Microsoft Entra ID to AD not syncing the groups members

Wael Khuzam 20 Reputation points
2024-06-24T13:28:31.6033333+00:00

Hi,

I have configured Microsoft Entra ID to AD to sunc Azure security groups to on.prem AD, it's syncing the groups according to the Scopping Filter correctly but the groups are sunced with no members!

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,457 questions
0 comments No comments
{count} votes

Accepted answer
  1. Sandeep G-MSFT 16,521 Reputation points Microsoft Employee
    2024-06-25T04:36:16.76+00:00

    @Wael Khuzam

    Thank you for posting this in Microsoft Q&A.

    As I understand you have configured Group writeback in your tenant and groups are getting synced, but groups members are not syncing to on-premises.

    In Group writeback feature groups provisioned to AD using cloud sync can only contain on-premises synchronized users and / or additional cloud created security groups. Group memberships can be managed in Group writeback only for the accounts which are synced to Azure AD.

    Since Sync/provisioning does not support user writeback, users created as cloud only in Azure will not be synced as group members to On-premise AD.

    If you select a security group that has a nested security group as its member, then only the nested group will be written back and not it's members. For example, if a Sales security group is a member of the Marketing security group, only the Sales group itself will be written back and not the members of the Sales group.

    All of these users must have the onPremisesObjectIdentifier attribute set on their account.

    The onPremisesObjectIdentifier must match a corresponding objectGUID in the target AD environment.

    Groups that are larger than 50,000 members aren't supported.

    Let me know if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


1 additional answer

Sort by: Most helpful
  1. Vasil Michev 99,841 Reputation points MVP
    2024-06-24T16:15:36.34+00:00

    Do the users exist on-premises? Provisioning is just for group objects, not users.