question

MarkCoppa-2389 avatar image
0 Votes"
MarkCoppa-2389 asked MarkCoppa-2389 commented

Prevent "emergency access" users from syncing to on-prem AD when using AD Connect

I'm looking for guidance on preventing (filtering) "emergency access" users from syncing to on-prem AD when using AD Connect. From the reference doc Manage emergency access accounts in Azure AD:

"Create two or more emergency access accounts. These accounts should be cloud-only accounts that use the .onmicrosoft.com domain and that are not federated or synchronized from an on-premises environment.*"

I've only found documentation on using Synchronization Rules to filter from on-prem Active Directory to AAD.


Thank you

azure-active-directoryazure-ad-connect
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

danielalden avatar image
0 Votes"
danielalden answered MarkCoppa-2389 commented

With AD Connect you cannot sync users back to local AD. Just create cloud only account and activate monitoring when it used.

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Great, thank you.

0 Votes 0 ·