Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Entra IDMedium
A client is migrating its on-premises Active Directory Domain Services (AD DS) users to Microsoft Entra ID. The client wants to ensure that all user objects are synchronized, but only specific attributes (e.g., mail, sAMAccountName, userPrincipalName, displayName) should be synchronized to Microsoft Entra ID for privacy and compliance reasons. Other attributes, such as employeeID or personal details, must be excluded. Which Microsoft Entra Connect feature should be used to achieve this?
- AGroup-based filtering
- BAttribute filtering
- COU filtering
- DDomain filtering
Show answer & explanationAnswer & explanation
Correct answer: B. Attribute filtering
Attribute filtering in Microsoft Entra Connect allows you to control which specific attributes of synchronized objects are provisioned to Microsoft Entra ID. This is crucial for privacy and compliance when only a subset of attributes is required in the cloud.
Why the other options are wrong
- A. Group-based filtering determines which objects are synchronized, not which attributes of those objects are synchronized.
- C. OU filtering excludes entire OUs, not specific attributes of objects within them.
- D. Domain filtering excludes entire domains, which is too broad for this requirement.
Microsoft Entra Connect Attribute Filtering
Microsoft Entra Connect Attribute filtering enables administrators to specify which attributes of synchronized objects are allowed to flow from on-premises Active Directory to Microsoft Entra ID. This helps manage data privacy and reduce the data footprint in the cloud.
- Controls specific properties of objects.
- Configured via Synchronization Rules Editor.
- Important for privacy and compliance.
Memory trick: Attributes: Pick Your Properties Wisely