Group Sync from Azure AD to onprem AD

MS Techie 2,751 Reputation points
2023-05-26T08:22:33.4533333+00:00

Whenever any user is added to group in Azure AD , will the group membership be synced back to on-prem AD ?

This question is applicable for both Distribution Group and Security Group.

Please advise.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Harpreet Singh Matharoo 8,396 Reputation points Microsoft Employee Moderator
    2023-05-26T10:55:59.53+00:00

    Hello @MS Techie

    Thank you for reaching out. I would like to confirm that this would only happen if you enable Group Writeback feature within Azure AD Connect Sync.

    Group writeback allows you to write cloud groups back to your on-premises Active Directory instance by using Azure Active Directory (Azure AD) Connect sync. You can use this feature to manage groups in the cloud, while controlling access to on-premises applications and resources.

    There are two versions of group writeback. The original version is in general availability and is limited to writing back Microsoft 365 groups to your on-premises Active Directory instance as distribution groups. The new, expanded version of group writeback is in public preview and you can write back Microsoft 365 groups as distribution groups, security groups, or mail-enabled security groups.

    For more details, please review following screenshot and documentation link: Plan for Azure AD Connect group writeback

    User's image

    I hope this helps to resolve your query. Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.