Azure Active Directory object write back

Desmond Richard 11 Reputation points
2021-02-09T17:21:55.653+00:00

Good Day

We currently using Azure AD Connect to sync our On-premise AD to Azure AD.

Can one sync objects, User accounts, Distribution lists, etc from Azure AD back to on-premise AD?
So if an object gets created by teams or 365 one can manage that object from on-premise AD.

So i guess this will be a bi-directional sync. So if objects get created on Azure AD or On-premise AD the sync happens both ways so that objects are available both on Azure AD and On-premise AD?

Thank you

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Sam Cogan 10,812 Reputation points Microsoft Employee Volunteer Moderator
    2021-02-09T17:24:16.667+00:00

    It is not possible to sync objects from AAD to On Premises AD, this is a one way sync only.

    The only exception to this is if you utilise Azure AD Domain Services, where resources can sync from AAD, but this is a separate AD instance, it would not help you sync to your on-premises AD.


  2. Marilee Turscak-MSFT 37,206 Reputation points Microsoft Employee Moderator
    2021-02-09T23:03:04.077+00:00

    With Azure AD DS it's still a one-way synchronization. And like Sam mentioned it still woudn't help with the on-premises sync.

    "A managed domain is configured to perform a one-way synchronization from Azure AD to provide access to a central set of users, groups, and credentials. You can create resources directly in the managed domain, but they aren't synchronized back to Azure AD."

    https://learn.microsoft.com/en-us/azure/active-directory-domain-services/overview


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.