如何在Azure AD for Office 365和内部部署AD用户上集成现有用户? [英] How can I integrate the existing users on Azure AD for Office 365 and on-premise AD users?

查看:145
本文介绍了如何在Azure AD for Office 365和内部部署AD用户上集成现有用户?的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!

问题描述

在我的组织中,我们使用的是Office 365.我们的许可证是Office 365 Business。

In my organization, we have used Office 365. Our license is Office 365 Business.

现在我想要同步Azure AD和我们的内部部署AD。  我的前任过去试图这样做,并放弃了。 因此,Azure AD中的每个实际用户都有2个用户。

Now I'd like to sync Azure AD and our on-premise AD.  My predecessor tried to do this in the past, and gave up.  So there are 2 users for each actual user in Azure AD.

例如

Masahiro Tanaka  (ID:masahiro_tanaka @ myorg.com,来源:Azure Active Directory)

Masahiro Tanaka  (ID: masahiro_tanaka@myorg.com,  source: Azure Active Directory)

Masahiro Tanaka  (ID:masahiro_tanaka @ myorg.onmicrosoft.com,来源:Windows Server AD)

Masahiro Tanaka  (ID: masahiro_tanaka@myorg.onmicrosoft.com,  source: Windows Server AD)

有没有办法整合它们?

推荐答案

Hello Masahiro,

Hello Masahiro,

第一次设置AD连接时,可以合并帐户。您必须按照 中说明的步骤进行操作这个

doc
以便匹配发生并且帐户合并。

Merging of accounts is possible when you are setting up AD connect for the first time. You would have to follow the steps explained in  this doc so that the match happens and accounts are merged.

在您的方案中,因为您已将帐户同步到azure AD,

In your scenario, as you already have the accounts synced to azure AD,

1)您必须删除@ myorg.onmicrosoft.com帐户。 (您可以在AD连接配置中从范围过滤器中删除OU)

1) you would have to delete the @myorg.onmicrosoft.com accounts. (you can do this removing the OU's from scoping filter in AD connect configuration)

2)确保云中没有重复的帐户。

2) Ensure that there are no duplicate accounts in cloud.

3)确保硬匹配/软匹配所需的条件(在此
中解释
doc
)由内部部署帐户满足。

3) Ensure that the conditions required for hard match / soft match (explained in this doc) are met by the on-premise accounts.

4)创建一个测试OU并将一个用户移动到此OU

4) create a test OU and move one user to this OU

5)将此OU添加到同步范围

5) add this OU to the sync scope

6)确保正在进行合并和重复帐户没有被创建

6) ensure that merging is happening and duplicate accounts are not getting created

7)最后将剩余的OU添加到同步范围 

7) Finally add the remaining OU's to sync scope 


这篇关于如何在Azure AD for Office 365和内部部署AD用户上集成现有用户?的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!

查看全文
登录 关闭
扫码关注1秒登录
发送“验证码”获取 | 15天全站免登陆