On-Premises
22 TopicsWindows AD account password expired but user can still send/receive email and use Teams
Hi. I recently discovered that some users with expired AD passwords are still working as if nothing has changed, which caught me by surprise. All the users affected do not use the VPN on a regular basis, or sign into Office 365. They all use desktop office for their email (Outlook) and chats (Teams). We are all still working from home. It appears as if a user is only challenged to update their expired password once they physically authenticate against the domain controller(s). But what if they never do? This means a user with an expired password will continue to send/receive emails and send chats in Teams regardless of when their password expired, unless they perform some form of "logon". I ran a PowerShell script to elucidate more and found that we have dozens of users in this boat. Some users have passwords that expired YEARS ago! Is this by design? In that the password expiration attribute is pointless until said account actively connects or authenticates to the domain? Why is the "expiration" attribute not part of the user SID? I'm baffled. We have on premise domain controllers which syncs out to Office 365 via ADSync and this is syncing fine with no errors, including password sync. Any help appreciated.Solved30KViews0likes2CommentsAzure AD SSPR Password write back issue
Hi all, A company I work for have issues with the reset password function with AD Connect. In the SSPR audit logs in Azure AD, we face on 'Reset password (self-service)' the status reason 'OnPremisesAdminActionRequired', with a follow up event log within the AD connect server: event ID: 33004 with error "hr=80230626, message=The password could not be updated because the management agent credentials were denied access" I face this issue before and this was causing because the AD DS connector account did not have the right permissions. In this case this is not. What I have done so far: - Updated AD Connect from 2.0.89.0 to 2.0.91.0 - enforced TLS 1.2: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/reference-connect-tls-enforcement - Checked AD DS connecter account 'MSOL_xxxxxxxx' permissions: https://docs.microsoft.com/en-us/azure/active-directory/authentication/troubleshoot-sspr-writeback#verify-that-azure-ad-connect-has-the-required-permissions - the user do not have the options 'password never expires' or 'user cannot change password' configured - Let AD connect talk to another DC dc02 instead of dc01 - Checked connection to SSPR service from DC's : Test-NetConnection -ComputerName ssprdedicatedsbprodscu.servicebus.windows.net -Port 443 - The action 'Change password (self-service)' are successful (via my account portal) , only action 'Reset password (self-service)' face this issue (via passwordreset.microsoftonline.com) -- both use the same OnPremisesAgent ->> AADConnect Have anyone a idea what else I can try more? Regards, RicardoSolved24KViews0likes13CommentsUnfederating Domains
Hi Friends, I need to unfederate 2 domains. I have around 60 users in on-premises and azure. I DO NOT want to change passwords of current Users. I know there is command Convert-MSOLDomainToStandard Can you please explain what is the impact of below command:- Convert-MSOLDomainToStandard –DomainName <federated domain name> -SkipUserConversion $false -PasswordFile c:\userpasswords.txt I will appreciate your great help! Many ThanksSolved15KViews0likes3CommentsAdd Support for Multiple Domains for federation with O365
Hi Team, We currently have ADFS (ADFS is running on Windows 2016) in place for around 100 users auth to 365 using a single domain 'domain1.com', we have federated it and enabled SSO. We now need to federate additional domains - 'domain2.com and domain3.com' The new domains have been added and verified in 365 so now show as managed domains The original domain1.com did not have the -supportmultipldomains switch used when it was converted to a federated domain. What do we need to do here? Should we remove the Microsoft Online trust from AD FS federation server Management Console? and then update original domain . Though, i assume it will be done during non-business hours. Password synch is enabled and we do not want to change passwords of users. What will be the Impact on 100 or more current users of The original domain1.com, if we delete the Microsoft Office 365 Identity Platform entry from our AD FS federation server Management Console? Please explain the impact on the Production Users. Thanks!13KViews0likes3CommentsWhat happens to locked out on premise account, when synced to O365?
Can someone please point me to the articles, i cannot find them online. What happens to locked out on premise account, when synced to O365? Can the user continue to login to O365, send/receive email etc?Solved8.4KViews0likes5CommentsAzureAD Joined Device and onprem w/ PIN
I am working on a scenario where we want to move to Azure ADDS, we still have some need for LDAP/S, Unix, etc but want on prem to go away. Endpoints are already azure AD Joined to the 365 Tenant. Tenant is insync with onprem w/ Azure AD Connect w/ password hash as well... here is where it gets fun...endpoint with password login has no problem accessing onprem file server, but as you know Azure Join Devices force pin enrollment and default to it. When user logs in with PIN, I get cred prompt...eventually this box will goto azure, but I suspect this will occur when it gets out there also... I have attempted AzureAdKerberosServer, oneway trust with AADDS/Local and domain certificate avenue, no love...has anyone gone down this rabbit hole?2.7KViews0likes3CommentsHow to make Skype for Business and OneDrive automatically insert credentials on launch ?
We have a client, that wants new users to sign in to a domain joined computer and automatically get signed in to Outlook, Skype for Business and OneDrive. Now the client has an on-premise Active Directory which is synced with AAD Connect to Office 365. So desktop applications are Office 365. Now, I have configured Seamless Single Sign On feature and configure modern authentications, pushed intranet sites with GPO. This has solved half of the issue, now the users don't have to enter their password, only email. But Outlook and Teams for example already automatically get their email address entered into Sign in Address bars, that can't be said for Skype for Business and OneDrive though, I still need to manually enter email addresses there and let sSSO do it's work. Now my question is this, is it possible to make it so, that all of the remaining applications (Skype for Business and OneDrive) would automatically insert user's email address into Sign in Address (or email address, or user name, etc.) on first launch?2.5KViews0likes7CommentsPassword Write Back not working
We are using Azure AD connector for syncing users accounts from AD > Azure. Now we want to use the write back solution, but we are getting an error, ID 31035. Steps I have already done in Azure AD connect: Use a admin user of the Azure AD Use a special local AD user with right to change password Admin user in Azure AD Ă¡nd the test user have Azure Premium licenses Checked in powershell if PassWordReset is running Disable firewall 'ADFS' server Restarted the service on the 'ADFS' server No luck... Any other solution?2.2KViews0likes2CommentsSeeking advise for Migration On-prem to Office 365
Hi, Our company wants to migrate mailboxes on our on-prem (this mailboxes are used by the application) total of 50 mailboxes. Hope you can guide what migration is the best and safe way to use? In my mind is staged as they would like to do testing first on one mailbox to test if it is working fine with the application using the mailbox is it possible ? Best Regards, Mark Diaz2.1KViews0likes7CommentsAD Sync removal
Hi, Currently working on a local AD forest / domain tear down process and looking to remove the current AD synch process. The forest is currently synchronizing to a multi domain O365 tenant which also has AD Sync running from other domains in a different forest. What is the best safest way to remove AD sync from the legacy Forest / Domain with out impacting the other forest / domains synch process? Looking forward to you advise. Cheers2.1KViews0likes2Comments