Entra Group Provision to AD - Leverage Entra Governance Features On-Premises!

Поділитися
Вставка
  • Опубліковано 11 чер 2024
  • Enable group object and membership replication from Entra ID to Active Directory to take advantage of Entra governance for your AD trusting services!
    🔎 Looking for content on a particular topic? Search the channel. If I have something it will be there!
    🤔 Due to the channel growth and number of people wanting help I no longer can answer or even read questions and they will just stay in the moderation queue never to be seen so please post questions to other sites like Reddit, Microsoft Community Hub etc.
    ▬▬▬▬▬▬ C H A P T E R S ⏰ ▬▬▬▬▬▬
    00:00 - Introduction
    00:09 - Entra group governance
    02:26 - What about AD?
    03:58 - Synchronization and source of authority
    05:07 - Group writeback from Entra ID
    06:43 - How it works
    10:16 - Requirements
    12:53 - Configuration of writeback
    14:49 - Supported group types
    16:37 - Configuring target container in AD
    18:26 - Scope filters
    19:19 - Attribute mappings
    20:30 - Starting the sync and logs
    22:03 - What about cloud only user handling?
    23:21 - Key group considerations
    23:47 - Replication schedule
    24:41 - DO NOT EDIT MEMBERSHIP IN AD!
    29:29 - Licensing
    29:52 - Summary
    32:03 - Close
    ▬▬▬▬▬▬ K E Y L I N K S 🔗 ▬▬▬▬▬▬
    ► Whiteboard:
    🔗 github.com/johnthebrit/Random...
    ► Microsoft Documentation
    🔗 learn.microsoft.com/entra/ide...
    🔗 learn.microsoft.com/entra/ide...
    ▬▬▬▬▬▬ Want to learn more? 🚀 ▬▬▬▬▬▬
    📖 Recommended Learning Path for Azure
    🔗 learn.onboardtoazure.com
    🥇 Certification Content Repository
    🔗 github.com/johnthebrit/Certif...
    📅 Weekly Azure Update
    🔗 • Azure Infrastructure U...
    ☁ Azure Master Class
    🔗 • Microsoft Azure Master...
    ⚙ DevOps Master Class
    🔗 • DevOps Master Class
    💻 PowerShell Master Class
    🔗 • PowerShell Master Class
    🎓 Certification Cram Videos
    🔗 • Microsoft Certificatio...
    🧠 Mentoring Content
    🔗 • Virtual Mentoring
    ❔ Questions? Maybe I answered it in my FAQ
    🔗 savilltech.com/faq
    👕 Cure Childhood Cancer Charity T-Shirt Channel Store
    🔗 johns-t-shirts-store.creator-...
    👂 Enable the subtitles and from there you can translate to your native language via the auto-translate feature in settings! • UA-cam Captions and A... for a demo of using this feature.
    SUBSCRIBE ✅ / @ntfaqguy
    #microsoft #azure #johnsavillstechnicaltraining

КОМЕНТАРІ • 26

  • @NTFAQGuy
    @NTFAQGuy  Місяць тому +6

    Govern groups in Entra and use them with your on-premises Active Directory! Please make sure to read the description for the chapters and key information about this video and others.
    ⚠ P L E A S E N O T E ⚠
    🔎 If you are looking for content on a particular topic search the channel. If I have something it will be there!
    🕰 I don't discuss future content nor take requests for future content so please don't ask 😇
    🤔 Due to the channel growth and number of people wanting help I no longer can answer or even read questions and they will just stay in the moderation queue never to be seen so please post questions to other sites like Reddit, Microsoft Community Hub etc.
    👂 Translate the captions to your native language via the auto-translate feature in settings! ua-cam.com/video/v5b53-PgEmI/v-deo.html for a demo of using this feature.
    Thanks for watching!
    🤙

  • @kokkosbollful
    @kokkosbollful Місяць тому

    Many thanks John, this is exactly what i need for a new project I’m working on! You are the GOAT 🥂

  • @adrianhorja5336
    @adrianhorja5336 Місяць тому +1

    This is exactly what I needed for a new project, thank you John.

  • @ArminBoe
    @ArminBoe Місяць тому +1

    During the time watching the number of views is constantly increasing, guess it is the best answer to your great constantly job, thanks a lot as always to you John

  • @heinrichfourie5789
    @heinrichfourie5789 Місяць тому

    Thanks John - As always, clearly explained. Appreciate the time and effort you put into these.

  • @rahulsaikh893
    @rahulsaikh893 Місяць тому +1

    Thanks for information Gurudev ❤

  • @MoChowdhury-cl5hy
    @MoChowdhury-cl5hy Місяць тому +1

    Great explanation per usual John

  • @mriw
    @mriw Місяць тому +1

    Very useful thanks John!

  • @yulaw3289
    @yulaw3289 Місяць тому +1

    enjoying this video for today learning, thanks a lot for supers up-to-date Azure series😇😇😇

    • @NTFAQGuy
      @NTFAQGuy  Місяць тому

      Glad you like them!

  • @VirtualPackets
    @VirtualPackets Місяць тому

    Thanks a again John, very useful and nice demo, was not aware we could use both Entra Connect & Cloud sync simultaneously so learnt something new today 👍

  • @markdriver8511
    @markdriver8511 Місяць тому

    Great video thanks :-)

  • @KenPatterson-vw9yj
    @KenPatterson-vw9yj Місяць тому

    Thanks for the video, John. This feature could be useful in the setup we are deploying, so quite timely.

  • @vortical911
    @vortical911 Місяць тому

    Oof. I guess I need to pay more attention to the deprecation of features.
    I have been using Group Writeback V2 to write back a mail-enabled M365 dynamic group. The only reason I need it to be mail-enabled is because someone before my time set up a 3rd party integration (Exclaimer) to look at our on-prem AD instead of Azure/Entra, and for some bizarre reason, this integration cannot even 'see' non-mail-enabled groups when linked to on-prem/LDAP 😭
    Anywho, we don't have Entra Cloud Sync set up yet, but I guess it's time to dive in since it can be run alongside Entra Connect Sync. Thanks as always John!

  • @andykimura
    @andykimura Місяць тому +1

    Great video John! I've been testing EntraID Group Provisioning (Group Writeback) for several months. I noticed today (4/25/2024) that the word PREVIEW has disappeared from the EntraID Cloud Sync config page. Do you know if Microsoft has GA'ed this? Their formal documentation has not been updated yet.

  • @lesserleeking
    @lesserleeking Місяць тому +7

    If only they could do user writeback, that would make life so much easier. They stopped with this years ago.

    • @The_Cyberz
      @The_Cyberz Місяць тому +1

      Sort of. They have HR driven provisioning that will create the on-prem user object.

  • @papajohnscookie
    @papajohnscookie Місяць тому +1

    Sounded really good until you mentioned it needing cloud sync and cannot be used with existing groups. Great explanation as always. Edit: didn't realise you could use both connect and cloud sync!

    • @NTFAQGuy
      @NTFAQGuy  Місяць тому +5

      Right, it's not a big deal to need cloud sync for the provisioning part. You can still replicate with regular Entra Connect.