Can i manage Sharepoint Online Permissions with AD?

%3CLINGO-SUB%20id%3D%22lingo-sub-2363176%22%20slang%3D%22en-US%22%3ECan%20i%20manage%20Sharepoint%20Online%20Permissions%20with%20AD%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2363176%22%20slang%3D%22en-US%22%3E%3CP%3EMorning.%3C%2FP%3E%3CP%3EWe%20use%20Office%20365%20with%20a%20hybrid%20set%20up.%20We%20create%20our%20Security%20%2F%20distribution%20gruops%20in%20our%20On%20prem%20Exchange%20which%20then%20syncs%20to%20O365.%20I%20want%20to%20use%20Security%20groups%20in%20our%20On%20prem%20AD%20to%20control%20security%20groups%20in%20SharePoint%20online.%3C%2FP%3E%3CP%3EWhen%20i%20try%20to%20add%20people%20to%20SPO%20groups%20(members%2C%20owner%2C%20visitor%20o%20a%20new%20created%20group)%20i%20can%20only%20see%20individual%20users%2C%20or%20already%20existing%20SharePoint%20sites.%3C%2FP%3E%3CP%3EI%20read%20in%20different%20forums%20people%20is%20able%20to%20do%20it%20but%20haven't%20been%20able%20to%20find%20how%20to%20do%20it.%3C%2FP%3E%3CP%3EIf%20anybody%20has%20any%20information%20please...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethank%20you%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2363176%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EPermissions%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESharePoint%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESites%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2364011%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20i%20manage%20Sharepoint%20Online%20Permissions%20with%20AD%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2364011%22%20slang%3D%22en-US%22%3EYes%2C%20but%20you%20need%20to%20sync%20your%20local%20AD%20with%20Azure%20AD%20through%20Azure%20AD%20Connect%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2364397%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20i%20manage%20Sharepoint%20Online%20Permissions%20with%20AD%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2364397%22%20slang%3D%22en-US%22%3EThank%20you%20for%20the%20info.%20that%20is%20what%20we%20expected.%3CBR%20%2F%3ECan%20you%20recommed%20any%20literature%20or%20pages%20with%20information%20on%20how%20to%20best%20manage%20security%20%2F%20access%20%2F%20permission%20groups%20in%20sharepoint%3F%20there%20are%20some%20many%20different%20opinions%20that%20i%20am%20getting%20a%20bit%20confuse%20(to%20create%20my%20onw%20user%20groups%20or%20use%20Member%20%2F%20owner%20groups%20in%20sharepoint%20for%20example)%20thank%20you%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Morning.

We use Office 365 with a hybrid set up. We create our Security / distribution gruops in our On prem Exchange which then syncs to O365. I want to use Security groups in our On prem AD to control security groups in SharePoint online.

When i try to add people to SPO groups (members, owner, visitor o a new created group) i can only see individual users, or already existing SharePoint sites.

I read in different forums people is able to do it but haven't been able to find how to do it.

If anybody has any information please...

 

thank you

5 Replies
Yes, but you need to sync your local AD with Azure AD through Azure AD Connect
Thank you for the info. that is what we expected.
Can you recommed any literature or pages with information on how to best manage security / access / permission groups in sharepoint? there are some many different opinions that i am getting a bit confuse (to create my onw user groups or use Member / owner groups in sharepoint for example) thank you

The Sharing functionality in SharePoint/OneDrive/Teams uses SharePoint Security Groups to give people access to items that have been shared. It creates a new SharePoint Security Group every time a new Sharing link is created for an item. You might want to consider that before you spend too much time worrying about SharePoint permissions in the first place.

However, if you are going to try using AD security groups to manage access and permissions to SharePoint sites, one good approach is to use a combination of SharePoint Security Groups plus AD Security Groups inside of those SharePoint Security Groups.

For example, every SharePoint site comes with three SharePoint Security Groups - Owners (Full Control), Members (Edit), and Visitors (Read). You should put your AD Security groups inside one of these default SharePoint Security Groups.

That is great thank you very much for your reply.
We were thinking of using the existing AD groups and as you said, add them to the security groups in SP.
Regarding Security Groups in SP, is it still not recommended to create customised Security Groups? (for example, if i want somebody to have visitor permissions for most things but want them to be able add items to a list)?
Thanks again

I would again suggest understanding the Share functionality in SharePoint before getting too far into trying to control access and permissions via groups.

However, if your situation calls for using AD Security Groups and SharePoint Security Groups, I don't see a problem in using them. I have created SharePoint Security Groups for a specific List or Library if I needed to give people a different level of permissions to that particular list or library.

For example, if our HR department has Read access to most of a SharePoint site, they will be in the SharePoint Visitors group to give them that access. But then if I need the HR department to have Edit access to a specific HR Document Library, I would probably create a SharePoint Security Group specifically for assigning Edit permissions on that HR Document library and then add the HR department to that group.

SharePoint Online has made it a little more difficult to get to the Groups page in site settings to create a new SharePoint Security Group, but you can still get there when needed.