How to Match Active Directory Users with Microsoft Entra ID
Question details
Resolve ProxyAddresses conflicts to successfully synchronize matching on-premises Active Directory users with cloud Microsoft Entra ID users.

- Product
- Microsoft Entra Connect
- Device & OS
- not provided
- Scenario
- Synchronizing a hybrid Active Directory environment where overlapping on-premises and cloud users already exist.
- Observed behavior
- Microsoft Entra Connect fails to synchronize specific users, reporting duplicate ProxyAddresses conflicts during the synchronization cycle.
Before making changes, verify you have administrative credentials for both your on-premises Active Directory and Microsoft Entra ID, and ensure you correctly identify the target cloud user to avoid linking the wrong accounts.
Resolve Duplicate ProxyAddresses and Perform Soft Matching
Clear duplicate attributes and rely on Microsoft Entra Connect's soft matching mechanism (via UPN or SMTP) to automatically link existing cloud and on-premises users.
Soft matching is the preferred method for linking hybrid identities. It works by matching the primary SMTP address or User Principal Name (UPN) of an on-premises user with a cloud user. Conflicts must be cleared before this can succeed.
Open the Synchronization Service Manager on your Entra Connect server to identify the specific user accounts experiencing the duplicate ProxyAddresses error.
Open Active Directory Users and Computers (ADUC), navigate to the user's properties, and open the Attribute Editor tab to find the proxyAddresses attribute. Remove any duplicate or conflicting SMTP entries.
Ensure the user's on-premises User Principal Name (UPN) and primary email address perfectly match the target cloud account in Microsoft Entra ID.
Open PowerShell as an administrator on the Entra Connect server and run 'Start-ADSyncSyncCycle -PolicyType Delta' to trigger synchronization and allow soft matching to complete.

Perform a Hard Match Using Microsoft Graph PowerShell
If soft matching fails or is not possible, manually link the accounts by converting the on-premises ObjectGUID to a Base64 string and applying it as the ImmutableId in the cloud.
Manage Your IT Documentation with WPS Office
While resolving Active Directory and Microsoft Entra ID synchronization conflicts requires specialized Microsoft administration tools, documenting your IT procedures, PowerShell scripts, and network topologies doesn't have to be expensive. WPS Office is a highly compatible, free alternative to Microsoft Office for managing all your administrative documentation.
- 1. Download and Install: Visit the official WPS Office website to download the free suite for your operating system.
- 2. Create Documentation: Open WPS Writer or WPS Spreadsheet to begin drafting your network configurations or synchronization checklists.
- 3. Save and Share: Save your documents in standard Microsoft formats or export them as PDFs to share securely with your IT team.

Frequently Asked Questions
Why does Entra Connect report duplicate ProxyAddresses conflicts?
This error occurs when an on-premises Active Directory user is being synced with an email address in their proxyAddresses attribute that is already assigned to a different user, group, or contact within Microsoft Entra ID.
What is the difference between soft matching and hard matching in Entra ID?
Soft matching links an on-premises user to a cloud user based on their User Principal Name (UPN) or primary SMTP address. Hard matching forces the link by configuring the cloud user's OnPremisesImmutableId attribute to explicitly match the Base64-encoded ObjectGUID of the on-premises user.
Why should I use Microsoft Graph PowerShell instead of the MSOnline module?
Microsoft has officially deprecated the MSOnline (MSOL) and Azure AD PowerShell modules. Microsoft Graph PowerShell is the modern, supported standard for managing Microsoft 365 and Entra ID resources from the command line.
How do I trigger a sync after fixing the ProxyAddresses conflict?
To force a sync, open an elevated PowerShell prompt on the server hosting Microsoft Entra Connect and execute the command 'Start-ADSyncSyncCycle -PolicyType Delta'.




