DeviceWriteback Sync rules editor question

James Meszaros 20 Reputation points
2024-06-10T23:46:15.4666667+00:00

I want to use Device Writeback to sync back AzureAd devices back to on premise AD. When i set it up, it syncs back all devices, even devices that are currently in AD, thus creating duplicates.

I need to filter the sync back to only include AzureAd devices to be synced back.

Microsoft Security Microsoft Entra Microsoft Entra ID
{count} votes

Accepted answer
  1. Akshay-MSFT 17,951 Reputation points Microsoft Employee Moderator
    2024-06-13T11:20:56.6433333+00:00

    @James Meszaros

    Thank you for your time and patience. I was able to test this in my lab and found the following:

    • I have a pre exiting Entra ID tenant with some Mobile, Entra ID joined, Entra Id registered and HybridAD join autopilot devices.
    • I configured a new on prem AD and configured the device options to "device writeback"
    • I could see only devices which existed in my pre-configured Entra ID tenant were written back to the container.
    • No devices which were present in AD and were not hybrid AD joined or Entra ID joined were duplicated.

    Also device write would copy all the device objects which are registered in Entra ID:

    User's image

    So the devices which are pre-registered to Entra ID by any means will be written back however device-based CA would be applicable to Windows hello for business cert trust enabled devices.

    If you don't have any further queries and the suggestion above answers your ask, please "Accept the answer", This will help us and others in the community as well.

    Thanks,

    Akshay Kaushik

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.