- Azure AD Connect (should be possible with all builds of AADConnect – if you run into an issue, comment or email me)
PROBLEM SCENARIO DESCRIPTION
The problem we are attempting to resolve here is how to take a Group Object from Forest A and merge it with a Contact Object from Forest B using Azure AD Connect. The goal is to have a Group Object with information provided from both objects in Office 365.
KEY POINTS TO BE AWARE
- In Azure AD Connect, you can only join on the same object type in the Azure AD Connect Metaverse
- You will need to utilize inbound synchronization rules
Understand the business need/rule(s) that you are attempting to achieve here. This will help in the development of this solution. It will help:
- Determine if you need a Provisioning Synchronization Rule and/or a Join Synchronization Rule.
- Determine if you need a Scoping Filter to have the Inbound Synchronization Rule execute for a certain set of objects.
*NOTE: Modifying the default synchronization rule, you run the risk of the rule being overwritten during an upgrade. Making a copy of the rule allows you to have an already configured rule that you can make adjustments to fit your internal business rules.
- Recommend to make copies of the following default Inbound Synchronization Rules for Contact objects and then disable the default Synchronization Rules
- In from AD – Contact Join (Provisioning Inbound Synchronization Rule)
- In from AD – Contact Common (Join Inbound Synchronization Rule)
- The Description Page of your new Inbound Synchronization Rule is the most important piece. You need to ensure that the Connected System Object Type is contact and the Metaverse Object type is Group.
- Connected System Object Type = Contact
- Metaverse Object Type = Group
- AZURE AD CONNECT: (SYNC): Understanding the default configuration: https://azure.microsoft.com/en-us/documentation/articles/active-directory-aadconnectsync-understanding-default-configuration/
- AZURE AD CONNECT: (SYNC): How to make changes to the default configuration: https://azure.microsoft.com/en-us/documentation/articles/active-directory-aadconnectsync-change-the-configuration/