Need to sync multiple onpremise Active Directory Groups and the users in those groups to Azure Active Directory. How is it best to do this?

Timothy Reese 1 Reputation point
2022-04-01T18:44:36.713+00:00

I would like to sync multiple (but not all) AD groups from on premise to Azure AD. I would like to also sync the users included in these groups from on premise to Azure AD. I would then use the Azure AD groups to provide access to different applications.

How is it best to do this?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,629 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Andy David - MVP 145.6K Reputation points MVP
    2022-04-01T18:49:23.067+00:00

    Syncing by groups alone is not supported in production however - only for a pilot test
    So, sync your on-prem forest and filter out any OUs not needed in the sync and ensure the groups and users in those groups that you DO need are not in any OU you may be filtering out.

    https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-configure-filtering#:~:text=You%20can%20configure%20group%2Dbased,can't%20be%20enabled%20again.

    189307-image.png

    1 person found this answer helpful.
    0 comments No comments