Synchronizing the Directories

After the Directory Synchronization tool has been installed, it can be used to synchronize the directories for the first time. For the first synchronization, a copy of the local users and groups is written to the Office 365 directory. From there forward, the Directory Synchronization tool checks for any changes to the local AD objects and updates the Office 365 directory with the changes.

If the default option was selected on the final page when the Directory Synchronization tool was installed, the Microsoft Online Directory Services Synchronization Configuration Wizard starts automatically. If not, you can invoke the wizard by logging on to the system where the tool is installed, and, from the Start menu, selecting All Programs, Microsoft Online Services, Directory Synchronization, Directory Sync Configuration. Use the wizard to configure directory synchronization, as detailed here:

1. At the Welcome screen, click Next.

2. At the Microsoft Online Services Credentials screen, enter the credentials of an Office 365 administrator account, and click Next. The wizard verifies that directory synchronization has been activated in the online tenant. If a configuration error message appears, the activation of the feature might not be complete within Office 365, which can be verified using the online portal. After activation is verified, the wizard continues.

3. At the Active Directory Credentials page, enter the credentials of an Enterprise Admin account, and click Next.

4. At the Exchange Hybrid Deployment page, click Next to continue.

5. When the configuration is complete, click Next.

6. At the Finished page, verify that the Synchronize Directories Now check box is selected, and click Finish.


Note

When configured, the directory synchronization service automatically creates a service account named MSOL_AD_SYNC in the Users container at the root of Active Directory, and applies a randomly generated password that never expires. This service account is used by the Directory Synchronization tool to read the local Active Directory and write to Office 365, using the credentials provided in the Microsoft Online Services Credentials page of the Configuration Wizard. This service account should never be moved or removed, and the password on the account should never be manually reset; otherwise, synchronization failures will occur.


After directory synchronization has been configured, it will run every three hours automatically. If there are changes that need to be synchronized more urgently, there are two methods that can be used to force synchronization. The first method is to run the Directory Services Synchronization Configuration Wizard, following the same procedure already described. To force directory synchronization, the Synchronize Directories Now check box should be selected on the final page of the wizard. Though simple, this method of forcing synchronization does require the appropriate credentials to be entered each time the wizard is run. To force directory synchronization without the need to enter credentials, Windows PowerShell can be used. Use the following procedure to force directory synchronization using a Windows PowerShell cmdlet:

1. Log on to the system where the Directory Synchronization tool is installed using an account with local administrator permissions.

2. Use Windows Explorer to navigate to the directory where the Directory Synchronization tool is installed (by default, %programfiles%Microsoft Online Directory Sync), and double-click on the DirSyncConfigShell.psc1 file, which opens a Windows PowerShell window with the directory synchronization cmdlets loaded.

3. Execute the cmdlet Start-OnlineCoexistenceSync to force directory synchronization.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset