New On-Prem AD Won't Sync to existing AAD

Callum Inglis 1 Reputation point
2021-11-22T13:03:13.63+00:00

Hello,

We have a client on Server 2008, with on-prem Active Directory in addition to Azure AD, with Azure AD Connect syncing from AD to AAD.

Users have various licences assigned in AAD, along with teams, outlook (Inc. Shared Mailboxes) and so on.

A new Server 2019 stack has been built, which includes a rebuild of AD. I now wish to sync this new on-prem AD with the existing AAD tenant. The docs suggest this isn't possible, though we need an alternative solution.

Despite meeting the requirements for a softmatch in AD sync (Matching UserPrincipleName & ProxyAddress) i can not get this to work. The error shown is InvalidSoftMatch, "attributeConflictName" is "Mail". I have tried populating the Mail field in local AD to match what's in AAD but this throws a different error that the values must be unique.

If i delete a user in AAD, i can re-sync and this will create a new account in AAD based on the AD values, however mailboxes, onedrive, teams etc etc are not re-mapped.

I have tried setting mS-DS-ConsistencyGuid to the same value as exists in the 2008 AD, and running a sync, but the same errors as shown. mS-DS-ConsistencyGuid is set as the source anchor in both the 2008 and 2019 stacks.

Any advice on the best way forward with this would be greatly appreciated!

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,819 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,381 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 39,336 Reputation points
    2021-12-15T18:50:09.083+00:00

    This article resolves an issue where one or more Active Directory Domain Services (AD DS) object attributes do not synchronize with Azure Active Directory (Azure AD) through the Azure Active Directory synchronization tool.

    Learn more about him in the article below:

    https://learn.microsoft.com/en-us/troubleshoot/azure/active-directory/objects-dont-sync-ad-sync-tool

    ---

    --If the answer is helpful, please vote positively and accept the answer--

    0 comments No comments