Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceEasy

A company is implementing Azure AD Connect to synchronize on-premises Active Directory users to Azure AD. They need to ensure that only specific organizational units (OUs) are synchronized to Azure AD to limit the number of cloud identities. Which configuration option in Azure AD Connect should be used to achieve this?

  1. APassword Hash Synchronization
  2. BAttribute Filtering
  3. COU Filtering
  4. DDevice Writeback
Show answer & explanation

Correct answer: C. OU Filtering

OU Filtering in Azure AD Connect allows administrators to select specific organizational units from the on-premises Active Directory to be synchronized to Azure AD, effectively limiting the scope of synchronized objects.

Why the other options are wrong

  • A. Password Hash Synchronization is a method for synchronizing user passwords from on-premises to Azure AD, not for selecting which OUs to synchronize.
  • B. Attribute Filtering is used to include or exclude objects based on specific attribute values, not based on their organizational unit container.
  • D. Device Writeback is an optional feature that writes Azure AD registered devices back to on-premises Active Directory, unrelated to OU synchronization.

OU Filtering (Azure AD Connect)

A feature in Azure AD Connect that enables administrators to specify which organizational units (OUs) from their on-premises Active Directory should be synchronized to Azure Active Directory.

  • Limits the scope of synchronized objects.
  • Configured during or after Azure AD Connect installation.
  • Reduces the number of cloud identities.

Memory trick: Only synchronize the branches you need from your on-premises tree to the cloud.

More Manage Azure identities and governance questions