Password Has Removal from Azure AD

RST 86 Reputation points
2020-08-26T18:43:23.8+00:00

Hi Team,

If I disable PHS in AADC server, does it remove all the password hashes (already synched) from Azure AD or the hash still there even though not using it?

I am testing PHS with staged rollout and if I wanted to rollback, need to ensure hash also gets purged from AAD, and how do we validate its actually purged.

Thank in advance Team!

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,543 questions
{count} votes

Accepted answer
  1. Andy David - MVP 142.2K Reputation points MVP
    2020-08-29T11:49:18.113+00:00

    The only way would probably be to remove and purge any of the Azure Accounts you staged the roll-out with.
    If that is not possible, then change their passwords after the rollback and it wont matter.

    Regardless, I would not be concerned, honestly. Those hashes cant be used other than in Azure - for those accounts.

    https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-password-hash-synchronization

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. RST 86 Reputation points
    2020-09-01T11:45:42.653+00:00

    Thank you JamesTran-MSFT & AndyDavid -I guess thats the only option as the hash can't be used furhters other than Azure AD.

    Quick check though I have selected users in the staged roll out, the password synch applies to all the users defined in AADConnect scope, and their password hash will be reamin in Azure AD, is it