So we do everything via O365 for most part right now, I want to sync the passwords so users can change that themselves. Is Azure AD Connect the way to go, please assist with how to only get passwords to sync with this so users can change themselves via ctrl alt del.<\/p>","upvoteCount":8,"answerCount":20,"datePublished":"2019-07-08T18:03:15.000Z","author":{"@type":"Person","name":"dontworryok","url":"https://community.spiceworks.com/u/dontworryok"},"suggestedAnswer":[{"@type":"Answer","text":"
So we do everything via O365 for most part right now, I want to sync the passwords so users can change that themselves. Is Azure AD Connect the way to go, please assist with how to only get passwords to sync with this so users can change themselves via ctrl alt del.<\/p>","upvoteCount":8,"datePublished":"2019-07-08T18:03:15.000Z","url":"https://community.spiceworks.com/t/sync-ad-passwords-to-o365/719889/1","author":{"@type":"Person","name":"dontworryok","url":"https://community.spiceworks.com/u/dontworryok"}},{"@type":"Answer","text":"
Azure AD Sync is the correct way to synchronize your local AD users and passwords with O365. Then any changes to local credentials will replicate over to AzureAD (and O365).<\/p>\n
Caveat is that any changes to the email user profile will need to be made in AD (I prefer this because it brings most of the user management to ADUC).<\/p>","upvoteCount":1,"datePublished":"2019-07-08T18:25:22.000Z","url":"https://community.spiceworks.com/t/sync-ad-passwords-to-o365/719889/2","author":{"@type":"Person","name":"pbrain","url":"https://community.spiceworks.com/u/pbrain"}},{"@type":"Answer","text":"
If you set up write back they can also change their password online and have it sync back to AD as well.<\/p>","upvoteCount":0,"datePublished":"2019-07-08T18:41:13.000Z","url":"https://community.spiceworks.com/t/sync-ad-passwords-to-o365/719889/3","author":{"@type":"Person","name":"alex3031","url":"https://community.spiceworks.com/u/alex3031"}},{"@type":"Answer","text":"
Juanoflo is correct. However, Azure AD will not JUST bring the passwords. Your active AD users will be brought into your O365 account as well. Then, you will have to assign mailboxes to those people. Usually, its just as easy as making sure all the email information in your AD is their actual email address. Its pretty easy. Then those that don’t have email accounts will just show up as unlicensed in the O365 account. Its very simple and easy to use once it is setup. The only difficulty you will have is the possibility that some accounts won’t match up to the already-existing email accounts in O365. That will just take some fine tuning and is very easy to correct.<\/p>","upvoteCount":0,"datePublished":"2019-07-08T18:41:54.000Z","url":"https://community.spiceworks.com/t/sync-ad-passwords-to-o365/719889/4","author":{"@type":"Person","name":"derekswitzer","url":"https://community.spiceworks.com/u/derekswitzer"}},{"@type":"Answer","text":"
So on the micro admin page for active users, all users are showing twice, one with normal domain and other with the onmicrosoft one, how can I remove those and just keep the regular domain ones.<\/p>\n
Also, i tested it and my password is changing on the laptop if I do ctrl alt del as well as in on premise AD, but how can I get that to sync to O365 and all.<\/p>","upvoteCount":0,"datePublished":"2019-07-08T19:28:44.000Z","url":"https://community.spiceworks.com/t/sync-ad-passwords-to-o365/719889/5","author":{"@type":"Person","name":"dontworryok","url":"https://community.spiceworks.com/u/dontworryok"}},{"@type":"Answer","text":"
You will need to merge the onmicrosoft ones with the others. I believe this is what you will need to follow:<\/p>\n
https://www.codetwo.com/admins-blog/how-to-merge-an-office-365-account-with-an-on-premises-ad-account-after-hybrid-configuration/<\/a><\/p>","upvoteCount":1,"datePublished":"2019-07-08T19:33:16.000Z","url":"https://community.spiceworks.com/t/sync-ad-passwords-to-o365/719889/6","author":{"@type":"Person","name":"derekswitzer","url":"https://community.spiceworks.com/u/derekswitzer"}},{"@type":"Answer","text":" I have to follow this for every single user? Is there a way to re-sync it with Azure tools so it doesnt do this?<\/p>","upvoteCount":0,"datePublished":"2019-07-09T11:38:09.000Z","url":"https://community.spiceworks.com/t/sync-ad-passwords-to-o365/719889/7","author":{"@type":"Person","name":"dontworryok","url":"https://community.spiceworks.com/u/dontworryok"}},{"@type":"Answer","text":" You need to create an alternate UPN suffix in your AD that matches your email domain and assign that as primary for each user. If not, those “onmicrosoft” accounts will be created. The change will be seamless to the user, they can still log in locally via their normal method and will now have the ability to logon as [email protected]<\/a> if they wish.<\/p>\n