Forum Discussion
SUPARNA KANSAKAR
Jul 28, 2018Copper Contributor
Creating cloud only users and hybrid users with SSO
Hello, We want to create Employee users as hybrid users and students users as cloud only users. Currently we are using password hash synchronization. Employee users are hybrid users. If we want to ...
VasilMichev
Jul 28, 2018MVP
Well, if the accounts are "cloud-only", as in no corresponding object exist in your on-premises AD, there is no way to use password sync, PTA, or AD FS for those. Instead management and authentication will be done completely against O365, including passwords.
- SUPARNA KANSAKARJul 29, 2018Copper ContributorThanks.
I have one more question.
While using Azure AD connect for SSO or ADFS, can we use group filtering so that few users which we don't want to be on Azure AD and to be kept only on Local AD, can not be selected for synchronization or SSO.
Please advise.- JeremyMillerJul 29, 2018MVPYou can find details about filtering options here. https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnectsync-configure-filtering#filtering-options
- AnonymousJul 29, 2018Yes. Our filtering is an option while setting up and I recommend it. I filter things like service accounts and other things by not choosing the OUs they exist in.