azure ad connect synchronization rule attributes for groups

Marek, Sebastian 1 Reputation point
2021-11-19T06:57:53.217+00:00

Hi everyone,
I want to set up an additional rule in the Azure AD Connect synchronization service. I want to sync all users wich are members in defines groups. In the attruibute list I can´t find a attribute wich fits this requirement. The groupMembershipSAM Attribute does´t allow the operator equal. Does anyone have a idea to filter this? Thanks
150860-grafik.png

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. Siva-kumar-selvaraj 15,731 Reputation points Volunteer Moderator
    2021-11-24T15:07:50.71+00:00

    Hello @Marek, Sebastian ,

    Thanks for reaching out and apologize for delayed response.

    It's not supported to use group-based filtering in a custom configuration as you can only configure group-based filtering the first time that you install Azure AD Connect by using custom installation. It's intended for a pilot deployment where you want only a small set of objects to be synchronized. When you disable group-based filtering, it can't be enabled again.

    152210-image.png

    In a full production deployment, it would be hard to maintain a single group and all of its objects to synchronize. Instead of the filtering-on-groups feature, use one of the methods described in Configure filtering (such as OU or Attribute-based filtering).

    To learn more about, refer:
    https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-install-custom#sync-filtering-based-on-groups
    https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-configure-filtering#group-based-filtering

    ------
    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.