{"id":14776,"date":"2020-08-01T08:05:15","date_gmt":"2020-08-01T08:05:15","guid":{"rendered":"https:\/\/www.testpreptraining.com\/tutorial\/?page_id=14776"},"modified":"2020-08-01T08:05:16","modified_gmt":"2020-08-01T08:05:16","slug":"how-objects-credentials-are-synchronized-in-azure-active-directory","status":"publish","type":"page","link":"https:\/\/www.testpreptraining.ai\/tutorial\/how-objects-credentials-are-synchronized-in-azure-active-directory\/","title":{"rendered":"How objects &#038; credentials are synchronized in Azure Active Directory?"},"content":{"rendered":"\n<p>This tutorial will help to gain insights on How objects &amp; credentials are synchronized in Azure Active Directory? Objects and credentials in an Azure Active Directory Domain Services (Azure AD DS) managed domain can either be created locally within the domain, or synchronized from an Azure Active Directory (Azure AD) tenant. Also, When you first deploy Azure AD DS, an automatic one-way synchronization is configured and started to replicate the objects from Azure AD. Furthermore, This one-way synchronization continues to run in the background to keep the Azure AD DS managed domain up-to-date with any changes from Azure AD. No synchronization occurs from Azure AD DS back to Azure AD.<\/p>\n\n\n\n<p>The following diagram illustrates how synchronization works between Azure AD DS, Azure AD, and also an optional on-premises AD DS environment:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"2660\" height=\"786\" src=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/sync-topology-1.png\" alt=\"How objects &amp; credentials are synchronized in Azure Active Directory?\" class=\"wp-image-14778\" srcset=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/sync-topology-1.png 2660w, https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/sync-topology-1-750x222.png 750w\" sizes=\"auto, (max-width: 2660px) 100vw, 2660px\" \/><figcaption>Image source &#8211; Microsoft<\/figcaption><\/figure><\/div>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"synchronization-from-azure-ad-to-azure-ad-ds\"><strong>Synchronization from Azure AD to Azure AD DS<\/strong><\/h3>\n\n\n\n<p>User accounts, group memberships, and credential hashes are synchronized one way from Azure AD to Azure AD DS. Also, This synchronization process is automatic. You don&#8217;t need to configure, monitor, or manage this synchronization process. Furthermore, The initial synchronization may take a few hours to a couple of days, depending on the number of objects in the Azure AD directory. After the initial synchronization is complete, changes that are made in Azure AD, such as password or attribute changes, are then automatically synchronized to Azure AD DS.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"attribute-synchronization-and-mapping-to-azure-ad-ds\"><strong>Attribute synchronization and mapping to Azure AD DS<\/strong><\/h3>\n\n\n\n<p>The following table lists some common attributes and how they&#8217;re synchronized to Azure AD DS.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Attribute in Azure AD DS<\/th><th>Source<\/th><th>Notes<\/th><\/tr><\/thead><tbody><tr><td>UPN<\/td><td>User&#8217;s&nbsp;<em>UPN<\/em>&nbsp;attribute in Azure AD tenant<\/td><td>The UPN attribute from the Azure AD tenant is synchronized as-is to Azure AD DS. Also, The most reliable way to sign in to a managed domain is using the UPN.<\/td><\/tr><tr><td>SAMAccountName<\/td><td>User&#8217;s&nbsp;<em>mailNickname<\/em>&nbsp;attribute in Azure AD tenant or autogenerated<\/td><td>The\u00a0<em>SAMAccountName<\/em>\u00a0attribute is sourced from the\u00a0<em>mailNickname<\/em>\u00a0attribute in the Azure AD tenant. Furthermore, If multiple user accounts have the same\u00a0<em>mailNickname<\/em>\u00a0attribute, the\u00a0<em>SAMAccountName<\/em>\u00a0is autogenerated. If the user&#8217;s\u00a0<em>mailNickname<\/em>\u00a0or\u00a0<em>UPN<\/em>\u00a0prefix is longer than 20 characters, the\u00a0<em>SAMAccountName<\/em>\u00a0is autogenerated to meet the 20 character limit on\u00a0<em>SAMAccountName<\/em>\u00a0attributes.<\/td><\/tr><tr><td>Passwords<\/td><td>User&#8217;s password from the Azure AD tenant<\/td><td>Legacy password hashes required for NTLM or Kerberos authentication are synchronized from the Azure AD tenant. Subsequently, If the Azure AD tenant is configured for hybrid synchronization using Azure AD Connect, these password hashes are sourced from the on-premises AD DS environment.<\/td><\/tr><tr><td>Primary user\/group SID<\/td><td>Autogenerated<\/td><td>The primary SID for user\/group accounts is autogenerated in Azure AD DS. Also, This attribute doesn&#8217;t match the primary user\/group SID of the object in an on-premises AD DS environment. Subsequently, This mismatch is because the managed domain has a different SID namespace than the on-premises AD DS domain.<\/td><\/tr><tr><td>SID history for users and groups<\/td><td>On-premises primary user and group SID<\/td><td>The\u00a0<em>SidHistory<\/em>\u00a0attribute for users and groups in Azure AD DS is set to match the corresponding primary user or group SID in an on-premises AD DS environment. Also, This feature helps make lift-and-shift of on-premises applications to Azure AD DS also easier as you don&#8217;t need to re-ACL resources.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"synchronization-from-on-premises-ad-ds-to-azure-ad-and-azure-ad-ds\"><strong>Synchronization from on-premises AD DS to Azure AD and Azure AD DS<\/strong><\/h3>\n\n\n\n<p>Sbsequently, Azure AD Connect is used to synchronize user accounts, group memberships, and credential hashes from an on-premises AD DS environment to Azure AD. Attributes of user accounts such as the UPN and on-premises security identifier (SID) are synchronized. To sign in using Azure AD DS, legacy password hashes required for NTLM and Kerberos authentication are indeed synchronized to Azure AD.<\/p>\n\n\n\n<p>Furthermore, also having knowledge about Synchronization from a multi-forest on-premises environment and What isn&#8217;t synchronized to Azure AD DS. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"password-hash-synchronization-and-security-considerations\"><strong>Password hash synchronization and security considerations<\/strong><\/h3>\n\n\n\n<p>When you enable Azure AD DS, legacy password hashes for NTLM + Kerberos authentication are required. Also, Azure AD doesn&#8217;t store clear-text passwords, so these hashes can&#8217;t be automatically generated for existing user accounts. Subsequently, Once generated and stored, NTLM and Kerberos compatible password hashes are always stored in an encrypted manner in Azure AD.<\/p>\n\n\n\n<p>Furthermore, The encryption keys are unique to each Azure AD tenant. Indeed, These hashes are encrypted such that only Azure AD DS has access to the decryption keys. Finally,  No other service or component in Azure AD has access to the decryption keys.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><a href=\"https:\/\/www.testpreptraining.ai\/microsoft-azure-architect-technologies-az-303-free-practice-test\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" width=\"960\" height=\"150\" src=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/07\/Untitled-design-5.png\" alt=\"free practice test for AZ- 303\" class=\"wp-image-13928\" srcset=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/07\/Untitled-design-5.png 960w, https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/07\/Untitled-design-5-750x117.png 750w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" \/><\/a><\/figure><\/div>\n\n\n\n<p><a href=\"https:\/\/www.testpreptraining.ai\/tutorial\/exam-az-303-microsoft-azure-architect-technologies\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Go back to home page <\/strong><\/a><\/p>\n\n\n\n<p class=\"has-text-align-right\"><strong>Reference documentation &#8211; <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory-domain-services\/synchronization\" target=\"_blank\" rel=\"noreferrer noopener\">How objects and credentials are synchronized in an Azure Active Directory Domain Services managed domain<\/a> <\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This tutorial will help to gain insights on How objects &amp; credentials are synchronized in Azure Active Directory? Objects and credentials in an Azure Active Directory Domain Services (Azure AD DS) managed domain can either be created locally within the domain, or synchronized from an Azure Active Directory (Azure AD) tenant. Also, When you first&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"categories":[],"tags":[],"class_list":["post-14776","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How objects &amp; credentials are synchronized in Azure Active Directory?<\/title>\n<meta name=\"description\" content=\"Enhance and upgrade your Azure Architect skills by preparing from tutorial - How objects &amp; credentials are synchronized in Azure Active Directory?\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.testpreptraining.ai\/tutorial\/how-objects-credentials-are-synchronized-in-azure-active-directory\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How objects &amp; credentials are synchronized in Azure Active Directory?\" \/>\n<meta property=\"og:description\" content=\"Enhance and upgrade your Azure Architect skills by preparing from tutorial - How objects &amp; credentials are synchronized in Azure Active Directory?\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.testpreptraining.ai\/tutorial\/how-objects-credentials-are-synchronized-in-azure-active-directory\/\" \/>\n<meta property=\"og:site_name\" content=\"Testprep Training Tutorials\" \/>\n<meta property=\"article:modified_time\" content=\"2020-08-01T08:05:16+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/sync-topology-1.png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/how-objects-credentials-are-synchronized-in-azure-active-directory\/\",\"url\":\"https:\/\/www.testpreptraining.ai\/tutorial\/how-objects-credentials-are-synchronized-in-azure-active-directory\/\",\"name\":\"How objects & credentials are synchronized in Azure Active Directory?\",\"isPartOf\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#website\"},\"datePublished\":\"2020-08-01T08:05:15+00:00\",\"dateModified\":\"2020-08-01T08:05:16+00:00\",\"description\":\"Enhance and upgrade your Azure Architect skills by preparing from tutorial - How objects & credentials are synchronized in Azure Active Directory?\",\"breadcrumb\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/how-objects-credentials-are-synchronized-in-azure-active-directory\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.testpreptraining.ai\/tutorial\/how-objects-credentials-are-synchronized-in-azure-active-directory\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/how-objects-credentials-are-synchronized-in-azure-active-directory\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.testpreptraining.ai\/tutorial\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How objects &#038; credentials are synchronized in Azure Active Directory?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#website\",\"url\":\"https:\/\/www.testpreptraining.ai\/tutorial\/\",\"name\":\"Testprep Training Tutorials\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.testpreptraining.ai\/tutorial\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#organization\",\"name\":\"Testprep Training\",\"url\":\"https:\/\/www.testpreptraining.ai\/tutorial\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png\",\"contentUrl\":\"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png\",\"width\":583,\"height\":153,\"caption\":\"Testprep Training\"},\"image\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How objects & credentials are synchronized in Azure Active Directory?","description":"Enhance and upgrade your Azure Architect skills by preparing from tutorial - How objects & credentials are synchronized in Azure Active Directory?","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.testpreptraining.ai\/tutorial\/how-objects-credentials-are-synchronized-in-azure-active-directory\/","og_locale":"en_US","og_type":"article","og_title":"How objects & credentials are synchronized in Azure Active Directory?","og_description":"Enhance and upgrade your Azure Architect skills by preparing from tutorial - How objects & credentials are synchronized in Azure Active Directory?","og_url":"https:\/\/www.testpreptraining.ai\/tutorial\/how-objects-credentials-are-synchronized-in-azure-active-directory\/","og_site_name":"Testprep Training Tutorials","article_modified_time":"2020-08-01T08:05:16+00:00","og_image":[{"url":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/sync-topology-1.png"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/how-objects-credentials-are-synchronized-in-azure-active-directory\/","url":"https:\/\/www.testpreptraining.ai\/tutorial\/how-objects-credentials-are-synchronized-in-azure-active-directory\/","name":"How objects & credentials are synchronized in Azure Active Directory?","isPartOf":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#website"},"datePublished":"2020-08-01T08:05:15+00:00","dateModified":"2020-08-01T08:05:16+00:00","description":"Enhance and upgrade your Azure Architect skills by preparing from tutorial - How objects & credentials are synchronized in Azure Active Directory?","breadcrumb":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/how-objects-credentials-are-synchronized-in-azure-active-directory\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.testpreptraining.ai\/tutorial\/how-objects-credentials-are-synchronized-in-azure-active-directory\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/how-objects-credentials-are-synchronized-in-azure-active-directory\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.testpreptraining.ai\/tutorial\/"},{"@type":"ListItem","position":2,"name":"How objects &#038; credentials are synchronized in Azure Active Directory?"}]},{"@type":"WebSite","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#website","url":"https:\/\/www.testpreptraining.ai\/tutorial\/","name":"Testprep Training Tutorials","description":"","publisher":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.testpreptraining.ai\/tutorial\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#organization","name":"Testprep Training","url":"https:\/\/www.testpreptraining.ai\/tutorial\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/","url":"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png","contentUrl":"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png","width":583,"height":153,"caption":"Testprep Training"},"image":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/14776","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/comments?post=14776"}],"version-history":[{"count":1,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/14776\/revisions"}],"predecessor-version":[{"id":14781,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/14776\/revisions\/14781"}],"wp:attachment":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/media?parent=14776"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/categories?post=14776"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/tags?post=14776"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}