question

HKG-7714 avatar image
0 Votes"
HKG-7714 asked LawrieScott-4908 answered

Question about merging on-premise AD and Azure AD account

I have a user who have both on-premise and azure ad accounts (guest user in Azure). I would like to merge those 2 accounts as both accounts have the same proxy email address and that caused conflict with AD connect sync.

The azure guest account already have resource assigned to it, e.g. O365 group for sharepoint site and etc. If I assign the same immutableid to the on premise ad account, how would that affect the access to the assigned resource? After the merging, the user will be using the on-premise ad account to login. Would that account be able to access the resource that was assigned to the deleted guest account? Do I have to do any adjustment if the access remain the same after the merging?

Thanks

azure-active-directoryazure-ad-connect
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

michev avatar image
0 Votes"
michev answered

Matching guest users against and on-premises object is not a supported scenario afaik.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LawrieScott-4908 avatar image
0 Votes"
LawrieScott-4908 answered

Is the on premise account also a guest account, if so this cannot work, or a different type of account. If that is the case you should be able to assign those resources to the on-prem account and remove the Azure AD guest account. Then AD Connect will sync the on-prem account to the Azure AD account. I stand corrected but this seems like it would work.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.