Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionHard

A company has a hybrid identity environment with Azure AD Connect synchronizing users from an on-premises Active Directory. They observe that some users who are members of a specific security group in on-premises AD are not having their group memberships synchronized to Azure AD. All other user attributes and group memberships appear to synchronize correctly. What is the most likely reason for this issue?

  1. AThe security group contains nested groups, and Azure AD Connect does not support nested group synchronization.
  2. BThe security group is a distribution group, and only universal security groups are synchronized by default.
  3. CThe security group has a very large number of members, exceeding the default synchronization limit.
  4. DThe security group's 'mail' attribute is empty, which is a mandatory attribute for synchronization.
Show answer & explanation

Correct answer: C. The security group has a very large number of members, exceeding the default synchronization limit.

Azure AD Connect has a default limit for the number of members in a group that can be synchronized (by default, 50,000 for groups containing users from on-premises AD to Azure AD). If a security group exceeds this limit, its membership will not be synchronized to Azure AD, although the group object itself may sync.

Why the other options are wrong

  • A. Azure AD Connect does support nested group synchronization; it resolves nested members into direct members in Azure AD.
  • B. Azure AD Connect synchronizes security groups by default, regardless of whether they are universal, global, or domain local, as long as they are security-enabled. Distribution groups are not synced as security groups.
  • D. The 'mail' attribute is not mandatory for a security group object itself to synchronize or for its membership to sync. It's often used for mail-enabled groups but not a strict sync requirement.

Azure AD Connect Group Member Limit

Azure AD Connect has a default limit on the number of members a group can have for its membership to be synchronized to Azure AD.

  • Default limit is 50,000 direct members for groups synchronized to Azure AD.
  • Exceeding this limit prevents membership from syncing, but the group object itself may sync.
  • This limit can be increased, but requires careful consideration of performance and Azure AD limitations.

Memory trick: Group members need enough 'headroom' to cross the sync bridge.

More Implement an identity management solution questions