Forum Discussion

Taen keren's avatar
Taen keren
Steel Contributor
Apr 22, 2019
Solved

transition to O365 - AAD

Hi 

 

Just wanted to hear about any recommendations / best practice for the following: 

 

A company has a traditional AD on-prem - with OU's, User objects, Security Groups, Distribution lists, etc. which is Synced to AAD.  

How would the "recommendations" be for them and the 'utilization/adoption' of the various workloads/apps - as these are mostly O365 groups "driven"?

Company may have a lot of security group one per. department - but members in this are "static" after they are pulled to the Teams members group when creating an MS Team

 

I can in SharePoint add a security group to the SP members group - however, it's being administrative a "mess" (where to do what in AD or AAD - or both?) - or am I missing the "silver bullet"?     

  • Yeah it's still a mix and depends on if you still have onprem resources or not. I personally like to split the two up. Cloud is Office 365 groups which includes anything connected to that group and on-prem and Non SharePoint group connected sites (comm sites etc.) stay Security groups.

    Really isn't a best practice per say other than that. You don't want to use office 365 groups across other sites because membership into that group could affect access to other things that people may not think about and when guest access comes into play can get even worse that's why I like to try to keep it manual if possible.
  • Ms is pushing for membership through office 365 groups which don’t play very well with local Ad membership assignment! Modern pages work on O365 groups and it’s the easiest to not mess with synced Security groups except if you have a sharepoint intranet or classic sites! You may use dynamic office 365 groups if you have P1 licenses
    • Taen keren's avatar
      Taen keren
      Steel Contributor

      Hi adam deltinger 

       

      Yes I know the dynamic groups within Teams - and the Groups writeback - guess I'm asking 'where-to-do-what' and 'when-to-use-what' (AD or AAD wise) - if Dynamic groups are used the membership admin is turned off in the client 

      AD Security groups works fine in SharePoint - but not in Teams - Is the advise to create new O365 groups and migrate the AD groups so company only uses O365 groups  - some Admin planning/strategy  :D 

      • ChrisWebbTech's avatar
        ChrisWebbTech
        MVP
        Yeah it's still a mix and depends on if you still have onprem resources or not. I personally like to split the two up. Cloud is Office 365 groups which includes anything connected to that group and on-prem and Non SharePoint group connected sites (comm sites etc.) stay Security groups.

        Really isn't a best practice per say other than that. You don't want to use office 365 groups across other sites because membership into that group could affect access to other things that people may not think about and when guest access comes into play can get even worse that's why I like to try to keep it manual if possible.

Resources