Yesterday, Microsoft released version 1,1.561.0 of Azure AD Connect, its free Hybrid Identity bridge product to synchronize objects and their attributes from on-premises Active Directory Domain Services (AD DS) environments to Azure Active Directory.
This version is hot on the heels of version 1.1.557.0, because it features some fixes for organization who recently made the switch to mS-DS-ObjectGuid as their Source Anchor attribute in Azure AD Connect. Also, it incorporates many of the Automatic Upgrades behavioral changes when using the Customize Settings mode of the Azure AD Connect Configuration wizard.
Since version 184.108.40.206 of Azure AD Connect, the Azure AD Connect team has steadily expanded the Automatic Upgrade feature feature to support organizations with the following configurations:
- The installation is not a DirSync upgrade.
- The installation is not an Express settings.
- You have more than 100,000 objects in the metaverse.
- You are connecting to more than one Active Directory forest.
Express setup only connects to one Active Directory forest.
- You are not using a SQL Server Express LocalDB database.
- The Active Directory Connector account is not the MSOL_ or AAD_ account that is created, by default when you connect to Active Directory (anymore).
- The server is set to be in Staging Mode.
- You have enabled the Device Write-back feature.
- You have enabled the Group Write-back feature.
- You have enabled the User Write-back feature.
The Azure AD Connect team fixed an issue that caused the out-of-box synchronization rule “Out to AD – User ImmutableId” to be removed when OU-based filtering configuration is updated. This synchronization rule is required for the msDS-ConsistencyGuid as Source Anchor feature. Fortunately, the logic in Azure Active Directory and Active Directory Federation Services (AD FS) allow for a fallback scenario where the objectGUID is used for hard matching, when the mS-DS-ConsistencyGuid is empty.
The Azure AD Team fixed an issue that causes out-of-box synchronization rules to have precedence value that is less than 100. In general, precedence values 0 – 99 are reserved for custom synchronization rules.
The Azure AD Connect team fixed an issue where the Domain and OU Filtering screen in the Azure AD Connect wizard is showing the Sync all domains and OUs option as selected, even though OU-based filtering is enabled.
The Azure AD Connect team fixed an issue that caused the Configure Directory Partitions screen in the Synchronization Service Manager to return an error if the Refresh button is clicked. The error message is:
An error was encountered while refreshing domains:
Unable to cast object of type ‘System.Collections.ArrayList’ to type ‘Microsoft.DirectoryServices.MetadirectoryServices.UI.PropertySheetBase.MaPropertyPages.PartitionObject.”
The error occurs when a new Active Directory domain has been added to an existing Active Directory forest and you are trying to update Azure AD Connect using the Refresh button.
This is version 1.1.561.0 of Azure AD Connect.
It was signed off on on July 23, 2017.
You can download Azure AD Connect here.
The download weighs 79,6 MB.
Much of the above behavior was introduced in version 1.1.558.0, but internal testing led to several more fixes to make sure the choice for Azure AD Connect is the right choice for organizations on their Hybrid Identity journeys.
Azure AD Connect version 1.1.557,0 wasn’t released through the Automatic Upgrades feature, so I expect many organizations to go from 1.1.553.0 to version 1.1.561.0. Those with lifecycle management surrounding their Azure AD Connect installations should take note of release notes mentioning versions that are not offered through this feature.