Azure Directory Sync

Azure Directory Sync

Azure Directory Synchronization (aka Azure AD Connect) is used to synchronize user accounts, group memberships, and credential hashes from an On-Premises AD DS environment to Azure AD. Azure Directory Synchronization tool works by importing data from both directories (On-Premises and Azure), validating changes, and then exporting any changes to the directories.

Azure AD Connect sync: Understanding the architecture - Azure - Microsoft Entra | Microsoft Docs


Term definitions:

  • Connector: Used by sync engine to connect to a data source (CS)
  • Metaverse: Storage area that contains the aggregated identity information from multiple directories (MV)
  • Connected directories: The data repositories that are synchronized by sync engine are called connected data sources or connected directories (CD).

Sync engine identity management process


Search Metaverse

Metaverse search can be used to track object changes (e.g., adding or removing a member from a group). Search the meta verse for the group object.

  1. Open Synchronization Service Manager application
  2. Select the tile "Metaverse Search"
  3. Scope by Object Type: group
  4. Select the option "Add Clause" to add a condition to filter on (see example)
  5. Select the search button.


Inspect the object

  1. Using the search results, select the object in the results and select properties
  2. Select the connectors tab
  3. Select the properties tab for the select connector and confirm the attribute(s) is correct
  4. Repeat the steps for the next connector and confirm both connectors contain the same data

If the connectors space does not contain the same data, engage the M365 Identity team to continue investigating.


Arif Nota

Internal Audit, IT/OT Cybersecurity | AI Ops | ICS Security | Big 4 Alum | Lifelong Learner | MBA | MSc Cyber | AZ-104 | AZ-500 | CISM | PMP | CISA | CHIAP | CIA | CFE | CDPSE | CRISC | CRMA

11 个月

Experience really shines through in this discussion, great insights. #SyncTechnology

要查看或添加评论,请登录

MIR MD NEWAZ MORSHED的更多文章

  • Self-help diagnostics for issues in Microsoft Purview

    Self-help diagnostics for issues in Microsoft Purview

    Tired of chasing down issues in Microsoft Purview like it’s a game of hide-and-seek? Good news—Self-help diagnostics in…

    2 条评论
  • A new Outlook experience for Windows 10 devices

    A new Outlook experience for Windows 10 devices

    To assist with planning for the end of support for Windows 10 on October 14, 2025, and to streamline the transition to…

  • Sensitivity Label support for Double Key Encryption (DKE) 02

    Sensitivity Label support for Double Key Encryption (DKE) 02

    Double Key Encryption Prerequisites License: Microsoft 365 E5/A5 Microsoft 365 E5/A5 Compliance Microsoft 365…

  • Sensitivity Label support for Double Key Encryption (DKE) 01

    Sensitivity Label support for Double Key Encryption (DKE) 01

    Microsoft 365 offers integrated data protection features to encrypt users data, both while it is stored and during…

  • Let's Catch All the email

    Let's Catch All the email

    A Catch-All Account is your Spidey-sense for emails, alerting you to messages sent to non-existent addresses or typos…

  • 1.3 Best Practices for Security Operations (Secops)

    1.3 Best Practices for Security Operations (Secops)

    Security operations (SecOps) maintain and restore the security assurances of the system as live adversaries attack it…

  • 1.2 Advanced Delivery

    1.2 Advanced Delivery

    To keep organizations secure by default , Exchange Online Protection does not allow safe lists or filtering bypass for…

  • 1.1 Microsoft 365 Security

    1.1 Microsoft 365 Security

    Microsoft considers Zero Trust an essential component of any organization’s security plan. Today’s organizations need a…

  • Mail Flow Architecture

    Mail Flow Architecture

    Domain Name System DNS systems are used to convert domain names to IPs, and IPs to domain names. In mail flow, a server…

  • AzureAD/EntraID Audit Logs

    AzureAD/EntraID Audit Logs

    Changes to Azure AD objects are audited in Azure audit logs. Audit logs by default are retained for 30 days or longer…

社区洞察

其他会员也浏览了