Avatar of dougdog
dougdog

asked on 

On Prem AD groups v Azure AD groups in Hybrid

we are running Active directory hybrid with Azure
im trying to find out the pros and cons of using AD on prem groups v AD azure groups
what is the main differences?
How can end users manage each group etc
Microsoft 365Active DirectoryAzure

Avatar of undefined
Last Comment
timgreen7077
Avatar of timgreen7077
timgreen7077

Depending on your setup, if you are using Azure ADConnect for your hybrid setup, the on-prem groups are managed exclusively on-prem and synced to Azure AD or O365. groups created in Azure are only in Azure and are not Synced back on-prem unless you have write back enabled which i don't recommend. So any changes to groups created in Azure will stay only in Azure, but your synced users can be added to Auzre created groups also with no problem, but it will have be added and managed in Azure.

We create all groups on-prem and allow it to sync in Azure that way we still have central management for our groups.

I do have groups created in Azure, but I created these group in Azure because the users I have added to those groups are O365 users only and they have no on-prem account.

Its easier to create groups on-prem and manage on-prem an just allow ADConnect to sync those group to Azure AD. Thats my opinion anyway.
Avatar of dougdog
dougdog

ASKER

how can i allow end users to manage group membership for both on prem and azure
is one method easier than the other?
Avatar of timgreen7077
timgreen7077

I would suggest create the group on-prem and let it sync with Azure and any changes to the group should be done on-prem. That's the easiest method to me. Who ever you give permissions to modify those group will make changes to the group on-prem.
Avatar of dougdog
dougdog

ASKER

do they need the Ad snapin?
if cloud group is it easier to give a user permission to update groups
Avatar of timgreen7077
timgreen7077

I told you what I think is easier so its your choice now. No snapin required. just permissions. good luck.
Avatar of dougdog
dougdog

ASKER

but im asking how i can give an end user rights to add / remove members from the group using both on prem or azure?
do i need to give the access to AD to modify group member ship?
and do i need to give them access to azure to modify groups
ASKER CERTIFIED SOLUTION
Avatar of timgreen7077
timgreen7077

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
Active Directory
Active Directory

Active Directory (AD) is a Microsoft brand for identity-related capabilities. In the on-premises world, Windows Server AD provides a set of identity capabilities and services, and is hugely popular (88% of Fortune 1000 and 95% of enterprises use AD). This topic includes all things Active Directory including DNS, Group Policy, DFS, troubleshooting, ADFS, and all other topics under the Microsoft AD and identity umbrella.

86K
Questions
--
Followers
--
Top Experts
Get a personalized solution from industry experts
Ask the experts
Read over 600 more reviews

TRUSTED BY

IBM logoIntel logoMicrosoft logoUbisoft logoSAP logo
Qualcomm logoCitrix Systems logoWorkday logoErnst & Young logo
High performer badgeUsers love us badge
LinkedIn logoFacebook logoX logoInstagram logoTikTok logoYouTube logo