Forum Discussion
Guidelines for Active Directory before sync
Filtering is an optional feature, which you should only use when needed. There's negligible security impact of syncing your objects to Azure AD, and adjusting the OUs/objects to sync will hardly remedy any bad decisions implemented back when the AD was designed.
You can think of the default configuration as Microsoft's recommendation, as mentioned here: https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnectsync-configure-filtering
Hi Vasil
Thanks for your reply :)
So when MS guidelines says "Categorize your users" and "Use groups and group-based licensing" - and we have the AD administration "on prem" only - what to do then? .... the complete AD synced out - are 'just' to have the global address List available or am I missing something?.
- VasilMichevJun 26, 2018MVP
It's up to you really, I've seen organizations going either way. We certainly have more than enough settings to configure filtering now, so you can use it if you thinks it's best for your particular org. The closest think I could find to a "recommendation" is in the article I linked above :)