Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesEasy

A company uses Azure AD Connect to synchronize users from an on-premises Active Directory domain. They want to prevent a specific Organizational Unit (OU) containing service accounts from being synchronized to Azure AD. How can they achieve this using Azure AD Connect?

  1. AMove the OU to a separate, unsynchronized forest.
  2. BImplement a custom synchronization rule to block the OU.
  3. CExclude the OU in the Azure AD Connect wizard during configuration.
  4. DConfigure attribute filtering in Azure AD Connect.
Show answer & explanation

Correct answer: C. Exclude the OU in the Azure AD Connect wizard during configuration.

During the initial configuration or by running the Azure AD Connect wizard again, you can specify which Organizational Units (OUs) from your on-premises Active Directory should be synchronized to Azure AD. This provides a straightforward way to exclude specific OUs.

Why the other options are wrong

  • A. Moving the OU to a separate forest is an architectural change and an overly complex solution for simply excluding an OU from synchronization.
  • B. While possible, creating a custom synchronization rule is a more complex method for a simple OU exclusion that can be handled by the wizard.
  • D. Attribute filtering is used to exclude objects based on attribute values, not typically for entire OUs.

Azure AD Connect OU Filtering

The ability to select which Organizational Units from on-premises Active Directory are synchronized to Azure AD.

  • Configured during initial setup or by re-running the wizard.
  • Prevents objects within excluded OUs from being synchronized.
  • Helps manage the scope of synchronized identities.

Memory trick: Filter What Goes Up, Keep What Stays Down.

More Implement and manage hybrid identities questions