take the following config
On premise AD domain with a UPN suffix of AD.Local
UPN suffix is added for AD.com
Some users are set to use AD.com as their UPN suffix, others are left at AD.local
O365 is configured with a verified doamin of AD.com and the default domain of ad.onmicrosoft.com
in early builds of AADConnect, only accounts with update UPN's of AD,com would be sync'ed.
Now (im not sure exactly when this changed), an account that has AD.local as its UX suffix will be sync'ed and get the default domain suffix in O365... so AD.com
I've searched everywhere i can think of - but i cant find a way to turn this off. We only want accounts with the correct UPN suffix to be sync'ed.... if the UPN suffix is not one matched in O365 - dont sync the account.