logo
search
Microsoft Account Errors

How to Match Active Directory Users with Microsoft Entra ID

Phi Hung VoPhi Hung Vo Sep 25, 2026 869 views

Question details

Resolve ProxyAddresses conflicts to successfully synchronize matching on-premises Active Directory users with cloud Microsoft Entra ID users.

How to Match Active Directory Users with Microsoft Entra ID
Product
Microsoft Entra Connect
Device & OS
not provided
Scenario
Synchronizing a hybrid Active Directory environment where overlapping on-premises and cloud users already exist.
Observed behavior
Microsoft Entra Connect fails to synchronize specific users, reporting duplicate ProxyAddresses conflicts during the synchronization cycle.
Before you start

Before making changes, verify you have administrative credentials for both your on-premises Active Directory and Microsoft Entra ID, and ensure you correctly identify the target cloud user to avoid linking the wrong accounts.

Solution 1Recommended

Resolve Duplicate ProxyAddresses and Perform Soft Matching

Clear duplicate attributes and rely on Microsoft Entra Connect's soft matching mechanism (via UPN or SMTP) to automatically link existing cloud and on-premises users.

Soft matching is the preferred method for linking hybrid identities. It works by matching the primary SMTP address or User Principal Name (UPN) of an on-premises user with a cloud user. Conflicts must be cleared before this can succeed.

1
Identify the synchronization error

Open the Synchronization Service Manager on your Entra Connect server to identify the specific user accounts experiencing the duplicate ProxyAddresses error.

2
Clean up on-premises attributes

Open Active Directory Users and Computers (ADUC), navigate to the user's properties, and open the Attribute Editor tab to find the proxyAddresses attribute. Remove any duplicate or conflicting SMTP entries.

3
Align the UPN and primary SMTP

Ensure the user's on-premises User Principal Name (UPN) and primary email address perfectly match the target cloud account in Microsoft Entra ID.

4
Run a delta synchronization

Open PowerShell as an administrator on the Entra Connect server and run 'Start-ADSyncSyncCycle -PolicyType Delta' to trigger synchronization and allow soft matching to complete.

Resolve Duplicate ProxyAddresses and Perform Soft Matching
Verification: Once the delta sync finishes, check the Microsoft 365 admin center or Synchronization Service Manager to confirm the user accounts have successfully merged.
Free Microsoft Office alternative

Manage Your IT Documentation with WPS Office

While resolving Active Directory and Microsoft Entra ID synchronization conflicts requires specialized Microsoft administration tools, documenting your IT procedures, PowerShell scripts, and network topologies doesn't have to be expensive. WPS Office is a highly compatible, free alternative to Microsoft Office for managing all your administrative documentation.

  1. 1. Download and Install: Visit the official WPS Office website to download the free suite for your operating system.
  2. 2. Create Documentation: Open WPS Writer or WPS Spreadsheet to begin drafting your network configurations or synchronization checklists.
  3. 3. Save and Share: Save your documents in standard Microsoft formats or export them as PDFs to share securely with your IT team.
Fully compatible with Microsoft Word, Excel, and PowerPoint file formats (.docx, .xlsx, .pptx).Lightweight installation with a familiar, tabbed interface for quick adoption.Free built-in PDF editing tools, ideal for finalizing IT policies and standard operating procedures.Cost-effective solution to deploy across diverse IT and enterprise environments without licensing fees.
microsoft office alternative - wps office

Frequently Asked Questions

Why does Entra Connect report duplicate ProxyAddresses conflicts?

This error occurs when an on-premises Active Directory user is being synced with an email address in their proxyAddresses attribute that is already assigned to a different user, group, or contact within Microsoft Entra ID.

What is the difference between soft matching and hard matching in Entra ID?

Soft matching links an on-premises user to a cloud user based on their User Principal Name (UPN) or primary SMTP address. Hard matching forces the link by configuring the cloud user's OnPremisesImmutableId attribute to explicitly match the Base64-encoded ObjectGUID of the on-premises user.

Why should I use Microsoft Graph PowerShell instead of the MSOnline module?

Microsoft has officially deprecated the MSOnline (MSOL) and Azure AD PowerShell modules. Microsoft Graph PowerShell is the modern, supported standard for managing Microsoft 365 and Entra ID resources from the command line.

How do I trigger a sync after fixing the ProxyAddresses conflict?

To force a sync, open an elevated PowerShell prompt on the server hosting Microsoft Entra Connect and execute the command 'Start-ADSyncSyncCycle -PolicyType Delta'.