Hi,
We're switching domain federation provider from "other" to on-prem AD.
However, while testing Azure AD Connect, we ran into syncing problems, where the O365 user ImmutableID is different than the one Azure AD Connect provides.
What would be the best option here? Seem it's not even possible to change ImmutableID on an already federated user.
I found some threads suggesting that changing the UPN of the O365 user, clearing the ImmutableID and then change the UPN back would work, but I'm not sure what that might break on our users.
Is disconnecting the domain from federation altogether an option? As in, disconnecting the domain, clearing the ImmutableID on all users, sync with AD and then turn federation back with the new federation settings?