You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

多邮箱域名场景下本地AD与Azure AD/Entra ID同步的可行性及配置方案咨询

多邮箱域名场景下本地AD与Azure AD/Entra ID同步的可行性及配置方案咨询

Hey there, great question—this scenario is totally achievable, you just hit a common gotcha with default Azure AD sync settings. Let’s break down how to fix the current mess and configure things correctly moving forward.

First, Is This Even Possible?

Absolutely. Azure AD/Entra ID fully supports syncing on-prem AD users who share a single .local domain but use different email domains in O365. The key is controlling how attributes are mapped between your on-prem AD and Azure AD, and ensuring the sync matches existing O365 users correctly.

Step 1: Fix the Broken Mailboxes (If You Haven’t Already)

First things first—pause your Cloud Sync immediately to stop further overwrites. Then you’ll need to restore your users’ original email addresses in O365. You can do this manually for a few users, but for a larger group, PowerShell will save you hours:

# Export a list of all mailboxes to verify current settings
Get-Mailbox | Select-Object DisplayName, PrimarySmtpAddress, UserPrincipalName | Export-Csv -Path "C:\mailbox_backup.csv" -NoTypeInformation

# For a single user (example: Jimmy)
Set-Mailbox -Identity "Jimmy" -PrimarySmtpAddress "jimmy@reliancetechnologies.com"

# For bulk fixes, use a CSV with columns DisplayName and CorrectPrimaryAddress
Import-Csv -Path "C:\corrected_mailboxes.csv" | ForEach-Object {
    Set-Mailbox -DisplayName $_.DisplayName -PrimarySmtpAddress $_.CorrectPrimaryAddress
}

Step 2: Prep Your On-Prem AD Attributes

Your on-prem AD needs to have the right attributes set so Azure Sync knows which email addresses to use. For every user:

  • Set the mail attribute to their primary O365 email address (e.g., jimmy@reliancetechnologies.com). This will be used to match existing O365 users during sync.
  • Update the proxyAddresses attribute to include all email aliases for the user, with the primary address marked with uppercase SMTP: and aliases with lowercase smtp:. For example:
    • SMTP:jimmy@reliancetechnologies.com (primary)
    • smtp:jimmy@superiorproducts.com
    • smtp:jimmy@supprod.local
  • You can keep the UPN suffix as superiorproducts.com if you want—Azure AD allows the UPN to differ from the primary email address, as long as the UPN’s domain is verified in your tenant.

Step 3: Configure Azure AD Cloud Sync Correctly

Now adjust your sync settings to respect your multi-domain email setup:

  1. Go to the Entra ID portal, navigate to Identity > Hybrid management > Azure AD Cloud Sync, and open your existing sync configuration.
  2. In the Attribute mapping section:
    • For UserPrincipalName: Keep mapping it to your AD’s userPrincipalName (if you’re sticking with the superiorproducts.com UPN suffix) or change it to map to mail if you want UPN to match the primary email. Either works—just pick what fits your business needs.
    • For EmailAddresses: Ensure this maps to your AD’s proxyAddresses attribute. Crucially, set the Merge behavior to Merge instead of Replace—this tells Azure AD to combine existing O365 email addresses with those from AD, rather than overwriting them.
  3. In the Matching priority section:
    • Change the primary matching rule to use the mail attribute (AD’s mail → Azure AD’s mail) instead of the default UPN. This ensures the sync finds and matches existing O365 users by their email address, rather than creating new users or overwriting existing ones.
  4. Critical: Make sure all your subsidiary domains (like reliancetechnologies.com) are added and verified in your Azure AD tenant. Go to Identity > Settings > Domain names to add and verify each domain—Azure won’t accept email addresses from unverified domains.

Step 4: Test Before Full Sync

Always test with a small group of users first to avoid more issues:

  • Pick 2-3 users from different subsidiaries, trigger a manual sync for their objects, then check their Azure AD profile and O365 mailbox to confirm email addresses are correct and not overwritten.
  • If everything looks good, enable full incremental sync.

Key Notes to Remember

  • Never force a single UPN suffix on all users if their email addresses use different domains—unless you specifically want UPN and email to differ, which is allowed but needs careful mapping.
  • The proxyAddresses attribute is your friend here—it’s the source of truth for email addresses in sync scenarios.
  • Always verify all email domains in Azure AD before syncing, otherwise those addresses will be rejected or overwritten.

备注:内容来源于stack exchange,提问作者boog

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 11:05:30