Hi guys, need to get my head around this.
Lets say we have a company that today is only using cloud ids (Azure AD and an exchange online mailbox) and would like to set up an in-premises environment (domain controllers and Azure AD connect, Exchange server).
Is it possible to create new local accounts and have azure ad connect merge them with the azure AD account?
Is it as easy as matching the:
- userPrincipalName (adding correct domain suffix to local AD)
- proxyAddresses (verify that the emailaddresses are the same)
- sourceAnchor/immutableID (specified in the Azure AD Connect setup)
If the on-premises ad accounts have these correct attributes matching the azure AD accounts we are all good and Azure AD connect will find a match and everything is good?
Resetting a local AD password will be executed on the azure ad account (if we use password sync and it has performed a sync)
If we also configure an exchange hybrid lets say if we have an account that needs to be on-prem that will not be an issue?