Convert Security Group that is synced from on-premises, to an online only group and break the syncing

77293397 41 Reputation points
2022-03-02T23:49:33.347+00:00

Hi there,
I have synced our on-premises active directory to Azure AD with Azure AD Connect.

So, all our on-premises security groups are synced to Azure AD, and I cannot modify members in Azure AD(of course). However, since they are already in Azure AD(and linked to all the Sharepoint data we have also migrated... I would like to convert these synced groups in Azure AD to a cloud-only security groups.

Or, put another way, I want to keep them in azure AD, and disjoin them from syncing, so that they don't sync to on-prem AD anymore, and so that I can modify their membership in Azure AD going forward.

Or, in even another way... change the source of the group from "Windows Server AD" to "Cloud"

How can this be done?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

6 answers

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.

    9 deleted comments

    Comments have been turned off. Learn more

  2. Rahul Shah 5 Reputation points
    2023-02-08T21:19:35.49+00:00

    Hi Steve - Where you able to convert on-prem security group to cloud only ? I am in the same boat and would like to convert specific security groups to cloud only. But when I move these groups out of sync, they are just removed from Azure. I do not see them in Azure as deleted groups to restore them in Azure. I have followed this process for user accounts and it does work. I am able to restore the user accounts in Azure and then nullify the immutable id. But I guess groups do not work the same way. Any suggestions, workarounds for the groups ? Please advise.

    Thanks,

    Rahul

    1 person found this answer helpful.

  3. Matthew Browne 21 Reputation points MVP
    2022-03-03T19:46:59.797+00:00

    Your best option is to do the following

    Open Up Azure AD Connect

    Create an Ou for all the security groups you dont want synced , put the security groups into this

    Once this is done , then go back into your ad connect and ensure the out is not synced the security groups should disappear out of azure after 30 minutes.

    Best Regards
    Matthew Browne MCT
    @AzureGuruMatt


  4. 77293397 41 Reputation points
    2023-02-08T21:39:45.79+00:00

    Not yet, no... I have not been able to do that successfully.

    0 comments No comments

  5. Md. Abdul Razzak 10 Reputation points
    2023-10-02T03:32:02.99+00:00

    Create a new OU. Move all existing security groups to new OU that is non-sync to AAD.

    Run AD Connect tool and confirm that new OU is out of sync. After completing the sync process all the security group will be cloud only.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.