Hello @System Administrator,
Thank you for connecting over the team's call.
As discussed, we observed that whenever you attempt to sync a cloud-only user back to Active Directory (AD) via a cloud security group using Provision Microsoft Entra ID to Active Directory - Configuration, you encounter the following provisioning error: "The User '3c202fee-2d62-40e6-8d35-de6269d8086d' will be skipped due to the following reasons: 1) This object is not assigned to the application. If you did not expect the object to be skipped, assign the object to the application or change your scoping filter to allow all users and groups to be in scope for provisioning. 2) This object does not have required entitlement for provisioning. If you did not expect the object to be skipped, update provisioning scope to 'Sync all users and groups' or assign the object to the application with entitlement of provisioning category 3) This object did not pass a scoping filter. If you did not expect the object to be skipped, please review your scoping filters and ensure that the object passes your specified scoping criteria. The scope evaluation result is: {"On-prem Owned Users.dirSyncEnabled IS TRUE":false}
".
Cause: The provisioning is being skipped because the targeted user is a cloud-only user (created in Microsoft Entra ID).
Due to a design limitation, cloud-only users cannot be synced back to AD—only cloud-only security groups can be synced.
For more details, you can refer to the following document, which specifies that only on-prem synced users are supported for security group provisioning: Provision Microsoft Entra ID to Active Directory - Prerequisites
I hope this information is helpful. Please feel free to reach out if you have any further questions.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".