In Azure AD Connect , after installation, admins can exclude certain objects (users, OUs, attributes, groups, etc.) from synchronization. This is typically done during or after setup to control which parts of your on-premises Active Directory are synced to Azure AD . ✅ 1. Unchecking Organizational Units (OUs) During setup or in Azure AD Connect > Synchronization Rules Editor / Configuration Wizard , users can select specific OUs to sync. 👉 If they uncheck an OU , it means: Objects inside that OU (users, groups, etc.) will not be synced to Azure AD. Useful for: Excluding service accounts, test users, or sensitive data. Managing sync scope for performance or security reasons. 📌 Where to find it: Azure AD Connect > Customize synchronization options > Domain and OU filtering ✅ 2. Attribute Filtering (Advanced) Admins can also exclude attributes from syncing using custom sync rules. For example: You may want to prevent syncing attributes like...
Hey there! 👋 I'm Rajeswary Nadarajan. I’m on an exciting journey, transitioning into Azure Cloud Security Architect, and I’ve created this space to document everything—my learning experiences, challenges, wins, and insights. Whether it’s mastering cloud technologies, tackling certifications, or exploring the latest in Azure, data, and cloud engineering, I’ll be sharing it all here.