Home

Creating cloud only users and hybrid users with SSO

%3CLINGO-SUB%20id%3D%22lingo-sub-219762%22%20slang%3D%22en-US%22%3ECreating%20cloud%20only%20users%20and%20hybrid%20users%20with%20SSO%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-219762%22%20slang%3D%22en-US%22%3EHello%2C%3CBR%20%2F%3EWe%20want%20to%20create%20Employee%20users%20as%20hybrid%20users%20and%20students%20users%20as%20cloud%20only%20users.%20Currently%20we%20are%20using%20password%20hash%20synchronization.%3CBR%20%2F%3EEmployee%20users%20are%20hybrid%20users.%3CBR%20%2F%3EIf%20we%20want%20to%20have%20SSO%20or%20want%20to%20go%20with%20ADFS%2C%20will%20it%20cause%20problem%20to%20have%20different%20types%20of%20users%20as%20cloud%20only%20users%20and%20hybrid%20or%20federated%20users.%3CBR%20%2F%3EPlease%20advise.%3CBR%20%2F%3E%3CBR%20%2F%3EThanks%20and%20Regards%2C%3CBR%20%2F%3ESuparna%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-219762%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Active%20Directory%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-219889%22%20slang%3D%22en-US%22%3ERe%3A%20Creating%20cloud%20only%20users%20and%20hybrid%20users%20with%20SSO%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-219889%22%20slang%3D%22en-US%22%3EYou%20can%20find%20details%20about%20filtering%20options%20here.%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconnect%2Factive-directory-aadconnectsync-configure-filtering%23filtering-options%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconnect%2Factive-directory-aadconnectsync-configure-filtering%23filtering-options%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-219870%22%20slang%3D%22en-US%22%3ERe%3A%20Creating%20cloud%20only%20users%20and%20hybrid%20users%20with%20SSO%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-219870%22%20slang%3D%22en-US%22%3EYes.%20Our%20filtering%20is%20an%20option%20while%20setting%20up%20and%20I%20recommend%20it.%20I%20filter%20things%20like%20service%20accounts%20and%20other%20things%20by%20not%20choosing%20the%20OUs%20they%20exist%20in.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-219863%22%20slang%3D%22en-US%22%3ERe%3A%20Creating%20cloud%20only%20users%20and%20hybrid%20users%20with%20SSO%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-219863%22%20slang%3D%22en-US%22%3EThanks.%3CBR%20%2F%3EI%20have%20one%20more%20question.%3CBR%20%2F%3EWhile%20using%20Azure%20AD%20connect%20for%20SSO%20or%20ADFS%2C%20can%20we%20use%20group%20filtering%20so%20that%20few%20users%20which%20we%20don't%20want%20to%20be%20on%20Azure%20AD%20and%20to%20be%20kept%20only%20on%20Local%20AD%2C%20can%20not%20be%20selected%20for%20synchronization%20or%20SSO.%3CBR%20%2F%3EPlease%20advise.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-219861%22%20slang%3D%22en-US%22%3ERe%3A%20Creating%20cloud%20only%20users%20and%20hybrid%20users%20with%20SSO%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-219861%22%20slang%3D%22en-US%22%3EThanks%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-219799%22%20slang%3D%22en-US%22%3ERe%3A%20Creating%20cloud%20only%20users%20and%20hybrid%20users%20with%20SSO%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-219799%22%20slang%3D%22en-US%22%3E%3CP%3EWell%2C%20if%20the%20accounts%20are%20%22cloud-only%22%2C%20as%20in%20no%20corresponding%20object%20exist%20in%20your%20on-premises%20AD%2C%20there%20is%20no%20way%20to%20use%20password%20sync%2C%20PTA%2C%20or%20AD%20FS%20for%20those.%20Instead%20management%20and%20authentication%26nbsp%3Bwill%20be%20done%20completely%20against%20O365%2C%20including%20passwords.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-219790%22%20slang%3D%22en-US%22%3ERe%3A%20Creating%20cloud%20only%20users%20and%20hybrid%20users%20with%20SSO%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-219790%22%20slang%3D%22en-US%22%3E%3CP%3EWith%20Password%20hash%20sync%20with%20seamless%20single%20sign-on%20it%20works%20fine%20to%20have%20both.%20I%20can't%20speak%20for%20ADFS%20or%20passthrough%20auth%20sso.%20But%20if%20you%20setup%20using%20the%20standard%20Password%20hash%20sync%20with%20seamless%20single%20sign-on%20option.%20It'll%20work%20fine%20with%20both%20Hybrid%20and%20Cloud%20users%20using%20your%20logins%20with%20same%20login%20domain%20with%20both%20synced%20and%20cloud%20only%20users.%3C%2FP%3E%3C%2FLINGO-BODY%3E
SUPARNA KANSAKAR
Contributor
Hello,
We want to create Employee users as hybrid users and students users as cloud only users. Currently we are using password hash synchronization.
Employee users are hybrid users.
If we want to have SSO or want to go with ADFS, will it cause problem to have different types of users as cloud only users and hybrid or federated users.
Please advise.

Thanks and Regards,
Suparna
6 Replies

With Password hash sync with seamless single sign-on it works fine to have both. I can't speak for ADFS or passthrough auth sso. But if you setup using the standard Password hash sync with seamless single sign-on option. It'll work fine with both Hybrid and Cloud users using your logins with same login domain with both synced and cloud only users.

Well, if the accounts are "cloud-only", as in no corresponding object exist in your on-premises AD, there is no way to use password sync, PTA, or AD FS for those. Instead management and authentication will be done completely against O365, including passwords.

Thanks.
I have one more question.
While using Azure AD connect for SSO or ADFS, can we use group filtering so that few users which we don't want to be on Azure AD and to be kept only on Local AD, can not be selected for synchronization or SSO.
Please advise.
Yes. Our filtering is an option while setting up and I recommend it. I filter things like service accounts and other things by not choosing the OUs they exist in.
Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies