Is ad connect sync all the security group types to azure ad?

Shravan 101 Reputation points
2022-12-29T10:33:07.487+00:00

Ad connect will sync all the security group types. ( Domain local, Global, Universal) or it will synchronise universal group only?

Microsoft 365 and Office | SharePoint | For business | Windows
Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. Marilee Turscak-MSFT 37,206 Reputation points Microsoft Employee Moderator
    2022-12-30T20:02:06.977+00:00

    To add to @Michael Durkan 's answer, all three group types/scopes (Universal, Global, and Domain Local) can be synchronized, but there are limitations around the domain local and global scopes.

    If you use group writeback, for instance, all groups are written back with the group scope of universal.

    Currently, Azure AD Connect does also not recognize nested groups for authorization.

    Additionally, ADFS does not pull Domain Local groups, only universal and global groups. This is because domain local groups would be extremely slow since every domain would have to be queried as they aren't replicated.

    Let me know if this helps and if you have further questions.

    -

    If the information helped you, please Accept the answer. This will help us as well as other members of the community who might be researching similar information.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Michael Durkan 12,241 Reputation points MVP
    2022-12-29T11:23:41.997+00:00

    Hi

    Link below explains how groups are handled in Azure AD Connect:

    https://learn.microsoft.com/en-us/azure/active-directory/hybrid/concept-azure-ad-connect-sync-user-and-contacts#groups

    Hope this helps,

    Thanks

    Michael Durkan

    • If the reply was helpful please upvote and/or accept as answer as this helps others in the community with similar questions. Thanks!
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.