2026-08-15

Exchange Online versus on-premise environment

Let's assume there are:
  • (MF) main forest - source of the indentities - single user = single account
  • (RF) resource forest - linked mailboxes - Exchange attributes
  • (AT) tenant - with migrated mailboxes
Sometime I can see object in AADC/EIDC:
  • AT connector
  • MF connector
Sometime it's build of:
  • AT connector
  • RF connector
In this particular hybrid configuration part of attributes are managed by IAM in MF, rest of attributes come from RF. To properly build object MV (metaverse) must be build with the three connectors - MF - main account, RF - resource account - linked mailbox and finally AT - object in Azure.

I'm not sure who is responsible for two strange cases. I don't know - maybe IAM team, maybe EXO team, finally - me - guy responsible for Active Directory, AADC/EIDC and partially for Azure I should repair it. So how to enforce AADC/EIDC in this case to properly connect them:
  • ms-DS-ConsistencyGuid - present on MF account usually is equal to Base64 objectGuid of the MF account itself
  • ms-DS-ConsistencyGuid - in Base64 format should be on AT account as immutableId
  • ms-DS-ConsistencyGuid - can't be present on RF account or... this account will be a placeholder - so on RF account this attribute must be empty - null
  • msExchMasterAccountSid - on RF account must be equal SID's of MF account.

2026-07-21

TaskScheduler error 0x800710e0

0x800710e0 - meaning - task not launched do to missed start time - reason? Server restarted - by updating team.

2026-05-12

ADSIEdit 0x8000500d property not found

Some LDAP instance - connection through AdsiEdit - it is not a problem with authentication - my ldap account allowing me to connect. Problem with encryption? I don't think so, so what the hell it is?

2026-05-05

Error replication - tombstone lifetime exceeded

I've got small lab - domain controllers and the whole lab was run at 2018, so I've received error, that tombstone lifetime is exceeded.

reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters" /v "Allow Replication With Divergent and Corrupt Partner" /t REG_DWORD /d 1 /f

2026-02-20

double dots name prevent synchronization group to Azure

case: on-premise user or group with two consecutive dots in name like "Group..1"; AADC synchronization rule with simply flow mailnickname (direct) alias

error: wrong mailnickname (but mailnickname is empty in the source directory)