SOLVED
Home

SharePoint not seeing AD groups

%3CLINGO-SUB%20id%3D%22lingo-sub-1235501%22%20slang%3D%22en-US%22%3ESharePoint%20not%20seeing%20AD%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1235501%22%20slang%3D%22en-US%22%3E%3CP%3EI%20am%20setting%20up%20my%20company's%20SharePoint%20sites.%20Our%20Office%20365%20account%20is%20synchronized%20with%20Active%20Directory.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20working%20on%20configuring%20SharePoint%20security.%20When%20I%20configure%20a%20SharePoint%20group%20(Site%20Settings%20%26gt%3B%20Site%20Permissions%20%26gt%3B%20select%20a%20group%20%26gt%3B%20New)%2C%20I%20can%20add%20a%20user%20account.%20I%20know%20this%20works%20because%20when%20I%20start%20typing%20a%20user%20name%2C%20autocomplete%20lists%20user%20names%20from%20our%20Active%20Directory.%20I%20cannot%20do%20the%20same%20for%20%3CSTRONG%3EActive%20Directory%20groups%3C%2FSTRONG%3E.%20When%20I%20type%20the%20first%20few%20characters%20of%20a%20group%20name%2C%20autocomplete%20does%20not%20list%20the%20group%20I'm%20looking%20for.%20If%20I%20type%20the%20entire%20group%20name%20and%20then%20click%20the%20Share%20button%2C%20nothing%20happens.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20anyone%20give%20some%20clues%20about%20what%20might%20be%20configured%20incorrectly%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECam%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1235501%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Ead%20sync%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1235889%22%20slang%3D%22en-US%22%3ERe%3A%20SharePoint%20not%20seeing%20AD%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1235889%22%20slang%3D%22en-US%22%3EWhen%20did%20you%20sync%20the%20Groups%20to%20Office%20365%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1235919%22%20slang%3D%22en-US%22%3ERe%3A%20SharePoint%20not%20seeing%20AD%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1235919%22%20slang%3D%22en-US%22%3EOur%20AD%20is%20configured%20to%20sync%20to%20Office%20365%20every%2030%20minutes.%20I%20know%20that%20users%20and%20%22distribution%22%20groups%20are%20synced.%20It%20is%20possible%20that%20%22security%22%20groups%20are%20not%20part%20of%20that%20sync%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1235927%22%20slang%3D%22en-US%22%3ERe%3A%20SharePoint%20not%20seeing%20AD%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1235927%22%20slang%3D%22en-US%22%3EThis%20is%20something%20you%20can%20check%20through%20the%20Microsoft%20365%20Admin%20Center%3A%20If%20the%20Groups%20are%20synchronized%2C%20they%20should%20appear%20there%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1236200%22%20slang%3D%22en-US%22%3ERe%3A%20SharePoint%20not%20seeing%20AD%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1236200%22%20slang%3D%22en-US%22%3E%3CP%3EIn%20the%20%3CSPAN%20class%3D%22_1sMs4HtnnjNiwUlomBf_ia%22%3E%3CSTRONG%3EMicrosoft%20365%20admin%20center%3C%2FSTRONG%3E%20home%20screen%2C%20in%20the%20%22Search%20users%2C%20groups%2C%20settings%20or%20tasks%22%20text%20box%2C%20when%20I%20type%20something%2C%20autocomplete%20displays%20users%20and%20distribution%20groups%2C%20but%20not%20security%20groups.%20So%20that%20seems%20to%20confirm%20that%20the%20security%20groups%20are%20not%20being%20synchronized.%20%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22_1sMs4HtnnjNiwUlomBf_ia%22%3EIn%20the%20%3CSTRONG%3ESynchronization%20Service%20Manager%3C%2FSTRONG%3E%2C%20under%20Connectors%20%26gt%3B%20Properties%20%26gt%3B%20Select%20Object%20Types%2C%20the%20%22group%22%20checkbox%20IS%20checked.%20Where%20else%20could%20I%20look%20for%20something%20misconfigured%3F%3CBR%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1253642%22%20slang%3D%22en-US%22%3ERe%3A%20SharePoint%20not%20seeing%20AD%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1253642%22%20slang%3D%22en-US%22%3E%3CP%3EI%20found%20the%20solution.%20Our%20sync%20to%20Azure%20was%20not%20configured%20to%20sync%20the%20OU%20where%20the%20groups%20were%20located.%3C%2FP%3E%3CP%3ETo%20fix%2C%20go%20to%20%3CSTRONG%3EAzure%20AD%20Connect%3C%2FSTRONG%3E%20%26gt%3B%20%3CSTRONG%3EConfigure%3C%2FSTRONG%3E%20%26gt%3B%20%3CSTRONG%3ECustomize%20synchronizations%20options%3C%2FSTRONG%3E%20%26gt%3B%20%3CSTRONG%3EDomain%20%26amp%3B%20OU%20filtering%3C%2FSTRONG%3E.%20Make%20sure%20the%20OU%20is%20selected%2C%20and%20save.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

I am setting up my company's SharePoint sites. Our Office 365 account is synchronized with Active Directory.

 

I am working on configuring SharePoint security. When I configure a SharePoint group (Site Settings > Site Permissions > select a group > New), I can add a user account. I know this works because when I start typing a user name, autocomplete lists user names from our Active Directory. I cannot do the same for Active Directory groups. When I type the first few characters of a group name, autocomplete does not list the group I'm looking for. If I type the entire group name and then click the Share button, nothing happens.

 

Can anyone give some clues about what might be configured incorrectly?

 

Cam

5 Replies
Highlighted
When did you sync the Groups to Office 365?
Highlighted
Our AD is configured to sync to Office 365 every 30 minutes. I know that users and "distribution" groups are synced. It is possible that "security" groups are not part of that sync?
Highlighted
This is something you can check through the Microsoft 365 Admin Center: If the Groups are synchronized, they should appear there
Highlighted

In the Microsoft 365 admin center home screen, in the "Search users, groups, settings or tasks" text box, when I type something, autocomplete displays users and distribution groups, but not security groups. So that seems to confirm that the security groups are not being synchronized.

 

In the Synchronization Service Manager, under Connectors > Properties > Select Object Types, the "group" checkbox IS checked. Where else could I look for something misconfigured?

Highlighted
Solution

I found the solution. Our sync to Azure was not configured to sync the OU where the groups were located.

To fix, go to Azure AD Connect > Configure > Customize synchronizations options > Domain & OU filtering. Make sure the OU is selected, and save.