Migrate from a AAD and AD Hybrid to AAD only?
-
phenomlab Well I ran the command, so we'll see if it resolves the issue. If it does then I shouldn't get the warning email tomorrow morning. But I'm still seeing the Immutable ID in the Azure Portal properties for the test user account. So I'm not sure if it worked properly or not.
-
phenomlab So, the test account worked it seems (no error on it), however the old account that's been throwing the error for months (hence why we stopped the process) is still throwing the error, even after trying both the new
Set-AzureADUser
command the old andSet-MsolUser
command. I should note that this old account doesn't exist at all on-prem anymore (not in recycle bin anymore). I don't think that should impact anything though?Edit: I think I found the issue. I was passing
$null
to the Set-MsolUser command instead of"$null"
. Apparently that makes a huge difference. And theSet-AzureADUser
command just straight up doesn't work. -
phenomlab said in Migrate from a AAD and AD Hybrid to AAD only?:
BillyScott said in Migrate from a AAD and AD Hybrid to AAD only?:
Additionally, does anyone even know how you'd disconnect a Hybrid AD from AAD so that the synced users become cloud only users?
Yes, I have extensive experience in this. The real issue here is the immutable ID side of things. Do you still have an on-prem Exchange server? If so, that needs to be uninstalled - you can't just power it off.
phenomlab can you elaborate on this a bit? I'm currently wrapping up an email migration to Exchange Online and the topic of just shutting down the Exchange servers instead of uninstalling was brought up. We don't currently have plans to migrate AD as well, but I don't want to limit that possibility in the future.
-
font I'm actually interested to know about this too. While I already took care of the Immutable ID thing for our shared mailboxes, we haven't completely removed the Exchange Tools (we don't have a server, but we have the PowerShell Tools and didn't uninstall Exchange.
I'd be very interested to know how uninstalling Exchange ends up impacting user accounts and what not, and if it would allow me to actually manage user accounts entirely from the cloud (instead of the current mix of on-prem and cloud that I have to-do today.
-
phenomlab It appears that I got all the shared mailboxes taken care of properly with the Immutable ID thing! Huge thanks for that. Now here's an interesting question, we did a Hybrid migration for exchange (instead of cut-over) I'm assuming that I'll need to uninstall Exchange before make users cloud only, but not before we're actually ready to cut over to cloud only (given that we have to use local AD to manage things like SMTP attributes and what not)
-
font Provided you are using AADSync, you can use this guide. There are some prerequisites but they are easy to satisfy
Removing Hybrid Exchange
Prior to Microsofts update to the Exchange management tools in Exchange Server 2019 its likely that you were locked into an Exchange hybrid deploym...
Agile IT (www.agileit.com)
-
BillyScott Correct. See above post..
-
-
Thanks phenomlab. The article you linked had a warning to not uninstall the final Exchange server as that would remove attributes from AD. That's the impression I was under, maybe I misunderstood your comment about that causing an issue when migrating AD to AAD. Obviously uninstalling Exchange would affect recipient management, but does it have an impact on user management?
-
-
-
font said in Migrate from a AAD and AD Hybrid to AAD only?:
The article you linked had a warning to not uninstall the final Exchange server as that would remove attributes from AD. That's the impression I was under, maybe I misunderstood your comment about that causing an issue when migrating AD to AAD. Obviously uninstalling Exchange would affect recipient management, but does it have an impact on user management?
Sorry for the late response. You are correct - you should not actually uninstall Exchange - but you can power it off if it's the last server and you've moved everything out including connectors etc. You effectively only remove the hybrid element
Remove Exchange Hybrid Configuration
How to remove Exchange Hybrid Configuration from Active Directory and Microsoft 365? Learn how to delete Hybrid Configuration step by step.
ALI TAJRAN (www.alitajran.com)