0

Let's assume there is an up-to-date environment that uses Azure AD Connect to sync user accounts between AD DS on-prem and Azure AD in the cloud.

When adding new users - should they be added to Azure AD first (and then synced back to on-prem by Azure AD Connect) or rather to the on-prem AD (to be synced to Azure AD)? Why?

1 Answers1

0

As I know, if you add a new user to the on-premise AD, it can be synced back to Azure AD with Azure AD Connect. But if you add to Azure AD, it will not. So if you want to add new users, you would be better to add them to the on-premise AD.

What's more, if the user will not use the on-premise resource, you can add it to Azure AD. The Azure AD just provides people with a solution to the problem that the on-premise AD cannot solve.

Charles Xu
  • 146
  • 3