Update: AAD Connect Network Test Tool

I trotted out the trusty WireShark and Fiddler tools today and ran through the latest iteration of AAD Connect setup.  In so doing, I’ve added a few endpoints to the test: $CRL http://ocsp.msocsp.com $RequiredResources adminwebservice-s1-co2.microsoftonline.com $RequiredResourcesEndpoints https://adminwebservice-s1-co2.microsoftonline.com/provisioningwebservice.svc As always, the newest version is available at http://aka.ms/aadnetwork. Goodnight and good luck!


A few users reported bugs with logging that I have updated.  There was also an unreported bug when searching the XML generated by Get-ADSyncServerConfiguration for the connector’s AD user, which I have also resolved. You can get the updated tool at https://gallery.technet.microsoft.com/AD-Advanced-Permissions-49723f74.


Use AAD Connect to disable accounts with expired on-premises passwords

This week, I received an email from a colleague asking if there was a way to work around the default behavior described in https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnectsync-implement-password-synchronization: Password expiration policy If a user is in the scope of password synchronization, the cloud account password is set to Never Expire. You can continue to sign in to your cloud…


Advanced AAD Connect Permissions Configuration

Updated with additional requirements and scenarios, 2017-10-26. I recently worked with a customer that needed assistance in configuring the additional permissions required for AAD Connect delegation.  After chasing down an incredible number of prerequisite information, I decided it would be more helpful to my customer to put together a tool that would help them configure…