O365 Group Writeback (AADConnect)

Silver Contributor

We just enabled O365 Group Writeback via AADConnect to bring out O365 Groups back on prem.  They are created as Distribution Lists.

 

Are we able to change those to Security Groups so that they can leveraged elsewhere as security objects?  Will they get overwritten as DL's again on the next sync?  Or are they only limited to being DLs?

12 Replies
bump for any comment?

Cross-posted from "https://techcommunity.microsoft.com/t5/Office-365-Groups/O365-Group-Writeback-AADConnect/m-p/31472#M..."

 

We just enabled O365 Group Writeback via AADConnect to bring out O365 Groups back on prem.  They are created as Distribution Lists.

 

Are we able to change those to Security Groups so that they can leveraged elsewhere as security objects?  Will they get overwritten as DL's again on the next sync?  Or are they only limited to being DLs?

AFAIK, AADConnect creates DGs and not SGs. You don't get to vote.

 

Unless you follow the steps in http://robsgroupsblog.com/blog/how-to-write-back-an-office-group-in-azure-active-directory-to-a-mail..., in the understanding that these steps are unsupported. But it might work for you.

Hi Tony

 

This link doesn't work anymore, please help. I got this link from Office 365 for IT Pro

 

http://robsgroupsblog.com/blog/how-to-write-back-an-office-group-in-azure-active-directory-to-a-mail...

Which version of the book? We scan and remove outdated hyperlinks on an ongoing basis because they disappear all the time.

 

Does https://syscloudpro.com/2017/01/08/office-365-groups-write-back-without-azure-ad-premium/ help?

Could you tell me the version of the book (inside front cover) and the chapter/heading where this hyperlink exists? I can't find it in the current book....

This is update 5 published on 4 August 2018. in companion book. page 132procedure.jpg

My environment - Exchange 2010 Hybrid with 100 % mailboxes in cloud. Disabled centralized transport, migrating to Exchange 2016 in next 2 months as only SMTP traffic ( application printer, scanner).

 

Question -  I read book and this is great knowledge so thank you for that. My senior leadership wants to use local EXchange 2010 DLs for managing office 365 groups. I have informed that this is not possible as Onrem, EXODS and Azure are different worlds.

 

Also they want to use office 365 group dynamically, in this situation where my 100 % mailboxes are in cloud , Azure connect writeback feature won't be of any use to me , please do suggest.

 

Also if i use Azure portal and create dynamic group, users cant leave unless I remove dynamic query.

 

By any chance, do you think i will be able to use Local DLs  ?

 

 

My environment - Exchange 2010 Hybrid with 100 % mailboxes in cloud. Disabled centralized transport, migrating to Exchange 2016 in next 2 months as only SMTP traffic ( application printer, scanner).

 

Question -  I read book and this is great knowledge so thank you for that. My senior leadership wants to use local EXchange 2010 DLs for managing office 365 groups. I have informed that this is not possible as Onrem, EXODS and Azure are different worlds.

 

Also they want to use office 365 group dynamically, in this situation where my 100 % mailboxes are in cloud , Azure connect writeback feature won't be of any use to me , please do suggest.

 

Also if i use Azure portal and create dynamic group, users cant leave unless I remove dynamic query.

 

By any chance, do you think i will be able to use Local DLs  ?

Also they want to use office 365 group dynamically, in this situation where my 100 % mailboxes are in cloud , Azure connect writeback feature won't be of any use to me , please do suggest.

 

TR: You can create dynamic Office 365 Groups and maintain their membership using attributes in Azure AD. Office 365 Groups can only contain cloud mailboxes, so you will be all set. The groups can be written back to the on-premises directory, but without membership.

 

Also if i use Azure portal and create dynamic group, users cant leave unless I remove dynamic query.

 

TR: Or you update an attribute of their account.

 

Thank you so much, my vision is clear now :)