This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

O365 Distribution Group Sync to ARS

I have a bunch of O365 Distribution Groups that I used to bring down into ARS via the sync tool.  The issue is whenever I add someone to the group it doesn't update in O365.  When I add someone to the managed by field it doesn't update the owner field of the object.  I do know if I create a DL in ARS and check the box for to create it in Azure, there's no issues.  I have over 300 Distribution Groups in O365 that I need to have ARS manage.  How can I go about pulling those groups down and have the ability to manage them.  Do I have to create a 2-way sync via the sync tool or can I just pull them in and manage them that way?  I did make sure that the O365 enabled attribute is set for TRUE as part of the sync.

Parents
  • Make sure that you have your back sync configured properly to pull down the object IDs of the groups and populate them into the edsvaAzureObjectID atribute. You also want the sync to set the edsvaAzureOffice365Enabled to TRUE in Active Roles. More details and step by step can be found in the KB below:

    support.oneidentity.com/.../video-configure-azure-in-active-roles-7-2-part-2-of-2-

    The reason why this is working if you create the group in ARS, is because ARS notes all of this information on it's own if the object is created by ARS. If the object was created outside of the product, you will need to use the sync service back sync to populate everything.
Reply
  • Make sure that you have your back sync configured properly to pull down the object IDs of the groups and populate them into the edsvaAzureObjectID atribute. You also want the sync to set the edsvaAzureOffice365Enabled to TRUE in Active Roles. More details and step by step can be found in the KB below:

    support.oneidentity.com/.../video-configure-azure-in-active-roles-7-2-part-2-of-2-

    The reason why this is working if you create the group in ARS, is because ARS notes all of this information on it's own if the object is created by ARS. If the object was created outside of the product, you will need to use the sync service back sync to populate everything.
Children
No Data