SOLVED

Some Question Manage user in Azure AD Domain Service

%3CLINGO-SUB%20id%3D%22lingo-sub-510148%22%20slang%3D%22en-US%22%3ESome%20Question%20Manage%20user%20in%20Azure%20AD%20Domain%20Service%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-510148%22%20slang%3D%22en-US%22%3E%3CP%3EHello%3C%2FP%3E%3CP%3E%26nbsp%3B%20%26nbsp%3B%20In%20Azure%26nbsp%3BAD%20Domain%20Service%20i%20see%20default%20have%20some%20ou%3C%2FP%3E%3CP%3E%26nbsp%3B%20%26nbsp%3B%26nbsp%3B%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20251px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F111679i9FD175E4E42003A8%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Capture.PNG%22%20title%3D%22Capture.PNG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%20%26nbsp%3B%20in%20ADDC%20Users%20%2C%20i%20can%20create%20new%20user%20in%20here%20%3F%20and%20can%20delete%20user%20in%20here%20%3F%20if%20delete%20or%20create%20user%20in%20here%20then%20it%20can%20sync%20to%20Active%20Directory%20on-premier%20%3F%3C%2FP%3E%3CP%3E%26nbsp%3BBest%20Regards%2C%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-510148%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-531326%22%20slang%3D%22en-US%22%3ERe%3A%20Some%20Question%20Manage%20user%20in%20Azure%20AD%20Domain%20Service%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-531326%22%20slang%3D%22en-US%22%3E%3CP%3EIf%20you%20do%20not%20have%20any%20admin%20permssions%20as%20domain%20admin%20or%20enterprise%20admin%20you%20should%20not%20be%20allowed%20to%20create%20or%20remove%20users%20from%20there.%20The%20easiest%20way%20to%20do%20it%20is%20to%20create%20it%20through%20Azure%20AD%20and%20after%20that%20once%20the%20user%20is%20created%20it%20will%20sync%20up%20to%2020%20minutes%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F234118%22%20target%3D%22_blank%22%3E%40Tien%20Ngo%20Thanh%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-532153%22%20slang%3D%22en-US%22%3ERe%3A%20Some%20Question%20Manage%20user%20in%20Azure%20AD%20Domain%20Service%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-532153%22%20slang%3D%22en-US%22%3E%3CP%3EHello%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F234118%22%20target%3D%22_blank%22%3E%40Tien%20Ngo%20Thanh%3C%2FA%3E%26nbsp%3B!%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20you%20create%20AAD%20DS%20and%20you%20are%20member%20of%20%22AAD%20DC%20Admins%22%20it%20has%20limited%20permissions%20to%20managed%20domain%20(no%20domain%20or%20enterprise%20admin%20permissions).%20Pretty%20good%20list%20what%20can%20be%20done%20is%20found%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory-domain-services%2Factive-directory-ds-admin-guide-administer-domain%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ebehind%20this%20link.%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELast%20time%20I%20had%20a%20possibility%20to%20play%20with%20AAD%20Domain%20Services%20default%20permissions%20for%20those%20default%20OU's%20were%20defined%20so%20that%20admin%20were%20not%20able%20to%20create%20users%20for%20the%20OU's.%20Those%20were%3A%3C%2FP%3E%3CUL%3E%3CLI%3Eread%20permissions%20for%20all%20objects%3C%2FLI%3E%3CLI%3Ewrite%20permissions%20for%20gpOptions%20%26amp%3B%20gpLink%3C%2FLI%3E%3C%2FUL%3E%3CP%3EAnother%20questions%20was%20about%20the%20synchronization%2C%20it's%20one-way%20sync%20from%20on-premises%20to%20AAD%20Domain%20Services.%20If%20you%20create%20user%20account%20to%20own%20OU%20it%20will%20not%20be%20synced%20back%20to%20on-premises.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3ENote%20for%20managing%20custom%20OU's%20from%20docs.microsoft.com%3A%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%3CEM%3EWith%20a%20custom%20OU%2C%20you%20can%20go%20ahead%20and%20create%20users%2C%20groups%2C%20computers%2C%20and%20service%20accounts%20in%20this%20OU.%20You%20cannot%20move%20users%20or%20groups%20from%20the%20'AADDC%20Users'%20OU%20to%20custom%20OUs.%3C%2FEM%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CEM%3EUser%20accounts%2C%20groups%2C%20service%20accounts%2C%20and%20computer%20objects%20that%20you%20create%20under%20custom%20OUs%20are%20not%20available%20in%20your%20Azure%20AD%20tenant.%20In%20other%20words%2C%20these%20objects%20do%20not%20show%20up%20using%20the%20Azure%20AD%20Graph%20API%20or%20in%20the%20Azure%20AD%20UI.%20These%20objects%20are%20only%20available%20in%20your%20Azure%20AD%20Domain%20Services%20managed%20domain.%3C%2FEM%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Regular Contributor

Hello

    In Azure AD Domain Service i see default have some ou

    Capture.PNG

    in ADDC Users , i can create new user in here ? and can delete user in here ? if delete or create user in here then it can sync to Active Directory on-premier ?

 Best Regards,

Thanks

2 Replies
Highlighted

If you do not have any admin permssions as domain admin or enterprise admin you should not be allowed to create or remove users from there. The easiest way to do it is to create it through Azure AD and after that once the user is created it will sync up to 20 minutes@Tien Ngo Thanh 

Highlighted
Solution

Hello @Tien Ngo Thanh ! 

 

When you create AAD DS and you are member of "AAD DC Admins" it has limited permissions to managed domain (no domain or enterprise admin permissions). Pretty good list what can be done is found behind this link.

 

Last time I had a possibility to play with AAD Domain Services default permissions for those default OU's were defined so that admin were not able to create users for the OU's. Those were:

  • read permissions for all objects
  • write permissions for gpOptions & gpLink

Another questions was about the synchronization, it's one-way sync from on-premises to AAD Domain Services. If you create user account to own OU it will not be synced back to on-premises.

 

Note for managing custom OU's from docs.microsoft.com:

With a custom OU, you can go ahead and create users, groups, computers, and service accounts in this OU. You cannot move users or groups from the 'AADDC Users' OU to custom OUs.

 

User accounts, groups, service accounts, and computer objects that you create under custom OUs are not available in your Azure AD tenant. In other words, these objects do not show up using the Azure AD Graph API or in the Azure AD UI. These objects are only available in your Azure AD Domain Services managed domain.