A company is using Azure AD Connect to synchronize user accounts. They recently renamed an Organizational Unit (OU) in their on-premises Active Directory where several synchronized user accounts reside. After the rename, users in that OU are reporting issues accessing Azure AD resources, and some appear to be duplicated or missing. What is the most likely reason for these issues?
- AThe Source Anchor attribute for the affected user objects has become invalid.
- BOU renaming is not directly supported by Azure AD Connect and requires manual intervention.
- CThe Azure AD Connect sync service needs to be manually restarted to detect the change.
- DThe password hashes need to be resynchronized after the OU rename.
Show answer & explanationAnswer & explanation
Correct answer: A. The Source Anchor attribute for the affected user objects has become invalid.
Renaming an OU in Active Directory does not typically invalidate the Source Anchor attribute (which is usually objectGUID or ms-DS-ConsistencyGuid) of the user objects themselves. However, if the OU was used as part of a synchronization rule's scoping filter or if the rename somehow disrupted the connector's ability to locate the objects, it could lead to issues. More commonly, if synchronization rules were based on the OU's distinguished name, a rename could break those rules, leading to objects being out of scope or new objects being created if the Source Anchor was somehow re-evaluated.
Why the other options are wrong
- B. Azure AD Connect generally handles OU renames without issues *if* the Source Anchor remains valid and no rules explicitly depend on the OU's distinguished name for identity matching. The issues described suggest a deeper disruption than expected.
- C. Azure AD Connect performs scheduled synchronization cycles; a manual restart is typically not needed for an OU rename to be detected if the Source Anchor remains valid.
- D. Password hashes are independent of OU structure and would not cause this type of synchronization issue.
Azure AD Connect OU Renaming Impact
Renaming an Organizational Unit in on-premises AD can disrupt Azure AD Connect synchronization if rules or the Source Anchor derivation are dependent on the OU's distinguished name or if the sync process glitches.
- ObjectGUID (common Source Anchor) is stable across OU moves/renames.
- Custom sync rules relying on OU DNs can break.
- May lead to duplicate objects or objects falling out of sync scope.
Memory trick: Change the Path, Keep the Anchor, Else Identity's a Dancer.