No sign on options for domain users synced with AD Connect after changing from federated to managed domain

Don Shappelle 11 Reputation points
2022-07-02T22:33:53.24+00:00

Hi:
I had the hybrid configuration working fine, with certain OUs syncing, and my users, computers, and groups all proper. Password hash sync was working and my domain users were syncing to azure ad without issue.

Then, I converted to federated domain with ADFS (I should not have) while testing in my lab. I switched back to managed but now my domain users, when attempting to access cloud resources, are given no sign options, only a logon screen after entering UPN that says "Choose a way to sign in" which is blank.

Sync is still working because I created a new user in the synced OU and ran the sync successfully, with the user account visible in Azure AD. However, attempts to use the account to auth to something like AVD, for example, result in the empty "Choose a way to sign in" screen.

What am I missing to get the password (and eventual MFA requirement) back for these user accounts? Accounts I created in the cloud only are fine.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} vote

2 answers

Sort by: Most helpful
  1. T. Kujala 8,766 Reputation points
    2022-07-03T02:03:00.723+00:00

  2. James Hamil 27,221 Reputation points Microsoft Employee Moderator
    2022-07-05T19:25:50.447+00:00

    Hi @ DonShappelle-7845 , following up on your reply I wanted to post some more details here. After changing settings or syncing it usually takes up to an hour for everything to propagate. In the event that nothing updates within an hour usually means something is broken but yours isn't!

    If this answer helped you please mark it as "Verified" so other users can reference it.

    Thank you,
    James

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.