Question about merging on-premise AD and Azure AD account

HK G 516 Reputation points
2022-05-06T22:38:18.593+00:00

I have a user who have both on-premise and azure ad accounts (guest user in Azure). I would like to merge those 2 accounts as both accounts have the same proxy email address and that caused conflict with AD connect sync.

The azure guest account already have resource assigned to it, e.g. O365 group for sharepoint site and etc. If I assign the same immutableid to the on premise ad account, how would that affect the access to the assigned resource? After the merging, the user will be using the on-premise ad account to login. Would that account be able to access the resource that was assigned to the deleted guest account? Do I have to do any adjustment if the access remain the same after the merging?

Thanks

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. Vasil Michev 119.9K Reputation points MVP Volunteer Moderator
    2022-05-07T10:58:01.403+00:00

    Matching guest users against and on-premises object is not a supported scenario afaik.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Lawrie Scott 1 Reputation point
    2022-05-07T11:05:51.67+00:00

    Is the on premise account also a guest account, if so this cannot work, or a different type of account. If that is the case you should be able to assign those resources to the on-prem account and remove the Azure AD guest account. Then AD Connect will sync the on-prem account to the Azure AD account. I stand corrected but this seems like it would work.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.