Tuesday, October 21, 2014

Home / Azure Active Directory Sync – Object Selection and Synchronization Schedule

Azure Active Directory Sync – Object Selection and Synchronization Schedule

Finally I got some time to play with the new Azure Active Directory Sync tool and configuration.   You can see the new features of this tool in Alex Simons’  blog - http://blogs.technet.com/b/ad/archive/2014/04/21/new-sync-capabilities-in-preview-password-write-back-new-aad-sync-and-multi-forest-support.aspx.

Installation

The installation was very straight forward.  The step-by-step instruction are provided in the http://msdn.microsoft.com/en-us/library/azure/dn757602.aspx article.  The administration tools and scripts are located in difference places which was little confusing in the beginning.  There  are three tools available to administer or customize the AAD sync configuration. 

Synchronization Service Manager - C:\Program Files\Microsoft Azure AD Sync\UIShell\miisclient.exe

Synchronization Rules Editor - C:\Program Files\Microsoft Azure AD Sync\UIShell\SyncRulesEditor.exe

Synchronization Service Key Management - C:\Program Files\Microsoft Azure AD Sync\Bin\miiskmu.exe

Synchronization Service Manager

This is where you administer or customize your synchronization options.  It is an MIIS client. In the backend it creates Management Agent (MA) for your directory and Azure. 

1

The default location of this file (missclient.exe) is in C:\Program Files\Microsoft Azure AD Sync\UIShell

Schedule

By default, the Azure AD sync schedule to run every 3 hours.    It is Windows scheduled task as shown in the following screenshot:

2

You can manually force the replication from here if needed.   In the backend it calls the DirectorySycnClientCmd.exe file which is located in C:\Program Files\Microsoft Azure AD Sync\Bin\ folder.

Note:  If you have Office 365 in a hybrid mode, changing the default schedule or creating a custom schedule is not recommended or supported. 

3

Object Filter and Customization

Object selection and customization can be performed using the Synchronization Service Manager tool.

4

 

Synchronization Rules Editor

This is where you can create custom filters based on an attribute or attribute values. By default, this tool (SyncRulesEditor.exe) is located in C:\Program Files\Microsoft Azure AD Sync\UIShell\folder. 

 

You can create a new filter by selecting the Add new rule button in the Synchronization Rules Editor

 

image

If you are planning to use an attribute based filer, make sure that the required attribute is selected (enabled) in the connector (MA) properties.

 

image

 

 

 

SS

Santhosh Sivarajan

Microsoft MVP · Identity & Cybersecurity Architect

Santhosh has 30+ years of hands-on enterprise experience in Identity and Access Management, Microsoft Entra ID, Active Directory, Microsoft 365 and Zero Trust architecture. He is the author of two books on Windows Server and security, and leads consulting, assessments and training at SAG Business Group.

1 comments:

Post a Comment

Popular Posts
Workstation Trust Relationship Issue Issue: You receive the following error message, when you try to login to the domain.  The security database on the server does not have ... ADMT Service Account - Permission and Configuration The ADMT service account needs to have proper permission in source and target domains.  You don’t need to use 2 separate accounts.  You can ... My First Peek into Microsoft Exchange 2010 By Santhosh Sivarajan Before I really dive into Exchange 2010, I thought I would install and play with it first. I took some screen shots and notes during the ins... ObjectSID and Active Directory What is an objectSID in Active Directory? When a new object is created in Active Directory, Domain Controller assigns a unique value used ... AD Group Report - List Group Members in Active Directory–PowerShell Script Updated Script - http://portal.sivarajan.com/2011/10/search-ad-collect-local-admin-group.html Script #1 This script... Add Users to a Group–PowerShell Script Purpose – Add users to a group from an input file – PowerShell V2 Script.  Input file – Input file (Users.csv) contains samAccountName in... User Account Migration and Merging – Part I (ADMT) Part I - User Account Migration and Merging Using ADMT Part II - User Account Migration and Merging Using QMM pre-creating user account ... User Account Migration and Merging – Part II (Quest Migration Manager) Part I - User Account Migration and Merging Using ADMT Part II - User Account Migration and Merging Using QMM Pre-creating user account in... Delete Stale or Inactive Computer Accounts from Active Directory Here is an easy way to identify and delete inactive or stale computers in an Active Directory environment.  Using the dsquery command you c... Converting PowerShell (PS1) to EXE / Standalone Application As we know, there many applications available to convert a PowerShell file to a standalone executable file.  Based on my experience, PowerSh...