Prevent "emergency access" users from syncing to on-prem AD when using AD Connect

Mark Coppa 21 Reputation points
2020-02-25T21:38:57.657+00:00

I'm looking for guidance on preventing (filtering) "emergency access" users from syncing to on-prem AD when using AD Connect. From the reference doc Manage emergency access accounts in Azure AD:

"*Create two or more emergency access accounts. These accounts should be cloud-only accounts that use the .onmicrosoft.com domain and that are not federated or synchronized from an on-premises environment."

I've only found documentation on using Synchronization Rules to filter from on-prem Active Directory to AAD.

Thank you

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Answer accepted by question author
  1. Daniel Aldén 156 Reputation points
    2020-02-25T22:14:06.387+00:00

    With AD Connect you cannot sync users back to local AD. Just create cloud only account and activate monitoring when it used.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.