多邮箱域名场景下本地AD与Azure AD/Entra ID同步的可行性及配置方案咨询
Hey there, great question—this scenario is totally achievable, you just hit a common gotcha with default Azure AD sync settings. Let’s break down how to fix the current mess and configure things correctly moving forward.
First, Is This Even Possible?
Absolutely. Azure AD/Entra ID fully supports syncing on-prem AD users who share a single .local domain but use different email domains in O365. The key is controlling how attributes are mapped between your on-prem AD and Azure AD, and ensuring the sync matches existing O365 users correctly.
Step 1: Fix the Broken Mailboxes (If You Haven’t Already)
First things first—pause your Cloud Sync immediately to stop further overwrites. Then you’ll need to restore your users’ original email addresses in O365. You can do this manually for a few users, but for a larger group, PowerShell will save you hours:
# Export a list of all mailboxes to verify current settings Get-Mailbox | Select-Object DisplayName, PrimarySmtpAddress, UserPrincipalName | Export-Csv -Path "C:\mailbox_backup.csv" -NoTypeInformation # For a single user (example: Jimmy) Set-Mailbox -Identity "Jimmy" -PrimarySmtpAddress "jimmy@reliancetechnologies.com" # For bulk fixes, use a CSV with columns DisplayName and CorrectPrimaryAddress Import-Csv -Path "C:\corrected_mailboxes.csv" | ForEach-Object { Set-Mailbox -DisplayName $_.DisplayName -PrimarySmtpAddress $_.CorrectPrimaryAddress }
Step 2: Prep Your On-Prem AD Attributes
Your on-prem AD needs to have the right attributes set so Azure Sync knows which email addresses to use. For every user:
- Set the
mailattribute to their primary O365 email address (e.g., jimmy@reliancetechnologies.com). This will be used to match existing O365 users during sync. - Update the
proxyAddressesattribute to include all email aliases for the user, with the primary address marked with uppercaseSMTP:and aliases with lowercasesmtp:. For example:SMTP:jimmy@reliancetechnologies.com(primary)smtp:jimmy@superiorproducts.comsmtp:jimmy@supprod.local
- You can keep the UPN suffix as
superiorproducts.comif you want—Azure AD allows the UPN to differ from the primary email address, as long as the UPN’s domain is verified in your tenant.
Step 3: Configure Azure AD Cloud Sync Correctly
Now adjust your sync settings to respect your multi-domain email setup:
- Go to the Entra ID portal, navigate to Identity > Hybrid management > Azure AD Cloud Sync, and open your existing sync configuration.
- In the Attribute mapping section:
- For
UserPrincipalName: Keep mapping it to your AD’suserPrincipalName(if you’re sticking with the superiorproducts.com UPN suffix) or change it to map tomailif you want UPN to match the primary email. Either works—just pick what fits your business needs. - For
EmailAddresses: Ensure this maps to your AD’sproxyAddressesattribute. Crucially, set the Merge behavior toMergeinstead ofReplace—this tells Azure AD to combine existing O365 email addresses with those from AD, rather than overwriting them.
- For
- In the Matching priority section:
- Change the primary matching rule to use the
mailattribute (AD’smail→ Azure AD’smail) instead of the default UPN. This ensures the sync finds and matches existing O365 users by their email address, rather than creating new users or overwriting existing ones.
- Change the primary matching rule to use the
- Critical: Make sure all your subsidiary domains (like
reliancetechnologies.com) are added and verified in your Azure AD tenant. Go to Identity > Settings > Domain names to add and verify each domain—Azure won’t accept email addresses from unverified domains.
Step 4: Test Before Full Sync
Always test with a small group of users first to avoid more issues:
- Pick 2-3 users from different subsidiaries, trigger a manual sync for their objects, then check their Azure AD profile and O365 mailbox to confirm email addresses are correct and not overwritten.
- If everything looks good, enable full incremental sync.
Key Notes to Remember
- Never force a single UPN suffix on all users if their email addresses use different domains—unless you specifically want UPN and email to differ, which is allowed but needs careful mapping.
- The
proxyAddressesattribute is your friend here—it’s the source of truth for email addresses in sync scenarios. - Always verify all email domains in Azure AD before syncing, otherwise those addresses will be rejected or overwritten.
备注:内容来源于stack exchange,提问作者boog

