need to clean up Federated domain

%3CLINGO-SUB%20id%3D%22lingo-sub-1672558%22%20slang%3D%22en-US%22%3Eneed%20to%20clean%20up%20Federated%20domain%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1672558%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Members%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGood%20day%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20a%20federated%20domain%20in%20Azure.%20-%26gt%3B%20eg.%20fed.dom.lo.com%3C%2FP%3E%3CP%3Ethe%20AD%20Connect%20was%20set%20up%20and%20it%20had%20synchronized%20all%20the%20users%20in%20our%20on-prem%20domain%20controller%20to%20the%20Azure.%3C%2FP%3E%3CP%3EAssume%20we%20had%2020k%20users%20in%20the%20specific%20OU%2C%20which%20was%20set%20for%20the%20sync.%20Now%2C%20the%20change%20that%20came%20in%20would%20want%20us%20to%20sync%20users%20which%20have%20a%20specific%20attribute%20set.%3C%2FP%3E%3CP%3Eie%2C%20departmentName%20%3D%20xyz%20and%20not%20all.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMy%20doubts%20are%20as%20below%2C%3C%2FP%3E%3CP%3E1.What%20would%20happen%20to%20the%20existing%20users%20in%20Azure%20federated%20domain%2C%20would%20there%20be%20a%20clean%20up%20automatically%20done%3F%20ex%2C%20users%20synced%20are%2020k%2C%20but%20users%20with%20attribute%20are%20just%203k.%3C%2FP%3E%3CP%3E2.How%20would%20we%20do%20a%20clean%20up%20on%20Azure%20domain%3F%3C%2FP%3E%3CP%3E3.%20Could%20we%20delete%20all%20the%20users%20on%20Azure%20domain%20and%20add%20the%20inbound%20sync%20rule%20to%20have%20the%20limited%20users%20show%20up%20again%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eor%20any%20better%20way%20to%20achieve%20this.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%3C%2FP%3E%3CP%3EV%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1672558%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EADConnect%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EADFS%202016%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1673839%22%20slang%3D%22en-US%22%3ERe%3A%20need%20to%20clean%20up%20Federated%20domain%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1673839%22%20slang%3D%22en-US%22%3E%3CP%3EIf%20you%20remove%20a%20user%20from%20the%20sync%20scope%2C%20the%20corresponding%20object%20in%20Azure%20AD%20will%20be%20deleted%20along%20with%20all%20its%20data%20across%20O365%2C%20so%20make%20sure%20you%20are%20certain%20you%20want%20to%20do%20this.%20It%20doesnt%20matter%20if%20the%20domain%20is%20federated%20or%20not.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAnd%20you'll%20probably%20run%20into%20the%20deletion%20threshold%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-sync-feature-prevent-accidental-deletes%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-sync-feature-prevent-accidental-deletes%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Visitor

Hi Members,

 

Good day,

 

We have a federated domain in Azure. -> eg. fed.dom.lo.com

the AD Connect was set up and it had synchronized all the users in our on-prem domain controller to the Azure.

Assume we had 20k users in the specific OU, which was set for the sync. Now, the change that came in would want us to sync users which have a specific attribute set.

ie, departmentName = xyz and not all.

 

My doubts are as below,

1.What would happen to the existing users in Azure federated domain, would there be a clean up automatically done? ex, users synced are 20k, but users with attribute are just 3k.

2.How would we do a clean up on Azure domain?

3. Could we delete all the users on Azure domain and add the inbound sync rule to have the limited users show up again?

 

or any better way to achieve this.

 

Thank you

V

1 Reply

If you remove a user from the sync scope, the corresponding object in Azure AD will be deleted along with all its data across O365, so make sure you are certain you want to do this. It doesnt matter if the domain is federated or not.

 

And you'll probably run into the deletion threshold: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-feature-prevent-a...