MicrosoftDocs / azure-docs

Open source documentation of Microsoft Azure
https://docs.microsoft.com/azure
Creative Commons Attribution 4.0 International
10.25k stars 21.42k forks source link

Not agreeing with approach #89643

Closed RZomermanMS closed 2 years ago

RZomermanMS commented 2 years ago

[Enter feedback here]

I have to object against this way of establishing the immutableID between the groups. There are some fundamental problems with this approach:

A better solution is to writeback the mS-DS-ConsistencyGuid to the F1 (SOURCE) group and have it copy automatically during ADMT copying to the F2 group.

see: https://blog.azureinfra.com/2022/03/10/immutableid-ms-ds-consistencyguid-aadconnect-admt-part-4-groups/

You should also make a note that group membership is NOT merged, but instead the first domain wins.. (meaning always F1) and changes made directly to F2 are not reflected in AAD - UNLESS a change is made in the ruleset.

(Roelf)

Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

AnuragSharma-MSFT commented 2 years ago

@RZomermanMS Thank you for the feedback. We are actively investigating and will get back to you soon.

shashishailaj commented 2 years ago

@RZomermanMS We are going to engage on this internally and will create a review item internally for this one with the Azure AD connect content team with your suggestions and copy you there as well. Once the discussion is done , we will update the document as per the outcome.