Skype for Business本地迁移Teams:HybridOnpremSfbUser用户无法创建Teams
Hey Marius, I’ve dealt with this exact stubborn leftover Skype for Business attribute issue before— let’s walk through actionable steps to get those two users unblocked:
Step 1: Verify Azure AD User Attributes First
Even after cleaning up AD, Azure AD might still hold onto old SfB metadata. Use these PowerShell commands to check the problematic users:
# Connect to Azure AD Connect-AzureAD # Get user details and filter SfB-related attributes Get-AzureADUser -ObjectId "user@yourdomain.com" | Select-Object UserPrincipalName, @{Name="msRTCSIP-DeploymentLocator"; Expression={$_.ExtensionProperty["msRTCSIP-DeploymentLocator"]}}, @{Name="msRTCSIP-PrimaryUserAddress"; Expression={$_.ExtensionProperty["msRTCSIP-PrimaryUserAddress"]}}
Look for values pointing to your old on-prem SfB server here— if they exist, we’ll need to clear them directly in Azure AD.
Step 2: Clear SfB Attributes in Azure AD
If the above command shows lingering on-prem SfB properties, use this to reset them to the standard online-only values:
# Set deployment locator to the online SfB endpoint Set-AzureADUserExtension -ObjectId "user@yourdomain.com" -ExtensionName "msRTCSIP-DeploymentLocator" -ExtensionValue "sipfed.online.lync.com" # Clear any remaining on-prem line URI references Set-AzureADUserExtension -ObjectId "user@yourdomain.com" -ExtensionName "msRTCSIP-LineURI" -ExtensionValue $null
This forces the user’s SfB identity to align with the DirsyncSfBUser type that works for your other users.
Step 3: Force an Immediate AD Connect Sync
Don’t wait for the default 30-minute sync cycle— trigger a delta sync to ensure AD and Azure AD are fully aligned:
# Run this on your AD Connect server Import-Module ADSync Start-ADSyncSyncCycle -PolicyType Delta
Wait 5-10 minutes for the sync to complete, then check the user’s "Interpreted User Type" again in the Teams admin center or via PowerShell.
Step 4: Reset User State with Skype for Business Online PowerShell
If the above steps don’t stick, connect to SfB Online PowerShell to override any remaining hybrid state flags:
# Connect to SfB Online $credential = Get-Credential $session = New-CsOnlineSession -Credential $credential Import-PSSession $session # Reset the user's SfB attributes to online-only Set-CsUser -Identity "user@yourdomain.com" -OnPremLineURI $null -EnterpriseVoiceEnabled $false # Clean up the session Remove-PSSession $session
This bypasses any lingering hybrid configurations that might be stuck in the system.
Step 5: Last Resort: Check Azure AD Backend Cache
If all else fails, the issue might be a backend cache in Azure AD. In this case:
- Wait 24 hours (sometimes caches take time to expire automatically)
- Or open a support ticket with Microsoft, providing the user UPNs and details of your AD cleanup— their engineering team can force a cache refresh on their end.
I’ve seen steps 2 and 3 resolve this issue 9 times out of 10— let me know how it goes!
内容的提问来源于stack exchange,提问作者Marius Thiemann

