Jump to content

Recommended Posts

Posted

Morning all,

 

I'm just getting my head round Azure AD connect and am at a stage where I'm at a bit of a panic that I'm going to end up wiping my onsite AD.

Brief history before today: I setup the Azure ad connect with basic settings and have been syncing up to Azure with no issue (the only reason I want to do this is to allow students and staff to download free office, we use Google Apps for it's cloud features).

 

Due to not simply being able to assign Office pro licences to a group of students (eg 'All students' ou\group) and instead either having to assign a few licences at a time or use powershell I decided I wanted to exclude/remove (from azure, not local) some ou's from syncing up to azure to not include things like assessment users etc.

 

I followed the steps under 'Organizational-unit–based filtering' in this guide : https://azure.microsoft.com/en-us/documentation/articles/active-directory-aadconnectsync-configure-filtering/#organizational-unitbased-filtering

selecting my .local Active Directory Domain Services connector and going into properties, containers etc and deselecting all the OU's that I don't want to sync up to Azure. I then ran full import and delta synchronisation.

 

I then panicked as I'm new to Azure and have limited knowledge on it... Would the above steps actually wipe things from my local AD instead of azure??? should I have done the steps on the Windows Azure Active Directory connector instead???

 

As I'm panicking and don't want to delete anything from local AD I've gone back through my steps on the .local connector and reselected all the containers and then run a full import and a delta sync again.

 

Currently the scheduled Ad azure sync is disabled in task scheduler and I still have the sync service manager open. Is it safe to assume no changes at all will be made during the next sync when I enable it and can I just close the manager? Then do some more research.

 

Sorry for sounding particularly thick on the subject but I've gone into panic mode and am doubting things.

 

Any advice would be appreciated.

 

Thanks

Posted

I can see why you got confused, the tool hasn't got the friendliest interface I've ever come cross. From the sounds of it you have done everything correctly, deselect the OUs you don't want to sync from your local AD and then run a full synchronisation to pull the changes through to Azure AD.

 

Removing items from your local AD will remove them from the Azure AD, it doesn't work the other way round.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...