{"id":1241,"date":"2014-01-23T19:31:44","date_gmt":"2014-01-23T18:31:44","guid":{"rendered":"http:\/\/sccmfaq.wordpress.com\/?p=1241"},"modified":"2014-01-23T19:31:44","modified_gmt":"2014-01-23T18:31:44","slug":"azure-directory-sync-initial-configuration","status":"publish","type":"post","link":"https:\/\/blog.hosebei.ch\/?p=1241","title":{"rendered":"Azure Directory Sync Initial Configuration"},"content":{"rendered":"<p>When you are implementing Windows Intune with SCCM, you always come to the Point, where you got to install Azure Directory Synchronization, otherwise you will need to create your user account manually, and the users have also to manage two Passwords for their user account, one for on-premise and one for the cloud.<br \/>\nTwo big questions in this Topic is, what attributes will be synchronized and from which objects?<br \/>\nThe other part is how to manage the Password, either with ADFS or Password synchronization?<!--more--><\/p>\n<p>I would strongly recommend to read the TechNet article about Azure Directory Synchronization carefully (http:\/\/technet.microsoft.com\/en-us\/library\/jj573653.aspx).<br \/>\nSo the process of installing and configuring a DirSync is quite simple when you follow the available Guidelines. It is well described and really depends on your needs and Infrastructure (Multi Forest Design etc.) where and what kind of Software you need to install. But be aware of the last Screen, when you run the Windows Azure Active Directory Sync tool Configuration Wizard:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2014\/01\/azuredirsync01.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2014\/01\/azuredirsync01.png?w=300\" alt=\"End of Wizard\" width=\"300\" height=\"215\" class=\"aligncenter size-medium wp-image-1242\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2014\/01\/azuredirsync01.png 623w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2014\/01\/azuredirsync01-300x216.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nBe sure that you have unchecked the &#8220;Synchronize your directories now&#8221; box, otherwise the entire Directory will be synchronized. You can sync the directories afterwards through powershell or running the wizard again. Because after the configuration is done through the wizard, the initial configuration is not as what we need, so we don&#8217;t want to sync.<br \/>\nTo modify the initial configuration, navigate to the Installation path of the DirSync tool, and start miisclient.exe:<br \/>\n&#8220;C:Program FilesWindows Azure Active Directory SyncSYNCBUSSynchronization ServiceUIShellmiisclient.exe&#8221;<br \/>\nThis will open the Forefront Identity Manager Console, where you can check the config, and change it if wanted. The most common change is to select one or more specific Organizational Unit to sync with Azure Directory. You can achieve this, by clicking on &#8220;Management Agents&#8221;:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2014\/01\/azuredirsync02.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2014\/01\/azuredirsync02.png?w=300\" alt=\"FIM Console Management Agents\" width=\"300\" height=\"92\" class=\"aligncenter size-medium wp-image-1245\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2014\/01\/azuredirsync02.png 572w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2014\/01\/azuredirsync02-300x92.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nIn the list of the Management agents, double-click the &#8220;Active Directory Connector&#8221; entry:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2014\/01\/azuredirsync03.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2014\/01\/azuredirsync03.png?w=300\" alt=\"Active Directory Conector FIM\" width=\"300\" height=\"90\" class=\"aligncenter size-medium wp-image-1247\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2014\/01\/azuredirsync03.png 577w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2014\/01\/azuredirsync03-300x91.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nThis will open the properties of this connector, and you have to navigate to &#8220;Configure Directory Partitions&#8221; and click on the &#8220;Containers &#8230;&#8221; button:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2014\/01\/azuredirsync04.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2014\/01\/azuredirsync04.png?w=300\" alt=\"FIM AD Connector Partition\" width=\"300\" height=\"225\" class=\"aligncenter size-medium wp-image-1249\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2014\/01\/azuredirsync04.png 670w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2014\/01\/azuredirsync04-300x225.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nYou will be asked for Domain credentials, the account which is shown was created when the wizard was run, thus you don&#8217;t know the Password. But you can simply use your credentials to connect to the AD. After this authentication, the following window is shown, where you can select or deselect OUs:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2014\/01\/azuredirsync05.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2014\/01\/azuredirsync05.png?w=300\" alt=\"Select OU in FIM AD Connector\" width=\"300\" height=\"289\" class=\"aligncenter size-medium wp-image-1251\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2014\/01\/azuredirsync05.png 451w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2014\/01\/azuredirsync05-300x289.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>An other way to reduce the number of synced object is to exclude objects based on an Attribute. For this, you have to navigate to &#8220;Configure Connection filter&#8221; and select the object which you want to configure, in my case &#8220;user&#8221; and click on &#8220;new&#8221;:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2014\/01\/azuredirsync06.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2014\/01\/azuredirsync06.png?w=300\" alt=\"DirSyncExlcusions\" width=\"300\" height=\"225\" class=\"aligncenter size-medium wp-image-1253\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2014\/01\/azuredirsync06.png 669w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2014\/01\/azuredirsync06-300x225.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nYou might recognize that there are already some entries in this list. In the &#8220;Filter for user&#8221; wizard, choose your Attribute, in my case &#8220;ExtensionAttribute13&#8221;, and define the rule &#8220;Equals NotForNSA&#8221;. All accounts that match this rule, will not be synced to Azure Directory:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2014\/01\/azuredirsync07.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2014\/01\/azuredirsync07.png?w=300\" alt=\"Filter for User\" width=\"300\" height=\"236\" class=\"aligncenter size-medium wp-image-1254\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2014\/01\/azuredirsync07.png 569w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2014\/01\/azuredirsync07-300x236.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nClick on &#8220;Add Condition&#8221; and Close the Windows by clicking on OK twice.<\/p>\n<p>Now you have set your Definition of what will be synchronized. Now we come to the which attributes part.<br \/>\nLet me say first, when you look at the list for the first time, it&#8217;s quite amazing how many attributes are selected by Default, but really necessary are only a few. I would not recommend to deselect some attributes. But if you want to, you can, except these 5:<br \/>\n-cn<br \/>\n-member (applies only to groups)<br \/>\n-samAccountName (applies only to users)<br \/>\n-alias (applies only to groups and contacts)<br \/>\n-displayName (for groups with an mail or proxyAddresses attribute populated)<br \/>\nRefer to this article for more Information about the attributes: http:\/\/support.microsoft.com\/kb\/2256198\/en-us<br \/>\nThis article contains also Information about the Attribute used in an Exchange Hybrid deployment, and which Attribute are used for read only, and which one are also written back from the Azure Directory to the On-Premise.<br \/>\nYou can also get those Information by looking at the &#8220;Configure Attribute Flow&#8221; section in this wizard (As example a small list from the user):<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2014\/01\/azuredirsync08.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2014\/01\/azuredirsync08.png?w=300\" alt=\"Attribute Flow\" width=\"300\" height=\"224\" class=\"aligncenter size-medium wp-image-1257\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2014\/01\/azuredirsync08.png 671w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2014\/01\/azuredirsync08-300x225.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>So, the most important things are configured now, you can start your synchronization, as said, you can go through the wizard again, or use powershell:<br \/>\n<code>Add-PSSnapin Coexistence-Configuration<br \/>\nStart-OnlineCoexistenceSync<\/code><br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2014\/01\/azuredirsync10.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2014\/01\/azuredirsync10.png?w=300\" alt=\"Start Azure Directory synchronization with powershell\" width=\"300\" height=\"167\" class=\"aligncenter size-medium wp-image-1258\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2014\/01\/azuredirsync10.png 569w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2014\/01\/azuredirsync10-300x168.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nYou should receive a success Status on your operation, see Picture above.<\/p>\n<p>Hope this helps someone \ud83d\ude42<br \/>\nMartin<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When you are implementing Windows Intune with SCCM, you always come to the Point, where you got to install Azure Directory Synchronization, otherwise you will need to create your user account manually, and the users have also to manage two Passwords for their user account, one for on-premise and one for the cloud. Two big [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"class_list":["post-1241","post","type-post","status-publish","format-standard","hentry","category-byod"],"_links":{"self":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/1241","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1241"}],"version-history":[{"count":0,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/1241\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1241"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1241"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1241"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}