|
Hi there, we have a hybrid environment, so on-prem AD is our first source of account truth. Looking at it I honestly couldn't find any reason why this is a test at all, because it is even contra-productive. I also couldn't find any official recommendation on excluding synched users always from CA policies? Why is this test existing at all. Should it be decommed? Best, |
Replies: 4 comments 2 replies
|
Good question! This doesn't exclude synchronized users--it excludes the identity(s) of the synchronization accounts that are used by Entra ID Connect itself. |
|
Hi @SamErde ,
Am I wrong or is that outdated with the latest updates on Entra ID Connect and supporting now modern authentication? Best, |
|
Hi @SamErde, |
For now, it would be good to update Maester's documentation so it correctly states the current functionality of Entra Connect (or Entra Cloud Sync where applicable). Entra Connect won't be completely replaced in 100% of environments for some time yet. I would be surprised if that takes anything less than 18 - 24 months to fully migrate and retire.