Why would one Sync onPrem AD groups

Vivak Hangloo 91 Reputation points
2020-07-04T02:51:55.367+00:00

I was looking at the sync scope for our AD connect server and see we are synching all our security and distribution groups and they show in Azure AD as well

I do not see any use of these groups as such and there is alot of chnage sthat happen to groups everydays as they are used by apps / file permisisons etc.

I only use a coupleof onPrem group in Azure AD to assign licesnes for O365 and havent though of any other reason why i will need them

ANy advice fro syncging onPrem AD groups to Azure AD

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,617 questions
{count} votes

Accepted answer
  1. Thierry DEMAN-BARCELO 491 Reputation points MVP
    2020-07-05T10:54:17.13+00:00

    Hi,

    there are a lot of reasons for synchronizing AD Groups to O365.

    The first advantage is to facilitate the management of users and groups (created/modified/deleted in one place).

    • IT admin and helpdesk already have the procedure to manage users and groups in AD. So, nothing changes for them, no need to delegate them permissions in Azure AD, which is some time complicated.
    • Groups that are distribution lists are present and immediately usable in O365 for Messaging Online
    • Security groups can be used in Sharepoint, and some other places.
    • Hybridation (Exchange, Sharepoint, Skype/Teams) can use take advantage of that.

    Now, groups in Office 365 are also a necessity, and accept more possibilities (external members, opt-in,...).

    Regards,

    1 person found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. T. Kujala 8,706 Reputation points
    2020-07-04T03:57:47.707+00:00

    Hi @Kitaab-8535,

    You can only sync selected groups to Azure AD.

    Open the Azure AD Connect tool (Synchronization Service Manager).

    Select the Connectors tab and right-click on your On-Premises domain.

    Select Properties.

    Select Configure Directory Partitions and Containers.

    Uncheck the containers that includes groups that you don't want to sync.

    11345-azure-ad-1.jpg

    1 person found this answer helpful.
    0 comments No comments

  2. Vivak Hangloo 91 Reputation points
    2020-07-04T14:41:51.177+00:00

    Thanks, isee that option . i can unselct them during the sync as well.
    i like to know why would someone sync onprem groups as all excpet of few they manage to assign license with

    how do people do in in production