Enabling identity synchronization in multi-forest environments
In this section, we will describe the required information for designing the synchronization in multi-forest environments with the Azure AD Connect tool. This section is divided into the following topics:
- UPN suffix decisions (recap)
- Supporting the separate technologies scenario
- Handling a full mesh scenario with optional GAL synchronization
- Providing synchronization for an account and resource forest scenario
- Understanding AAD Connect Rule Precedence logic
First we will start with a short recap of UPN suffixes and how Azure AD Connect handles different UPN states and configurations.
UPN suffix decisions (recap)
As we have already mentioned, and you already know, the UserPrincipalName (UPN) is one of the most relevant user attributes in the connection from a local Active Directory to the Azure Active Directory (AAD). AAD Connect follows the rules shown in the following figure:
As you can see in the previous figure, AAD Connect uses...