question

LukeLim95131 avatar image
1 Vote"
LukeLim95131 asked EnterpriseArchitect answered

How to check Azure AD Connect settings for Attributes filtering

From the Azure AD Connect GUI, I can get all existing settings.
But how can I check which attributes are configured currently? Other than running the AADC Documenter tool?

azure-ad-connect
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@LukeLim95131 I wanted to follow up and know if the below response helped in answering your query. If it did, please do not forget to accept the response as Answer

0 Votes 0 ·
vipulsparsh-MSFT avatar image
1 Vote"
vipulsparsh-MSFT answered vipulsparsh-MSFT commented

@LukeLim95131

1) Under Azure AD connect synchronization configuration export we list the Attribute which are excluded. This is a exclude only list and appears only when if you have used the wizard to select few attribute sync options.

You can check the view or export the current configuration and check for any attribute under excluded Attribute list :

32956-1.png

Once exported, you can see the list of attributes which were excluded from sync. For eg in my lab scenario I excluded all these attribute from syncing :
32895-1a.png


============================================================================================================

2) You can also go to the current configuration and Look for Azure AD attributes and select the view attributes option :
32957-2nd.png

It will open a file which can show you which attribute are getting synced and are not removed :
32770-3.png


If the suggested response helped you resolve your issue, please do not forget to accept the response as Answer and "Up-Vote" for the answer that helped you for benefit of the community.







1.png (81.4 KiB)
1a.png (20.8 KiB)
2nd.png (114.1 KiB)
3.png (10.2 KiB)
· 5
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

For Method 1, it only shows attributes that are exported? What is extenstionattribute1?

For Method 2, in my current configuration, under Sync I only have up to Optional Features.
33104-image.png


How come I don't have Apps and Attributes? Is it because my Azure AD Connect version is 1.1.x?

The previous one who did configuration didn't have any documentation. and I need to do a swing upgrade.

How can I get what was previously configured for these?
These are sample images of a new installation.
Any filtering done

33105-image.png


The Azure apps configured
32999-image.png

And of course attributes
33181-image.png

If there are no ways to view from the GUI, is there a Powershell script to extract these settings?
Or how to view from the Documenter?

Thanks.

1 Vote 1 ·
image.png (63.3 KiB)
image.png (43.0 KiB)
image.png (45.6 KiB)
image.png (53.0 KiB)

@LukeLim95131

1) Yes, this shows shows only the excluded ones. extenstionattribute1 is just another AD attribute which can be used to populate any value admin wants.
2) My AAD Connect version is : 1.5.45.0

Also do note, Starting on November 1st, 2020, we will begin implementing a deprecation process whereby versions of Azure AD Connect that were released more than 18 months ago will be deprecated. At that time we will begin this process by deprecating all releases of Azure AD Connect with version 1.3.20.0 (which was released on 4/24/2019) and older, and we will proceed to evaluate the deprecation of older versions of Azure AD Connect every time a new version releases.
(Reference : https://docs.microsoft.com/en-us/azure/active-directory/hybrid/reference-connect-version-history)

The documenter tool does have a attribute options, what do you see there ?
33196-attribute.png


0 Votes 0 ·
attribute.png (115.6 KiB)

Thanks for reverting.

33207-image.png



Does it mean everything under the Select Attributes are selected?

Or I have to look at column Flows Configured?. Ignore those with No and only select those that are Import, Export, Import/Export?

1 Vote 1 ·
image.png (87.8 KiB)

Yes I am well aware of the 18 months support release. This is why I am doing a swing upgrade. The problem is I got all the previous settings except for if we sync all users and devices, if any Azure AD apps are restricted, and if any exported attributes are excluded. So I need to find out all these before we can mitigate the risk to do a swing upgrade.

And because I am on 1.1.x now, I don't have the Export existing configuration feature. So I can't use Method 1 too.

0 Votes 0 ·
Show more comments
EnterpriseArchitect avatar image
0 Votes"
EnterpriseArchitect answered

Hi @vipulsparsh-MSFT is it the same as in this GUI ?
208549-image.png



image.png (38.9 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.