Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesEasy

A company is implementing Azure AD Connect for the first time. They have an existing on-premises Active Directory with multiple child domains and want to ensure that all user objects from all domains are synchronized to Azure AD. Which synchronization scope should they select during the Azure AD Connect configuration?

  1. ASynchronize only the root domain
  2. BSynchronize selected OUs only
  3. CSynchronize all domains and OUs
  4. DSynchronize users based on specific attributes
Show answer & explanation

Correct answer: C. Synchronize all domains and OUs

To ensure all user objects from all domains are synchronized, selecting 'Synchronize all domains and OUs' during the Azure AD Connect configuration is the most direct and comprehensive option. This ensures that the entire Active Directory forest is included in the synchronization scope by default.

Why the other options are wrong

  • A. Synchronizing only the root domain would exclude users in child domains.
  • B. Synchronizing selected OUs would exclude users in non-selected OUs and other domains.
  • D. Synchronizing based on specific attributes is attribute filtering and would not guarantee all users from all domains unless carefully configured, which is more complex than simply selecting all domains.

Azure AD Connect Synchronization Scope

The definition of which objects (users, groups, devices) from which parts of the on-premises Active Directory forest are synchronized to Azure AD.

  • Configured during the Azure AD Connect wizard.
  • Can be filtered by domains, OUs, or attributes.
  • Determines the initial set of objects for synchronization.

Memory trick: Scope It All, Or Pick and Choose, Don't Miss a Bit.

More Implement and manage hybrid identities questions