Closed RZomermanMS closed 2 years ago
@RZomermanMS Thank you for the feedback. We are actively investigating and will get back to you soon.
@RZomermanMS We are going to engage on this internally and will create a review item internally for this one with the Azure AD connect content team with your suggestions and copy you there as well. Once the discussion is done , we will update the document as per the outcome.
[Enter feedback here]
I have to object against this way of establishing the immutableID between the groups. There are some fundamental problems with this approach:
A better solution is to writeback the mS-DS-ConsistencyGuid to the F1 (SOURCE) group and have it copy automatically during ADMT copying to the F2 group.
see: https://blog.azureinfra.com/2022/03/10/immutableid-ms-ds-consistencyguid-aadconnect-admt-part-4-groups/
You should also make a note that group membership is NOT merged, but instead the first domain wins.. (meaning always F1) and changes made directly to F2 are not reflected in AAD - UNLESS a change is made in the ruleset.
(Roelf)
Document Details
⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.