Azure Entra Cloud sync - User not synced to OnPremise Active Directory

admin 5 Reputation points
2024-02-08T01:50:09.18+00:00

Microsoft Entra ID to AD

Groups are getting synced but not assigned users in the group. When syncing i get the following Message:

EntrySynchronizationSkip:

Result: Skipped

Description: The User 'xxxx' will be skipped due to the following reasons: 
1) This object is not assigned to the application. 
If you did not expect the object to be skipped,
assign the object to the application or change your scoping filter to allow all users
and groups to be in scope for provisioning. 
2) This object does not have required entitlement for provisioning.
If you did not expect the object to be skipped,
update provisioning scope to 'Sync all users and groups'
or assign the object to the application with entitlement of provisioning category 
3) This object did not pass a scoping filter. 
If you did not expect the object to be skipped, please review your scoping filters 
and ensure that the object passes your specified scoping criteria. 
The scope evaluation result is: {"On-prem Owned Users.dirSyncEnabled IS TRUE":false}

SkipReason: NotEffectivelyEntitled
IsActive: True
Assigned to the application: False   
IsInProvisioningScope: False
ScopeEvaluationResult: {"On-prem Owned Users.dirSyncEnabled IS TRUE":false}
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,064 questions
{count} vote

2 answers

Sort by: Most helpful
  1. Štor Vojtěch 5 Reputation points
    2024-04-03T18:52:10.0033333+00:00

    Hey did someone get it working. When i am trying to sync groups with users. All users are skipped with description: Skipped

    Description

    The User 'xxx' will be skipped due to the following reasons: 1) This object is not assigned to the application. If you did not expect the object to be skipped, assign the object to the application or change your scoping filter to allow all users and groups to be in scope for provisioning. 2) This object does not have required entitlement for provisioning. If you did not expect the object to be skipped, update provisioning scope to 'Sync all users and groups' or assign the object to the application with entitlement of provisioning category 3) This object did not pass a scoping filter. If you did not expect the object to be skipped, please review your scoping filters and ensure that the object passes your specified scoping criteria. The scope evaluation result is: {"On-prem Owned Users.dirSyncEnabled IS TRUE":false}

    SkipReason

    NotEffectivelyEntitled

    IsActive

    True

    Assigned to the application

    False

    IsInProvisioningScope

    False

    ScopeEvaluationResult

    {"On-prem Owned Users.dirSyncEnabled IS TRUE":false}

    ReportableIdentifier

    227dcdf8-15fc-46c6-ac03-332eba1cb7fe

    And yes i have read the documentation on https://learn.microsoft.com/en-us/entra/identity/hybrid/cloud-sync/how-to-configure-entra-to-active-directory
    And there is specified that users/groups will be synced..
    User's image

    1 person found this answer helpful.

  2. Givary-MSFT 32,986 Reputation points Microsoft Employee
    2024-03-01T08:51:09.6366667+00:00

    @admin Apologies for the delayed response, As I understand you are exploring the preview feature of Entra ID to AD (preview) through which you are trying to perform user writeback from Entra ID to on-premises AD.

    Reviewed this documentation - https://learn.microsoft.com/en-us/entra/identity/hybrid/cloud-sync/how-to-configure-entra-to-active-directory this feature has been provided to offer Group Provision (Group writeback) to Active Directory.

    Also, if you review the scoping section, only groups from Entra ID (cloud security groups) are provisioned to on-premise AD, not the users.

    Let me know if you have any further questions, feel free to post back.

    Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.