@David Bartlett
Thank you for posting this in Microsoft Q&A.
There are two versions of group writeback. The original version is in general availability and is limited to writing back Microsoft 365 groups to your on-premises Active Directory instance as distribution groups. The new, expanded version of group writeback is in public preview and enables the following capabilities:
- You can write back Microsoft 365 groups as distribution groups, security groups, or mail-enabled security groups.
- You can write back Microsoft Entra security groups as security groups.
- All groups are written back with a group scope of Universal.
- You can write back groups that have assigned and dynamic memberships.
- You can configure directory settings to control whether newly created Microsoft 365 groups are written back by default.
- Group nesting in Microsoft Entra ID will be written back if both groups exist in Active Directory.
- Written-back groups nested as members of on-premises Active Directory synced groups will be synced up to Microsoft Entra ID as nested.
- Devices that are members of writeback-enabled groups in Microsoft Entra ID will be written back as members of Active Directory. Microsoft Entra registered and Microsoft Entra joined devices require device writeback to be enabled for group membership to be written back.
- You can configure the common name in an Active Directory group's distinguished name to include the group's display name when it's written back.
- You can use the Microsoft Entra admin center, Graph Explorer, and PowerShell to configure which Microsoft Entra groups are written back.
The new version is enabled on the tenant and not per Microsoft Entra Connect client instance. Make sure that all Microsoft Entra Connect client instances are updated to a minimal build of Microsoft Entra Connect version 2.0 or later if group writeback is currently enabled on the client instance.
Group memberships can be managed in Group writeback only for the accounts which are synced to Azure AD. For Cloud only users group memberships are not managed by Group writeback
Let us know if you have any further questions.
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.