Cloud sync for AD to AZ is skipping "Change password at next logon" flag.

Leo Hernandez 0 Reputation points
2024-05-08T15:10:56.3866667+00:00

Hello,

I'm currently setting up Cloud sync for AD to AZ (Microsoft Entra ID). The users have synchronized successfully, I configured SSPS (self service password reset) for all users. When I tested to reset a test user password, it works.

However, when I apply "change password at next logon" from AD, I get the following error message from Microsoft entra ID:

EntrySynchronizationSkip

Result

Skipped

Description

SyncCredentialsChangeItem 'user@domain' will be skipped. OnPremisesChangePasswordOnNextLogOnFeatureNotEnabled

SkipReason

OnPremisesChangePasswordOnNextLogOnFeatureNotEnabled

ReportableIdentifier

User@domain

I have followed every step from this website and researched other websites as well and the issue persists. https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-enable-cloud-sync-sspr-writeback.

Any help would be appreciated.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,966 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,776 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 142.7K Reputation points MVP
    2024-05-08T16:37:54.9166667+00:00

  2. Andy David - MVP 142.7K Reputation points MVP
    2024-05-09T17:36:03.4966667+00:00

    Yea understand! I just was just curious if that command would at least let you see whats set.

    Are you syncing all users?

    If you change the password for the user on-prem and check the option to force password change at the next logon for their account ( both steps), does it then work?

    That is required with AADConnect:

    https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-password-hash-synchronization#synchronizing-temporary-passwords-and-force-password-change-on-next-logon