not sure what you mean by "Azure is only a backup server"

    But where are you changing this password , what event logs are you seeing this is and do you have SSPR enabled?

    https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-enable-sspr

    0 comments No comments

  2. Ganesan I 0 Reputation points
    2024-07-16T05:56:26.31+00:00

    Hi Andy,

    Thanks for the reply.

    Yes, I checked the docs and understood that Azure isn't a backup server here, instead Entra connect.

    And I learned that when I change my password with the help of on-prem AD, subject user is ANONYMOUS LOGON. And when I change my password with the help of Azure AD, subject user is "MSOL_xxx" (SSPR with password write back).

    So, SSPR and password write back is enabled.

    Could you confirm whether this is the correct?

    ref: https://www.youtube.com/watch?v=LwHUrH82ntU

    0 comments No comments