MIIS Deletes Microsoft 365 Accounts Upon Moving Users to Different OUs in Local Active Directory
Microsoft 365 (formerly Office 365) is a popular cloud-based productivity suite that offers a range of services, including email, collaboration tools, and more. Many organizations use Microsoft 365 in conjunction with a local Active Directory (AD) environment to manage user accounts and access to resources. However, there are some potential issues that can arise when syncing user accounts between the local AD and Microsoft 365 using the Microsoft Identity Integration Server (MIIS) tool.
MIIS and Microsoft 365 Sync
MIIS, also known as Microsoft Identity Manager (MIM), is a tool that allows organizations to synchronize user accounts and other data between different systems, including local AD and Microsoft 365. When a user account is created or modified in the local AD, MIIS can automatically update the corresponding account in Microsoft 365 to ensure that the two systems are in sync.
However, there is a potential issue that can occur when moving a user account to a different organizational unit (OU) in the local AD. Specifically, MIIS may interpret this as a request to delete the user account in Microsoft 365, rather than simply updating the account as expected.
The Issue with Moving Users to Different OUs
When a user account is moved to a different OU in the local AD, MIIS may interpret this as a request to delete the user account in Microsoft 365, even if the account is simply being moved to a different location within the same AD domain. This can result in the user's email account and other Microsoft 365 resources being deleted, which can be a major issue for organizations that rely on these services.
The root cause of this issue is related to the way that MIIS identifies user accounts. Specifically, MIIS uses the distinguished name (DN) of the user account in the local AD to identify the corresponding account in Microsoft 365. When a user account is moved to a different OU, the DN of the account changes, which can cause MIIS to interpret this as a request to delete the account in Microsoft 365.
Preventing Accidental Deletions
To prevent accidental deletions of user accounts in Microsoft 365 when moving users to different OUs in the local AD, there are a few steps that organizations can take:
- Use separate AD domains for local and cloud resources: By using separate AD domains for local and cloud resources, organizations can avoid the issue of MIIS interpreting a move of a user account as a request to delete the account in Microsoft 365. However, this approach may not be practical for all organizations, especially those with a large number of users and resources.
- Use a different attribute for identifying user accounts: Instead of using the DN of the user account in the local AD to identify the corresponding account in Microsoft 365, organizations can use a different attribute, such as the user principal name (UPN). This can help to prevent accidental deletions when moving user accounts to different OUs.
- Disable MIIS sync for OU moves: Another option is to disable MIIS sync for OU moves, which can prevent the tool from interpreting a move of a user account as a request to delete the account in Microsoft 365. However, this approach may not be practical for organizations that rely on MIIS to keep their local AD and Microsoft 365 in sync.
While MIIS is a powerful tool for syncing user accounts and other data between local AD and Microsoft 365, there are some potential issues that can arise when moving user accounts to different OUs in the local AD. By understanding these issues and taking steps to prevent accidental deletions, organizations can ensure that their user accounts and other resources are properly managed and available when needed.