Select Page

Azure AD GUID to Azure AD ImmutableID converter

Azure AD GUID to Azure AD ImmutableID converter

What is the ImmutableID

If you are working with Azure AD and you are synchronizing objects from your on-premises directory services (Active Directory) to Azure Active Directory using FIM or Azure AD Connect, then you might need to troubleshoot some synchronization issues from time to time. It is very important to understand how objects are represented in your AD and on Azure AD and how important for you to know what the ImmutableID means.

There are three stores of objects in this synchronization infrastructure:

  1. Object exists originally in Active Directory.
  2. Object is synced and stored in Azure AAD Connect (the store called metaverse).
  3. Object is finally stored in Azure AD.

During setting up the synchronization to Azure AD, you will be asked to choose an attribute to represents objects in your local Active Directory. This attribute should be immutable and not changed during the life-cycle of the whole ongoing sync to Azure AD. Usually, people go with the ObjectGUID. Nevertheless, there are some situations, like forest migrations, where ObjectGUID might change. Check this article for an example.

Let us suppose you chose to have ObjectGUID when you set up the synchronization to AzureAD. Now, let us go through the synchronization phases and see how an object is represented across the three stores.

While the object is represented in Active Directory using ObjectGUID, when it is synced to Azure AAD Connect, The objectGUID is converted  to base-64 format and stored in AAD Connect metaverse in a new attribute called (sourceAnchor). This attribute only exists in the AAD Connect metaverse.

Now, when the object is synced from the AAD Connect metaverse to Azure AD, the sourceAnchor value of that object will be copied to a the corresponding object in Azure AD in new attribute called ImmutableID .

Azure AD GUID to Azure AD ImmutableID converter 9

Let us say that a user called John exist in your AD, his objectGUID is something like this:

Azure AD GUID to Azure AD ImmutableID converter 1

The user objectGUID is converted  to base-64 and stored in AAD Coonect metaverse as (sourceAnchor) , and in Azure AD as ImmutableID :

Azure AD GUID to Azure AD ImmutableID converter 2


Azure AD GUID to Azure AD ImmutableID converter

So sometime you want a tool that converts from objectGUID to ImmutableID  and the other way. So I created a simple desktop application, that you click on , and use it to easily convert between Azure ImmutableID  and AD objectGUID. The application is so small (500k) as you can see below:

Azure AD GUID to Azure AD ImmutableID converter 3


Just double click it and the app will open:


Azure AD GUID to Azure AD ImmutableID converter 4


Now you can simply enter an AD GUID and it will compute the ImmutableID :


Azure AD GUID to Azure AD ImmutableID converter 5


Or you can enter an Azure ImmutableID  and it will compute the object GUID in your AD:

UID to Azure AD ImmutableID converter 6

Download the Tool

You can download the APP from here. The tool requires that you have .NET on your machine.

About The Author

Ammar Hasayen

Ammar is a digital transformer, cloud architect, public speaker and blogger. He is considered a trusted advisory with the ability to quickly navigate complex multi-cultural organizations and continuously improve and motivate cross-functional teams to achieve higher productivity, collaboration, revenue gain and cross-group knowledge sharing. His contributions to the tech community helped him get awarded the Microsoft Most Valuable Professional. Ammar appears in a lot of global conferences, and he has many publications about digital transformation and next generation technologies.

1 Comment

  1. Khalid

    Good one. I was using another tool GUID2ImmutableID, however I like GUI of this tool
    Appreciate your post Ammar.


Leave a reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Hi, I’m Ammar Hasayen


About Me

Cloud Architect | Cybersecurity | CISSP | Microsoft MVP | Pluralsight Author | Book Author | International Speaker | World Explorer | @ammarhasayen


LinkedIn Profile

My Pluralsight Course

Speaking at Microsoft Ignite Dubai

Ammar Hasayen Speaker Ignite

Pin It on Pinterest