Prevent "emergency access" users from syncing to on-prem AD when using AD Connect

Mark Coppa 21 Reputation points
2020-02-25T21:38:57.657+00:00

I'm looking for guidance on preventing (filtering) "emergency access" users from syncing to on-prem AD when using AD Connect. From the reference doc Manage emergency access accounts in Azure AD:

"*Create two or more emergency access accounts. These accounts should be cloud-only accounts that use the .onmicrosoft.com domain and that are not federated or synchronized from an on-premises environment."

I've only found documentation on using Synchronization Rules to filter from on-prem Active Directory to AAD.

Thank you

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,444 questions
0 comments No comments
{count} votes

Accepted answer
  1. Daniel Aldén 156 Reputation points
    2020-02-25T22:14:06.387+00:00

    With AD Connect you cannot sync users back to local AD. Just create cloud only account and activate monitoring when it used.


0 additional answers

Sort by: Most helpful