This article is primarily targeted at Czech state institutions and is based on recommendations of the Czech authority. However,...
Transferring federated domain to standard in Office 365Lukas Beran
If you want to get rid of domain federation in Office 365 and remove your ADFS server which means moving from single sign-on to cloud identities, you can easily do it using Office 365 Management Shell by Convert-MsolDomainToStandard .
But if your ADFS server is not available for some reason, you can use this approach because it requires connection to the ADFS server.
Convert-MsolDomainToStandard -DomainName <domain> -SkipUserConversion $false -PasswordFile C:\passwords.txt
I got error
Convert-MsolDomainToStandard : Failed to connect to Active Directory Federation Services 2.0 on the local machine. Ple
ase try running Set-MsolADFSContext before running this command again.
At line:1 char:1
+ Convert-MsolDomainToStandard -DomainName <domain> -SkipUserConversion ...
+ CategoryInfo : InvalidOperation: (:) [Convert-MsolDomainToStandard], FederationException
+ FullyQualifiedErrorId : InvalidCommandSequenceGeneva,Microsoft.Online.Identity.Federation.Powershell.ConvertDoma
Transferring federated domain with unavailable ADFS server
We have to get rid of the ADFS server which means disconnect our Office 365 domain and then convert our users to cloud-only identities.
First step is to change authentication method from ADFS to Office 365. We can do it using cmdlet Set-MsolDomainAuthentication . For example
Set-MsolDomainAuthentication -DomainName <domain> -Authentication Managed
Now I was able to authenticate to Office 365 servers instead of my local ADFS server. Now I also wanted to convert all of my identities from synchronized to cloud-only identities. We can do it directly from Office 365 Admin Center. This feature is not available from the new Office 365 admin portal in the time of writing this article, I had to switch to the old portal.
In the old portal, move to Users – Active Users and in the top part of the page is Active Directory synchronization and choose Manage.
Here is available Directory sync status where you should see Activated. Click on Deactivate and the synchronization will be deactivated. The process of deactivation and conversion of user accounts can take up to 72 hours. But in my case it completed in 15 minutes.