Entra Group Provision to AD - Leverage Entra Governance Features On-Premises!

Enable group object and membership replication from Entra ID to Active Directory to take advantage of Entra governance for your AD trusting services!
🔎 Looking for content on a particular topic? Search the channel. If I have something it will be there!
🤔 Due to the channel growth and number of people wanting help I no longer can answer or even read questions and they will just stay in the moderation queue never to be seen so please post questions to other sites like Reddit, Microsoft Community Hub etc.
▬▬▬▬▬▬ C H A P T E R S ⏰ ▬▬▬▬▬▬
00:00 - Introduction
00:09 - Entra group governance
02:26 - What about AD?
03:58 - Synchronization and source of authority
05:07 - Group writeback from Entra ID
06:43 - How it works
10:16 - Requirements
12:53 - Configuration of writeback
14:49 - Supported group types
16:37 - Configuring target container in AD
18:26 - Scope filters
19:19 - Attribute mappings
20:30 - Starting the sync and logs
22:03 - What about cloud only user handling?
23:21 - Key group considerations
23:47 - Replication schedule
24:41 - DO NOT EDIT MEMBERSHIP IN AD!
29:29 - Licensing
29:52 - Summary
32:03 - Close
▬▬▬▬▬▬ K E Y L I N K S 🔗 ▬▬▬▬▬▬
► Whiteboard:
🔗 github.com/johnthebrit/Random...
► Microsoft Documentation
🔗 learn.microsoft.com/entra/ide...
🔗 learn.microsoft.com/entra/ide...
▬▬▬▬▬▬ Want to learn more? 🚀 ▬▬▬▬▬▬
📖 Recommended Learning Path for Azure
🔗 learn.onboardtoazure.com
🥇 Certification Content Repository
🔗 github.com/johnthebrit/Certif...
📅 Weekly Azure Update
🔗 • Azure Infrastructure U...
☁ Azure Master Class
🔗 • Microsoft Azure Master...
⚙ DevOps Master Class
🔗 • DevOps Master Class
💻 PowerShell Master Class
🔗 • PowerShell Master Class
🎓 Certification Cram Videos
🔗 • Microsoft Certificatio...
🧠 Mentoring Content
🔗 • Virtual Mentoring
❔ Questions? Maybe I answered it in my FAQ
🔗 savilltech.com/faq
👕 Cure Childhood Cancer Charity T-Shirt Channel Store
🔗 johns-t-shirts-store.creator-...
👂 Enable the subtitles and from there you can translate to your native language via the auto-translate feature in settings! • KZread Captions and A... for a demo of using this feature.
SUBSCRIBE ✅ / @ntfaqguy
#microsoft #azure #johnsavillstechnicaltraining

Пікірлер: 25

  • @NTFAQGuy
    @NTFAQGuy12 күн бұрын

    Govern groups in Entra and use them with your on-premises Active Directory! Please make sure to read the description for the chapters and key information about this video and others. ⚠ P L E A S E N O T E ⚠ 🔎 If you are looking for content on a particular topic search the channel. If I have something it will be there! 🕰 I don't discuss future content nor take requests for future content so please don't ask 😇 🤔 Due to the channel growth and number of people wanting help I no longer can answer or even read questions and they will just stay in the moderation queue never to be seen so please post questions to other sites like Reddit, Microsoft Community Hub etc. 👂 Translate the captions to your native language via the auto-translate feature in settings! kzread.info/dash/bejne/qGmWl5VmgMqrnaw.html for a demo of using this feature. Thanks for watching! 🤙

  • @lesserleeking
    @lesserleeking12 күн бұрын

    If only they could do user writeback, that would make life so much easier. They stopped with this years ago.

  • @The_Cyberz

    @The_Cyberz

    12 күн бұрын

    Sort of. They have HR driven provisioning that will create the on-prem user object.

  • @adrianhorja5336
    @adrianhorja533611 күн бұрын

    This is exactly what I needed for a new project, thank you John.

  • @NTFAQGuy

    @NTFAQGuy

    11 күн бұрын

    Great to hear!

  • @vortical911
    @vortical91110 күн бұрын

    Oof. I guess I need to pay more attention to the deprecation of features. I have been using Group Writeback V2 to write back a mail-enabled M365 dynamic group. The only reason I need it to be mail-enabled is because someone before my time set up a 3rd party integration (Exclaimer) to look at our on-prem AD instead of Azure/Entra, and for some bizarre reason, this integration cannot even 'see' non-mail-enabled groups when linked to on-prem/LDAP 😭 Anywho, we don't have Entra Cloud Sync set up yet, but I guess it's time to dive in since it can be run alongside Entra Connect Sync. Thanks as always John!

  • @ArminBoe
    @ArminBoe12 күн бұрын

    During the time watching the number of views is constantly increasing, guess it is the best answer to your great constantly job, thanks a lot as always to you John

  • @NTFAQGuy

    @NTFAQGuy

    12 күн бұрын

    Thank you!

  • @KenPatterson-vw9yj
    @KenPatterson-vw9yj12 күн бұрын

    Thanks for the video, John. This feature could be useful in the setup we are deploying, so quite timely.

  • @VirtualPackets
    @VirtualPackets11 күн бұрын

    Thanks a again John, very useful and nice demo, was not aware we could use both Entra Connect & Cloud sync simultaneously so learnt something new today 👍

  • @NTFAQGuy

    @NTFAQGuy

    11 күн бұрын

    Very welcome!

  • @heinrichfourie5789
    @heinrichfourie578911 күн бұрын

    Thanks John - As always, clearly explained. Appreciate the time and effort you put into these.

  • @NTFAQGuy

    @NTFAQGuy

    11 күн бұрын

    Very welcome

  • @andykimura
    @andykimura9 күн бұрын

    Great video John! I've been testing EntraID Group Provisioning (Group Writeback) for several months. I noticed today (4/25/2024) that the word PREVIEW has disappeared from the EntraID Cloud Sync config page. Do you know if Microsoft has GA'ed this? Their formal documentation has not been updated yet.

  • @rahulsaikh893
    @rahulsaikh89312 күн бұрын

    Thanks for information Gurudev ❤

  • @NTFAQGuy

    @NTFAQGuy

    12 күн бұрын

    Always welcome

  • @mriw
    @mriw12 күн бұрын

    Very useful thanks John!

  • @NTFAQGuy

    @NTFAQGuy

    12 күн бұрын

    Very welcome!

  • @MoChowdhury-cl5hy
    @MoChowdhury-cl5hy12 күн бұрын

    Great explanation per usual John

  • @NTFAQGuy

    @NTFAQGuy

    12 күн бұрын

    Thanks 👍

  • @yulaw3289
    @yulaw328912 күн бұрын

    enjoying this video for today learning, thanks a lot for supers up-to-date Azure series😇😇😇

  • @NTFAQGuy

    @NTFAQGuy

    12 күн бұрын

    Glad you like them!

  • @markdriver8511
    @markdriver851110 күн бұрын

    Great video thanks :-)

  • @papajohnscookie
    @papajohnscookie12 күн бұрын

    Sounded really good until you mentioned it needing cloud sync and cannot be used with existing groups. Great explanation as always. Edit: didn't realise you could use both connect and cloud sync!

  • @NTFAQGuy

    @NTFAQGuy

    12 күн бұрын

    Right, it's not a big deal to need cloud sync for the provisioning part. You can still replicate with regular Entra Connect.