Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionEasy

A company is using Azure AD Connect to synchronize user accounts from an on-premises Active Directory to Azure AD. They want to prevent specific user accounts, located in a particular Organizational Unit (OU) named 'Contractors', from being synchronized to Azure AD. What is the most efficient way to achieve this?

  1. AMove the 'Contractors' OU to a different domain not synchronized by Azure AD Connect.
  2. BDisable the 'Contractors' OU in the Azure AD Connect synchronization scope.
  3. CConfigure attribute-based filtering in Azure AD Connect.
  4. DImplement group-based filtering for the 'Contractors' OU.
Show answer & explanation

Correct answer: B. Disable the 'Contractors' OU in the Azure AD Connect synchronization scope.

Azure AD Connect allows direct OU-based filtering during the synchronization configuration. Disabling the 'Contractors' OU in the synchronization scope prevents any objects within it from being synchronized.

Why the other options are wrong

  • A. Moving the OU to another domain is an unnecessary and disruptive change to the on-premises AD structure.
  • C. Attribute-based filtering is possible but more complex than direct OU filtering for this scenario.
  • D. Group-based filtering is used for including specific groups, not for excluding an entire OU efficiently.

Azure AD Connect OU Filtering

Azure AD Connect allows administrators to include or exclude specific Organizational Units (OUs) from synchronization, controlling which objects are provisioned to Azure AD.

  • Configurable during Azure AD Connect installation or later.
  • Prevents objects within excluded OUs from synchronizing.
  • Efficient for bulk exclusion of users/groups.

Memory trick: Connect filtering is like a sieve for your identities.

More Implement an identity management solution questions