Hello O365 experts,

I am in the preparation stages for Office 365 deployment for about 25 users. All users are in single forest, single domain on Windows 2012R2 and we run Exchange 2010 SP3 on Windows 20082.Since our local AD has a non-routable suffix (ourdomain.lan).

I plan to first add alternative UPN suffix (ourdomain.com) and then change all the user logins to that new suffix (adam@ourdomain.lan to adam@ourdomain.com)…

Our Exchange server emails are in first.last@ourdomain.com format.

We plan to subscribe to the Business Premium plan which includes Exchange Online.

From what I understand, to improve user experience with a Same-Sign-On, we will need to setup Azure AD Connect.

I’d like to know if it’s possible to limit synchronization to password only. All AD management should be local - no other integration with Azure AD.

Question(s):

  1. Which synchronization options must be configured in Azure AD Connect if all we want to do is a one-way password synchronization (Same-Sign-On)?
  2. Will domain users who currently login with domain\user be able to access O365 transparently (not be prompted again for first.last@domain.com login)

I did see Azure AD Sync just password for O365 - it dates back to May 2017 and and does not answer Question 2.

Thank you for ANY pointers on this - there is a massive amount of documents on MS O365 site and questions posted there seem to remain either not answered or answered after many weeks/months.

2 Spice ups
Which synchronization options must be configured in Azure AD Connect if all we want to do is a one-way password synchronization (Same-Sign-On)? 

I think Microsoft ADFS will do your requirement. Single your requiremnt is based on Single Sign On than Same Sign On

Thanks for the suggestion but AD federation is exactly what we want to avoid.

I was looking to determine which Options must be configured, and which should be disabled, at the initial setup of AD Connect to allow for Same-Sign-On (not Single-Sign-On).

We want to avoid AD integration to Azure AD as much as possible.

ADConnect will allow you to select the attributes you want to sync but by default, most/all of what it syncs you want - DL memberships, proxy addresses, many attributes you want for the GAL - display name and so forth.

Really no reason to unselect any of that.