Fixing Hybrid-User Sync Issues with Azure AD Connect

Поделиться
HTML-код
  • Опубликовано: 2 мар 2019
  • Fix your synchronization issues with AD Connect by changing your source anchor to the MS-DS-ConsistencyGUID AD attribute.
    01000011 01010010 01000011
    Subscribe: / @securecrc
    Translate_ImmutableID Script:
    blog.jumlin.com/
  • НаукаНаука

Комментарии • 73

  • @NiklasJumlin
    @NiklasJumlin 3 года назад +17

    "MOM! I'm famous!" How I couldn't imagine this script being useful to anyone else but myself.. I'm glad it was useful however! :) Cheers!
    P.S: A friend from the PowerShell community gave me the link to the video

    • @SecureCRC
      @SecureCRC  7 месяцев назад +2

      You're Very welcome. Sorry for the delayed response. You probably don't remember commenting! ;)

  • @alokdubey4085
    @alokdubey4085 4 года назад +8

    This was a brilliant video, cleared some doubts I had from long time. Thank you so much for putting up this video with a live demo.

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      You're Very welcome. Sorry for the delayed response. You probably don't remember commenting! ;)

  • @marksd8310
    @marksd8310 2 года назад +4

    Was stuck, followed so many sites. Came across you're really insightful video. Fixed my issue in a flash. Also what an awesome ImmutableID tool. Thank you so much!

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      You're Very welcome. Sorry for the delayed response. You probably don't remember commenting! ;)

  • @CC-qt6sf
    @CC-qt6sf Год назад +1

    Excellent demonstration and explanation.

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      You're Very welcome. Sorry for the delayed response. You probably don't remember commenting! ;)

  • @hrishikeshchowdhury6987
    @hrishikeshchowdhury6987 4 года назад +1

    Wonderful description. well explained. Thank you.

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      You're Very welcome. Sorry for the delayed response. You probably don't remember commenting! ;)

  • @ivanbravomunoz1305
    @ivanbravomunoz1305 4 года назад +2

    Very well explained. Thank you!

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      You're Very welcome. Sorry for the delayed response. You probably don't remember commenting! ;)

  • @hovhanneshovakimyan
    @hovhanneshovakimyan 3 года назад +1

    Really really good explanation. Thank you!

  • @tatetrick
    @tatetrick 3 года назад

    Exactly what I needed. Thank you.

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      You're Very welcome. Sorry for the delayed response. You probably don't remember commenting! ;)

  • @tbits01
    @tbits01 2 года назад

    Thank you for doing this amazing video. You’re brilliant!!! 😃

    • @SecureCRC
      @SecureCRC  Год назад

      thanks!

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      You're Very welcome. Sorry for the delayed response. You probably don't remember commenting! ;)

  • @Douglas_Hamilton
    @Douglas_Hamilton 3 года назад

    What a great video, thanks!

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      You're Very welcome. Sorry for the delayed response. You probably don't remember commenting! ;)

  • @JoyFos2024
    @JoyFos2024 2 года назад

    Awesome video, thank you!

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      You're Very welcome. Sorry for the delayed response. You probably don't remember commenting! ;)

  • @SigurdurKristofersson
    @SigurdurKristofersson Год назад

    Thank you so much. Great Video.

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      You're Very welcome. Sorry for the delayed response. You probably don't remember commenting! ;)

  • @pajaa133056
    @pajaa133056 3 года назад

    Thank you for your help with this.

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      You're Very welcome. Sorry for the delayed response. You probably don't remember commenting! ;)

  • @bshwjt
    @bshwjt 8 месяцев назад

    Pls make similar kind of tutoriuls. Nice explanation .

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      Thank you. I'll try. I have to be the Jack of All Trades, so sometimes they're not that detailed. I appreciate it!

  • @gtequemo
    @gtequemo 4 года назад

    Hi Joe, great video.
    I can't find the script on the blog.
    Would you please attach the script here and any steps?
    Thank in advanced for your help.

  • @otakuguild5603
    @otakuguild5603 2 года назад

    Excellent video

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      You're Very welcome. Sorry for the delayed response. You probably don't remember commenting! ;)

  • @cmertz112
    @cmertz112 4 года назад

    This video is perfect... thank you!!
    Just one question came up: if I plan to migrate standalone AD and O365/AAD installations to a linked/synced scenario with Azure AD Connect, to make use of SSO functionality, would it be enough to take the ImmutableID, convert it to hex, put it into the MS-DS-ConsistencyGUID and start sync afterwards?

    • @SecureCRC
      @SecureCRC  4 года назад +1

      AD Connect prefers to use the MSDS-ConsistencyGUID over the normal GUID property. Whichever is used, this property becomes the ImmutableID. YOu can look at the AD Connect configuration and see which one it is using by starting the tool and choosing View Configuration. Either property will work for SSO but the msds property is changeable. This "changability" is advantageous if a sync issue creates a duplicate account in Azure. If you're using, GUID now and want to switch to MSDS-ConsistencyGUID, you can use AD Connect to do this. as long as the property is NULL for all users, AD Coonnect will use it. If any user has it populated, AD Connect will not use it. It should not b e populated for anyone. If it is, you can use a powershell script to NULL the values on everyone. Just make sure that some other app isn't using the property for its own use. this would be one reason why the property has a value in the first place.

  • @pkaycr
    @pkaycr 5 лет назад +2

    Thank you so much! I'm grateful for this tutorial.
    Question: I visited the provided website, but I'm confused on how to save the Powershell Script. Any help will be appreciated.

    • @SecureCRC
      @SecureCRC  5 лет назад +1

      Peter Kay, glad you found it helpful.

    • @SecureCRC
      @SecureCRC  5 лет назад

      I just used copy and paste

    • @pajaa133056
      @pajaa133056 3 года назад

      Hey I was able to find a faster way to resolve this issue building on the information in the video.

  • @StreetSmartification
    @StreetSmartification 2 года назад

    Thanks a lot for this awesome video, very informative. Question: is that possible to reverse the process where we get our users from azure for example 20 of them and get it synced to on premise?

    • @SecureCRC
      @SecureCRC  Год назад

      Microsoft has a process called SMTP mapping that might work.

  • @SiBex_ovh
    @SiBex_ovh Год назад

    IdFix in settings have a SearchBase but how use a space for OU, ex: ou=!HQ Poland,ou=Corpo,ou=local ? I try ' or " in differ forms and not work.

  • @hosseinsabouri3121
    @hosseinsabouri3121 4 года назад

    Thanks. Make more videos please

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      You're Very welcome. Sorry for the delayed response. You probably don't remember commenting! ;)

  • @michaelrecinto1784
    @michaelrecinto1784 5 лет назад

    Do device objects use this attribute too? In a hybrid AAD and AD on prem I have users synced, but now we are trying to implement AAD Hybrid Join. I don't see devices in AAD.

    • @SecureCRC
      @SecureCRC  5 лет назад

      No Michael. I believe only User objects can use the msds-consisttncyguid. all other objects will use ObjectGUID property. Make sure the computer objects are in an OU that is being synched by AD Connect.

    • @pajaa133056
      @pajaa133056 4 года назад

      Hey was this resolved? I just completed this and got it working.

  • @brent4770
    @brent4770 3 года назад

    Can you do this in a home virtual network lab for training? I can't figure it out?

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      I have a home lab created with Hyper-v. I have a domain controller installed and other servers/workstations. You can create a DEV tenant with microsoft and get AD Connect to sync the two.

  • @monchurmiah1229
    @monchurmiah1229 Год назад

    Hi I’m having some issues with synchroniza, so when I create an user on ad it’s should show on office 365 but it’s not I can’t add any user into group through ad because of synchroniza any solution.

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      There is a sync services tool on the AD Connect server. look for sync errors. you can see these in the Entra portal also under the Hybrid node. It's probably a sync issue because of more than one account that has a duplicate property like email address.

  • @dhaneswarpokhariyal115
    @dhaneswarpokhariyal115 5 лет назад

    Hi, can we use PTA & PHS method only for few users?

    • @SecureCRC
      @SecureCRC  4 года назад

      you can't do that. you must choose one method for everyone.

  • @ameyraj4947
    @ameyraj4947 2 года назад

    Can We sync the ad group from azure ad group as it is easy to add users in azure ad group. And then sync with ad group on-premise.

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      you can turn on group-writeback in AD Connect wizard

  • @bejaises1
    @bejaises1 3 года назад

    Really great video, pointing me in the right direction, i have a user who was deleted from normal AD(Still showing in Azure AD), showing up in 365 but cant delete the mailbox/hide from GAL, error that the user is synced from on prem AD but there is no on prem AD account anymore ...argh

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      You're Very welcome. Sorry for the delayed response. You probably don't remember commenting! ;)

    • @bejaises1
      @bejaises1 7 месяцев назад

      @@SecureCRC lol yeah, i...think it got resolved :)

  • @emraankhan9921
    @emraankhan9921 2 года назад

    Hello ! I have project about Azure AD Users and On-premises users should sync both Environment like Same users in Cloud and On-premises ! and they will be able to log in different environment with same usermane and password .
    have any solution for that!

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      AD Connect will create the users in both places. user password hash and they'll have the same password. However, the sync is one-way from AD to Entra ID. Not backwards to the on-prem domain.

  • @danielchan713
    @danielchan713 3 года назад +1

    Very useful duplicate account, after ADMT active directory migration.

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      You're Very welcome. Sorry for the delayed response. You probably don't remember commenting! ;)

  • @arpitpeters1986
    @arpitpeters1986 2 года назад

    Please provide the difference between ms-dsi-consistancy-guid and source anchor and immutable ID. Also it's working

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      the guid is the attribute name within on-prem AD. the Immutable ID is the attributes name in Entra ID (Azure AD). the two systems just call it something different. So, Joe's MS-DS-Consistency-GUID (or just Object-GUID) has the same value as his Immutable ID. Since the AD attribute can be one of several things including object guid or ms-ds...guid, we refer to the attribute that we choose for this purpose as the Source Anchor. MS-DS-Consistency-GUID is the most flexible and widely used attribute.

  • @nimesis124
    @nimesis124 2 года назад

    I can see my local AD users in Azure AD but Azure AD users are not synced in local AD

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      AD Connect is a one-way sync. from AD to EntraID (azure AD)

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      AD Connect is a one-way sync from AD to EntraID (Azure AD). it does not sync backward.

  • @axis0401
    @axis0401 2 года назад

    Great video, though correct term is 'on premiseS' ...

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      You're Very welcome. Sorry for the delayed response. You probably don't remember commenting! ;)

  • @Eagle-pe9pg
    @Eagle-pe9pg 4 года назад +3

    Thank you this tutorial was excellent.

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      You're Very welcome. Sorry for the delayed response. You probably don't remember commenting! ;)

    • @SecureCRC
      @SecureCRC  7 месяцев назад

      You're Very welcome. Sorry for the delayed response. You probably don't remember commenting! ;)