When first synchronizing your on-premises Active Directory (AD) to Azure AD, it’s important to understand what Groups can and cannot be synchronized from on-premises AD. The table belowprovides an at a glance view. This can save time and prevent duplication and re-work.
The first column identifies the “Target” or new Office 365 entity that can be created, as defined by the second column. The third column identifies the current “source” group which can be re-used/sync’d, along with an explanation in the fourth column. The fifth and last column shows which entities can beconfigured for dynamic membership in Azure Active Directory, allowing group members to be added or removed automatically based on user attributes such as department, location, title, etc.
O365 Entity |
Purpose |
Corresponding on-prem AD group to sync |
Comments / Recommendations |
Configurable by Dynamic Membership? |
Office 365 Groups |
Collaboration between users, both inside and outside your company. |
Distribution List (or Distribution Group) |
MSFT provides a tool to convert on-prem distribution list to an O365 Group. That is a full group, and includes Planner, OneNote, etc. for that group, not just a distribution group. |
Yes, or also could be manually assigned |
Distribution Lists |
Sending notifications to a list of people. |
Distribution List (or Distribution Group) |
|
No |
Security Groups |
Granting access to resources like SharePoint. |
Security Group |
- |
Yes, but also could be manually assigned. |
Mail-enabled Security Groups |
Granting access to SharePoint resources, and emailing notifications to those users. |
Mail-enabled Security Group |
|
No |
Shared Mailboxes |
Used when multiple people need access to the same mailbox, such as a company information orsupport email address. |
- |
|
No |
N/A |
- |
Built-in security groups Large security groups |
|
- |
Sources:
https://docs.microsoft.com/en-us/office365/admin/create-groups/compare-groups?view=o365-worldwide
The entire list of attributes that are synchronized by Azure AD Connect sync can be found at:https://docs.microsoft.com/en-us/azure/active-directory/hybrid/reference-connect-sync-attributes-synchronized