Entra Group Provision to AD - Leverage Entra Governance Features On-Premises!
Enable group object and membership replication from Entra ID to Active Directory to take advantage of Entra governance for your AD trusting services!
🔎 Looking for content on a particular topic? Search the channel. If I have something it will be there!
🤔 Due to the channel growth and number of people wanting help I no longer can answer or even read questions and they will just stay in the moderation queue never to be seen so please post questions to other sites like Reddit, Microsoft Community Hub etc.
▬▬▬▬▬▬ C H A P T E R S ⏰ ▬▬▬▬▬▬
00:00 - Introduction
00:09 - Entra group governance
02:26 - What about AD?
03:58 - Synchronization and source of authority
05:07 - Group writeback from Entra ID
06:43 - How it works
10:16 - Requirements
12:53 - Configuration of writeback
14:49 - Supported group types
16:37 - Configuring target container in AD
18:26 - Scope filters
19:19 - Attribute mappings
20:30 - Starting the sync and logs
22:03 - What about cloud only user handling?
23:21 - Key group considerations
23:47 - Replication schedule
24:41 - DO NOT EDIT MEMBERSHIP IN AD!
29:29 - Licensing
29:52 - Summary
32:03 - Close
▬▬▬▬▬▬ K E Y L I N K S 🔗 ▬▬▬▬▬▬
► Whiteboard:
🔗 github.com/johnthebrit/Random...
► Microsoft Documentation
🔗 learn.microsoft.com/entra/ide...
🔗 learn.microsoft.com/entra/ide...
▬▬▬▬▬▬ Want to learn more? 🚀 ▬▬▬▬▬▬
📖 Recommended Learning Path for Azure
🔗 learn.onboardtoazure.com
🥇 Certification Content Repository
🔗 github.com/johnthebrit/Certif...
📅 Weekly Azure Update
🔗 • Azure Infrastructure U...
☁ Azure Master Class
🔗 • Microsoft Azure Master...
⚙ DevOps Master Class
🔗 • DevOps Master Class
💻 PowerShell Master Class
🔗 • PowerShell Master Class
🎓 Certification Cram Videos
🔗 • Microsoft Certificatio...
🧠 Mentoring Content
🔗 • Virtual Mentoring
❔ Questions? Maybe I answered it in my FAQ
🔗 savilltech.com/faq
👕 Cure Childhood Cancer Charity T-Shirt Channel Store
🔗 johns-t-shirts-store.creator-...
👂 Enable the subtitles and from there you can translate to your native language via the auto-translate feature in settings! • KZread Captions and A... for a demo of using this feature.
SUBSCRIBE ✅ / @ntfaqguy
#microsoft #azure #johnsavillstechnicaltraining
Пікірлер: 25
Govern groups in Entra and use them with your on-premises Active Directory! Please make sure to read the description for the chapters and key information about this video and others. ⚠ P L E A S E N O T E ⚠ 🔎 If you are looking for content on a particular topic search the channel. If I have something it will be there! 🕰 I don't discuss future content nor take requests for future content so please don't ask 😇 🤔 Due to the channel growth and number of people wanting help I no longer can answer or even read questions and they will just stay in the moderation queue never to be seen so please post questions to other sites like Reddit, Microsoft Community Hub etc. 👂 Translate the captions to your native language via the auto-translate feature in settings! kzread.info/dash/bejne/qGmWl5VmgMqrnaw.html for a demo of using this feature. Thanks for watching! 🤙
If only they could do user writeback, that would make life so much easier. They stopped with this years ago.
@The_Cyberz
12 күн бұрын
Sort of. They have HR driven provisioning that will create the on-prem user object.
This is exactly what I needed for a new project, thank you John.
@NTFAQGuy
11 күн бұрын
Great to hear!
Oof. I guess I need to pay more attention to the deprecation of features. I have been using Group Writeback V2 to write back a mail-enabled M365 dynamic group. The only reason I need it to be mail-enabled is because someone before my time set up a 3rd party integration (Exclaimer) to look at our on-prem AD instead of Azure/Entra, and for some bizarre reason, this integration cannot even 'see' non-mail-enabled groups when linked to on-prem/LDAP 😭 Anywho, we don't have Entra Cloud Sync set up yet, but I guess it's time to dive in since it can be run alongside Entra Connect Sync. Thanks as always John!
During the time watching the number of views is constantly increasing, guess it is the best answer to your great constantly job, thanks a lot as always to you John
@NTFAQGuy
12 күн бұрын
Thank you!
Thanks for the video, John. This feature could be useful in the setup we are deploying, so quite timely.
Thanks a again John, very useful and nice demo, was not aware we could use both Entra Connect & Cloud sync simultaneously so learnt something new today 👍
@NTFAQGuy
11 күн бұрын
Very welcome!
Thanks John - As always, clearly explained. Appreciate the time and effort you put into these.
@NTFAQGuy
11 күн бұрын
Very welcome
Great video John! I've been testing EntraID Group Provisioning (Group Writeback) for several months. I noticed today (4/25/2024) that the word PREVIEW has disappeared from the EntraID Cloud Sync config page. Do you know if Microsoft has GA'ed this? Their formal documentation has not been updated yet.
Thanks for information Gurudev ❤
@NTFAQGuy
12 күн бұрын
Always welcome
Very useful thanks John!
@NTFAQGuy
12 күн бұрын
Very welcome!
Great explanation per usual John
@NTFAQGuy
12 күн бұрын
Thanks 👍
enjoying this video for today learning, thanks a lot for supers up-to-date Azure series😇😇😇
@NTFAQGuy
12 күн бұрын
Glad you like them!
Great video thanks :-)
Sounded really good until you mentioned it needing cloud sync and cannot be used with existing groups. Great explanation as always. Edit: didn't realise you could use both connect and cloud sync!
@NTFAQGuy
12 күн бұрын
Right, it's not a big deal to need cloud sync for the provisioning part. You can still replicate with regular Entra Connect.