A cloud-based identity and access management service for securing user authentication and resource access
AD account not syncing to AAD
We have a user who someone created their Azure account instead of the on-prem AD account. AD account has been created now but I cannot sync it to Azure or merge the two. Is there a solution to fix this? Confirmed Entra Connector is syncing correctly. ImmutableId in AAD matches on-prem, as does the UPN.
Microsoft Security | Microsoft Entra | Microsoft Entra ID
-
VEMULA SRISAI • 14,065 Reputation points • Microsoft External Staff • Moderator
2025-10-02T21:12:42.1933333+00:00 Hello Chris Housden,
Thank you for posting your question in the Microsoft Q&A Forum.
This situation occurs when a Microsoft Entra ID (Azure AD) account was created in the cloud before the on-premises AD account existed. Even though the UPN and ImmutableId now match, Entra Connect won’t automatically merge them because the cloud account is considered authoritative.
What this means:
- The existing cloud account is “cloud-managed,” so the sync engine sees the on-prem account as a separate object.
- Matching UPN and ImmutableId alone doesn’t force a merge unless the account is in the correct state
The supported way to resolve this is by performing a Hard Match. Hard Match links the existing cloud-only account in Microsoft Entra ID to the on-premises Active Directory account by ensuring that the
ImmutableIdin Entra ID matches the on-premises sourceAnchor attribute (which is typicallyms-DS-ConsistencyGuidor, if not customized, theobjectGUID).Once this match is established, Microsoft Entra Connect will recognize both as the same identity and convert the cloud account into a synchronized account.
For full details, refer to Microsoft’s official guidance:
If this does not meet your situation, please let us know so that we can provide further assistance and ensure that your concerns are fully resolved. We are here to help you with any additional questions or issues.
-
Anonymous
2025-10-03T13:39:15.1333333+00:00 Thank you, That page is where I started. I've ran various scripts to hard match but have had no luck. The AAD account still shows on-premises sync set to no. There is an on-premises ImmutableId listed just below that. The scripts aren't producing errors; they just aren't working.
-
VEMULA SRISAI • 14,065 Reputation points • Microsoft External Staff • Moderator
2025-10-03T20:14:50.6633333+00:00 If the scripts ran without errors but the account still shows “On-premises sync: No,” the hard match didn’t take effect. This usually happens for two main reasons:
- Tenant takeover is blocked – The feature
BlockCloudObjectTakeoverThroughHardMatchEnabledis enabled, so Entra ID refuses to convert the cloud account even ifImmutableIdmatches. - SourceAnchor mismatch – The cloud account’s
ImmutableIdwas set fromobjectGUID, but Entra Connect is usingms-DS-ConsistencyGuid(or vice versa), so the join never happens.
Other causes can include the on-prem object being out of scope or duplicate UPN/SMTP conflicts.
Next steps:
- Disable the takeover block: Turn off the feature
BlockCloudObjectTakeoverThroughHardMatchEnabledif it’s enabled, because it prevents cloud accounts from being converted to synced accounts. - Align the ImmutableId: Make sure the cloud account’s
ImmutableIdmatches the correct sourceAnchor that Entra Connect uses (usuallyms-DS-ConsistencyGuid). - Run a full sync and verify: Start a full synchronization and check in Synchronization Service Manager that the object joins successfully and there are no conflicts like duplicate UPN or SMTP addresses.
- Tenant takeover is blocked – The feature
-
Moses Ater • 0 Reputation points
2025-10-05T11:07:26.09+00:00 Header 1 Header 2 Cell 1 Cell 2 Cell 3 Cell 4 -
VEMULA SRISAI • 14,065 Reputation points • Microsoft External Staff • Moderator
2025-10-06T20:49:09.8633333+00:00 Chris Housden I'm following up on my previous comment. Please let me know if you need any additional details or further clarification.
-
Anonymous
2025-10-07T14:45:56.6166667+00:00 Hi Vemula, I confirmed the ImmutableId matches AD and AAD, but Azure Connect still won't push to AAD, and On-Premises Sync enabled is still set to false. No errors are reported in the Sync service. In fact, it looks as though it successfully synced in Export Statistics, but not populating the user account in Azure
-
VEMULA SRISAI • 14,065 Reputation points • Microsoft External Staff • Moderator
2025-10-09T02:05:49.25+00:00 Chris Housden Thanks for informing,Please provide the details in private message to investigate further.
Sign in to comment