Entra Cloud Sync - Group Writeback

Bojan Zivkovic 436 Reputation points
2024-04-23T11:21:21.74+00:00

Hi, could this feature be used as PAM solution for temporary Domain Admins group membership in AD DS (group synced from Entra to AD DS would be a member of Domain Admins group, empty by default, and admins would get a temporary membership in synced group using PIM)? Currently I am using native PAM AD DS optional feature with GUI tool created in PS Studio leveraging JEA - admins request temporary membership in Domain Admins group which is automatically approved.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,561 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 142.2K Reputation points MVP
    2024-04-23T11:27:24.9133333+00:00

    Havent tested that but wouldnt that mean you syncing Domain admin accounts to Azure? Even if only during the writeback phase? thats generally not recommended

    0 comments No comments

  2. Marcin Policht 11,230 Reputation points MVP
    2024-04-23T11:38:26.3033333+00:00

    As far as I recall, the writeback creates groups with the Universal scope - they cannot be added to a domain global group (such as Domain Admins)


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin