Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionEasy
A company is planning to deploy Azure AD Connect for synchronizing user accounts from their on-premises Active Directory to Azure AD. They want to ensure that only users from specific departments, such as 'Sales' and 'Marketing', are synchronized, while all other users remain only in the on-premises directory. Which synchronization filtering method should they implement?
- AOrganizational Unit (OU) filtering
- BGroup-based filtering
- CDomain-based filtering
- DAttribute-based filtering
Show answer & explanationAnswer & explanation
Correct answer: A. Organizational Unit (OU) filtering
OU filtering allows administrators to select specific organizational units from their on-premises Active Directory to be synchronized to Azure AD, effectively excluding entire departments or user groups not located in those OUs.
Why the other options are wrong
- B. Group-based filtering is not a standard, built-in filtering option for Azure AD Connect synchronization scope for user objects; it's typically used for group writeback or specific scenarios, not primary user synchronization filtering.
- C. Domain-based filtering is used for multi-domain environments to select which domains to synchronize, not specific departments within a domain.
- D. Attribute-based filtering uses specific user attributes for filtering, which is more granular but less direct for filtering by department than OUs.
Azure AD Connect OU Filtering
A feature in Azure AD Connect that allows administrators to specify which Organizational Units (OUs) from an on-premises Active Directory should be synchronized to Azure AD.
- Controls the scope of synchronized objects.
- Configured during Azure AD Connect installation or post-installation.
- Helps manage which users/groups appear in Azure AD.
Memory trick: Filter out the noise, only sync what you need.