Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesMedium

A company is using Azure AD Connect to synchronize user accounts. They notice that some users are experiencing issues with their sign-in names (User Principal Names - UPNs) in Azure AD not matching their desired format. They want to ensure that all synchronized users have UPNs in Azure AD that match the format 'user@company.com', even if their on-premises UPN suffix is different (e.g., 'user@internal.local'). Which component of Azure AD Connect should they configure to achieve this?

  1. AFiltering
  2. BPassword Hash Synchronization settings
  3. CDirectory Extensions
  4. DSynchronization Rules Editor
Show answer & explanation

Correct answer: D. Synchronization Rules Editor

The Synchronization Rules Editor allows administrators to customize how attributes are synchronized between on-premises Active Directory and Azure AD. This includes modifying or transforming attributes like the User Principal Name (UPN) to ensure they meet specific formats or requirements in Azure AD.

Why the other options are wrong

  • A. Filtering is used to include or exclude objects from synchronization, not to transform attribute values.
  • B. Password Hash Synchronization settings deal with password synchronization, not UPN formatting.
  • C. Directory Extensions are used to extend the schema and synchronize custom attributes, not to change the format of existing standard attributes like UPN.

Azure AD Connect Sync Rules

Configurable rules that control how objects and attributes flow between on-premises Active Directory and Azure AD.

  • Can be used for attribute transformation, filtering, and joining objects.
  • Includes inbound (AD to Metaverse) and outbound (Metaverse to Azure AD) rules.
  • Custom rules can override default rules.

Memory trick: Rules Transform, Connect Flows, Make It So.

More Implement and manage hybrid identities questions