MS Azure Active directory connect - synch selected group to synch all users and devices

%3CLINGO-SUB%20id%3D%22lingo-sub-2049606%22%20slang%3D%22en-US%22%3EMS%20Azure%20Active%20directory%20connect%20-%20synch%20selected%20group%20to%20synch%20all%20users%20and%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2049606%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3EI%20have%20a%20client%20with%20on%20premise%20exchange%202013.%20I%20set%20up%20azure%20ad%20connect%20to%20synch%20pws%20only%20(pw%20hash%20synchronization)%20for%20a%20selected%20group%20we%20created%20in%20local%20AD.%20This%20works%20good%20and%20everything%20synchs%20no%20problem.%20Now%20we%20want%20to%20start%20synching%20all%20our%20users%20and%20not%20just%20that%20group.%20Has%20anyone%20done%20this%3F%20Are%20there%20any%20things%20to%20look%20out%20for%3F%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2053563%22%20slang%3D%22en-US%22%3ERe%3A%20MS%20Azure%20Active%20directory%20connect%20-%20synch%20selected%20group%20to%20synch%20all%20users%20and%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2053563%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F925115%22%20target%3D%22_blank%22%3E%40jessesan82%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%20you%20need%20to%20be%20aware%20of%20this%20%3A%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EMicrosoft%20doesn't%20support%20modifying%20or%20operating%20Azure%20AD%20Connect%20sync%20outside%20of%20the%20actions%20that%20are%20formally%20documented.%20Any%20of%20these%20actions%20might%20result%20in%20an%20inconsistent%20or%20unsupported%20state%20of%20Azure%20AD%20Connect%20sync.%20As%20a%20result%2C%20Microsoft%20can't%20provide%20technical%20support%20for%20such%20deployments.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3Eand%20that%20%3A%26nbsp%3B%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-sync-configure-filtering%23group-based-filtering%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%3CSTRONG%3EGroup-based%3C%2FSTRONG%3E%3C%2FA%3E%3A%20Filtering%20based%20on%20a%20%3CSTRONG%3Esingle%3C%2FSTRONG%3E%20group%20can%20%3CSTRONG%3Eonly%20be%20configured%3C%2FSTRONG%3E%20on%20initial%20installation%20by%20using%20the%20installation%20wizard.%3C%2FLI%3E%3C%2FUL%3E%3CP%3EIt%20means%20you%20cannot%20repeat%20this%20process%20.%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20you%20need%20to%20do%20is%26nbsp%3B%20use%20so%20you%20can%20sync%20only%20regular%20users%20(it's%20not%20a%20good%20idea%20to%20sync%20priviledged%20admins)%20%3A%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-sync-configure-filtering%23organizational-unitbased-filtering%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%3CSTRONG%3EOrganizational%20unit%20(OU)%E2%80%93based%3C%2FSTRONG%3E%3C%2FA%3E%3A%20By%20using%20this%20option%2C%20you%20can%20select%20which%20OUs%20synchronize%20to%20Azure%20AD.%20This%20option%20is%20for%20all%20object%20types%20in%20selected%20OUs.%3C%2FLI%3E%3C%2FUL%3E%3CP%3EReference%20%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-sync-configure-filtering%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20AD%20Connect%20sync%3A%20Configure%20filtering%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Visitor

I have a client with on premise exchange 2013. I set up azure ad connect to synch pws only (pw hash synchronization) for a selected group we created in local AD. This works good and everything synchs no problem. Now we want to start synching all our users and not just that group. Has anyone done this? Are there any things to look out for?

1 Reply

@jessesan82 

 

Hi you need to be aware of this :  

 

Microsoft doesn't support modifying or operating Azure AD Connect sync outside of the actions that are formally documented. Any of these actions might result in an inconsistent or unsupported state of Azure AD Connect sync. As a result, Microsoft can't provide technical support for such deployments.

 

and that :  

 

  • Group-based: Filtering based on a single group can only be configured on initial installation by using the installation wizard.

It means you cannot repeat this process . 

What you need to do is  use so you can sync only regular users (it's not a good idea to sync priviledged admins) : 

Reference : Azure AD Connect sync: Configure filtering | Microsoft Docs