Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionEasy
A company is deploying Azure AD Connect to synchronize user accounts from an on-premises Active Directory forest to Azure AD. They have a specific requirement to exclude a particular Organizational Unit (OU) containing service accounts from being synchronized to Azure AD. Which synchronization filtering method should be used to achieve this exclusion?
- AAttribute-based filtering
- BGroup-based filtering
- COrganizational Unit (OU)-based filtering
- DDomain-based filtering
Show answer & explanationAnswer & explanation
Correct answer: C. Organizational Unit (OU)-based filtering
Organizational Unit (OU)-based filtering in Azure AD Connect allows administrators to select which OUs to synchronize or exclude from synchronization, making it ideal for excluding specific OUs like those containing service accounts.
Why the other options are wrong
- A. Attribute-based filtering uses specific attributes (e.g., 'department') to include or exclude objects, which is more granular than needed for an entire OU.
- B. Group-based filtering synchronizes only members of specific groups, which is not the most direct method for excluding an entire OU.
- D. Domain-based filtering includes or excludes entire domains, not specific OUs within a domain.
Azure AD Connect OU Filtering
A synchronization filtering method in Azure AD Connect that allows specifying which Organizational Units (OUs) from on-premises Active Directory should be synchronized to Azure AD.
- Simplest and most common filtering method for large-scale exclusions.
- Configured during Azure AD Connect installation or via the wizard.
- Allows granular control over which parts of the AD hierarchy are synced.
Memory trick: Filtering options: OU, Domain, or Attribute, choose wisely to sync.