Quantcast
Channel: Azure Active Directory forum
Viewing all 16000 articles
Browse latest View live

Self service Password Reset is available to everyone!

$
0
0

Hi,

This is noticed at a EMS customer where the even the users with license unassigned get to register for password reset and verify.

Settings in the Azure portal are as follows;

Users enabled for password reset : YES

Restrict access to password reset : NO

Authentication methods available and required.

Require users to register when signing in to the access panel : YES

problem is that users without EMS licence assigned also get to register for password reset (including the global admin of the tenant :O)

Can anyone tell me where it has gone wrong?


Sync users to Office 365

$
0
0

Hi

I have setup dirsync but i unchecked the "sync directories now" at the end of the configuration as i wanted to edit and exclude some users to be synced

Now i have made these exclusions i have run a Full Import Full Sync on Active Directory Connector, it has been successful, but not seeing the users in Office 365. do i also need to run a full sync on "Windows Azure Active Directory Connector"?

Thank You

User Write Back deletes users from Azure

$
0
0
Hi I am doing a merge of two active directory forests into a 3rd. I can connect each of the legacy forests into Azure with no issues. However, when I add in the new AD that I want to write back users too I had to create a custom sync rule to populate the new forest. That works but as soon as the users sync with no errors their accounts get deleted from Azure which breaks the password sync. I've monitored the sync and at first everything gets joined together correctly but then the Azure join just disappears and the users are removed. I've tried to create some more custom sync rules to fix it but the accounts still get deleted. I did discover that if I remove the write back domain the account show up in Azure again. Any suggestions to stop this from happening?

SSO - Newton Recruiting

$
0
0
We are trying to utilize SSO with Newton Recruiting.  We are trying to utilize the Password Single Sign On option, but when clicking on the icon as an end user, the login does not take place.

New Azure AD only has role User

$
0
0

Hi,

I've just created a new Azure Active Directory using the Azure Portal and it has set the role to 'User' so I don't have permission to do anything with it. I can't even delete it. I just get the following message on all the tabs.

You do not have permission to access these resources.

Any suggestions?

Richard

Deleted AD Users not Deleted from AAD following Delta Sync?

$
0
0
Currently, when AD users are deleted on-prem and we run our delta sync, we're noticing that users are not being deleted from AAD.However, if we run a full sync, the users get deleted. Any thoughts on why this could be? We have no made any modifications based on attribute filtering from the default. We are doing this using AAD Sync.

Nested Group in Security Filtering

$
0
0

Hi is nested Groups for the Last Version von ADConnect supported?

It installed ADConnect and set the Filter of a specific Sec.Group everthing works fine, the Members of this Group are synced.

But a specific Group is also Member of this Group but this Users doesn't sync.

Example:

Group 1

- User1 (Member of Group 1)

- User 2 (Member of Group 1)

- Group 2 (Member of Group 1)

-- User 3 (Member of Group 2)

-- User 4 (Member of Group 2)

User 1 and 2 are Synced, but User 3 & 4 doesn't

i dont find any offical statement

Password Sync failed after sync, only password reset/change fix it

$
0
0

Hi, i setup a running deployment with ADConnect (Last GA Version) with Filtering with Security Group.

If i ad a User to the specific Security Group, 3h later the Delta Sync, sync my user to the AAD but the Password doesn't sync, so the user are unable to authenticate on portal.manage.micrsoft.com.

I have to change the Password from the User (onPrem), than i got the 611 EventID and the Sync/Logon works.

Thanks for help


Report for last logged in time for Azure Users

$
0
0

Hi Guys,

I read on the report feature provided by Azure Active Directory here and I couldn't find any report that I can trace how long have my users not logged in via AAD.

Reason for this is to do regular checking and to clean up our AAD. We want to set a policy to remove user's login if you have not logged in for xx number of day.

There is a similar report under user-specified category but it only generate the individual sign in activity. What we need to have is a report as a whole.

Is there any way that we can churn out this type of report?


Cheng

Validate User Using C# Programatically

$
0
0

Dear Team,

I have created  active directory in Microsoft azure .  I want to validate that  user  using c# when username and password takes as input and token as output. Please let me know what are the limitations and any c# code available .



Programming is like kicking yourself in the face, sooner or later your nose will bleed.

Retrieve AAD user from local AD user info?

$
0
0
Is there a way to programmatically retrieve an Azure AD user ID from the local AD user's SID if they are connected via AAD Connect with Password Sync?

how to know the synchronization is finished when using dirSync

$
0
0

Hi,

I plan to use powershell to force the directory sync. However there is a problem bothers me, which is how to know the synchronization is done? Is there any programmatic way to know it except go to UI to check?

Thanks.

Webex SSO with Azure

$
0
0

Getting the following error after setting up Federation between Azure and WebEx for SSO:

Correlation ID: 3264cbb6-76b2-4775-98ee-6f62d4f132ef

Timestamp: 2015-07-30 22:39:30Z

AADSTS70001: Application with identifier https://<company>.webex.com was not found in the directory b4223cf7-a39d-438f-b6df-050524c92e81

What am I doing wrong?

Potential Bug for Win 10 and AzureAD

$
0
0

From Gareth Roberts - @swgr25 via Twitter

Customer is having an issue with adding a workplace account on Windows 10. He tried 3 computers and it only worked on one of them. Might be a bug because customer cannot connect to other PC's after clean install.

aka.ms/keywu9

Thank you,

@AzureSupport

Azure AD Connect with unowned publically routable domain

$
0
0

We are soon to pilot Office 365 and wish to extend our Active Directory domain into Office 365.  Our domainis a publically routable domain, but it just so happens our company is not the Registrant for that domain. (I know, you're all cringing)  The chances of us registering that domain is slim to none.

Will our situation present a hurdle or road-block to extend our domain into Office365?

Thanks for the guidance.


Change password feature

$
0
0

Hi,

I need something clarified.Our company uses ADFS and SCCM together with Intune.

So we use on-prem. AD.

We use the Company Portal app on IOS for our iphones. Everything is working fine.So here is my question:

In order to use the Change Password option for a user in de Comp. Portal app we need Azure AD Premium?

Am I correct? 

connect-msolservice Error:Microsoft.Online.Administration.Automation.MicrosoftOnlineException

$
0
0
I have Microsoft azure subscription.
I am a co-administrator of the subscription.
I installed  Azure Active Directory Module dor Windows Powershell (64-bit version) 
I imported module using import-module MSOnline
My version is 1.0.8362.1

I want to mange Azure Active directory services.

But, to connect that when i type "connect-msolservice", it prompts for the credential.
I put it this way abc@test.onmicrososft.com and a valid password.
Using the same credential i am able to login to my subscription.
This is also a global admin user of the AD i created in the azure.

Still, I get this error
connect-msolservice : Exception of type 
'Microsoft.Online.Administration.Automation.MicrosoftOnlineException' was thrown.

Kindly suggest for the possible change i need to make.

Authenticate MVC website using Office 365 API through Azure Active Directory without prompting for a user log-in.

$
0
0

My public-facing MVC website collects user data through a form and after some data processing needs to perform a direct send of an email to the Office 365 email address, meaning SMTP relay is not an option here. The site is completely open to the public and doesn't need any pages secured. I figured that I can use Office 365 API to send emails, but I want to avoid using SMTP relays and prompting for a user log-in. Basically, I need the website to be authenticated as the user programmatically, thus avoiding redirection to the Azure AD login page.

Is it possible? If so, then how?

Windows Azure Active Directory

$
0
0

Hello,

Is it possible to put AD on Azure only? There will be no AD on-premise and on-premise desktops and laptops will be authenticating against Azure AD.

Existing Azure AD users syncing to on-premises AD server (feasible?)

$
0
0

Hi Techies,

Long story short, we never had an on-premises AD server until now. For the past year, we've only had Office 365 exchange online accounts, with this, we also setup Windows Azure AD online.

Question: All (25) users accounts are currently online. I want to run the Azure AD sync tool on the on-premises server so I can start syncing user accounts. Is this possible? I have no users (besides all the default ones, local admin, etc) on my "on-premises" server and was hoping the existing users online would sync down to our local server.... Will this work? 

Also, I am concerned that if I run the Azure Sync tool on my local server it will erase existing azure AD accounts online, since they don't exist on the local server. Not the case right?

Thank you for any help!


Viewing all 16000 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>