Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesHard
A company has implemented Azure AD Connect and is synchronizing user accounts. They recently renamed an organizational unit (OU) in their on-premises Active Directory. After the next synchronization cycle, they notice that users from the renamed OU are no longer visible in Azure AD. What is the most likely reason for this issue?
- APassword writeback is not enabled in Azure AD Connect.
- BThe Azure AD Connect Health agent is unhealthy.
- CThe Azure AD Connect server requires a reboot after an OU rename.
- DThe renamed OU was not included in the synchronization scope.
Show answer & explanationAnswer & explanation
Correct answer: D. The renamed OU was not included in the synchronization scope.
When an organizational unit (OU) is renamed, its distinguished name changes. If Azure AD Connect is configured to synchronize specific OUs, the renamed OU might no longer match the configured synchronization scope, causing its contents (users) to be de-provisioned from Azure AD.
Why the other options are wrong
- A. Password writeback is for synchronizing passwords from Azure AD to on-premises, not for object synchronization from on-premises to Azure AD.
- B. An unhealthy Health agent would impact monitoring, not necessarily stop synchronization of a specific OU.
- C. An OU rename does not typically require an Azure AD Connect server reboot; a full synchronization cycle should pick up changes if the scope is correct.
Azure AD Connect OU Renaming Impact
The effect of renaming an Organizational Unit (OU) in on-premises Active Directory on Azure AD Connect synchronization, potentially leading to de-provisioning of objects.
- Renaming an OU changes its Distinguished Name (DN).
- Synchronization scope filters often rely on OUs' DNs.
- Requires updating Azure AD Connect synchronization filters if specific OUs are selected.
Memory trick: Renaming the 'folder' means the 'sync list' needs an update.