Azure Entra Connect Cloudsync - 用户未同步到 OnPremise Active Directory

问题描述 投票:0回答:1

我已在本地 WinServer22 Active Directory 控制器上设置了 Azure Entra Connect Cloudsync 代理。

群组正在同步,但用户尚未同步。同步时我收到以下消息:

EntrySynchronizationSkip:

Result: Skipped

Description: The User 'xxxx' will be skipped due to the following reasons: 
1) This object is not assigned to the application. 
If you did not expect the object to be skipped,
assign the object to the application or change your scoping filter to allow all users
and groups to be in scope for provisioning. 
2) This object does not have required entitlement for provisioning.
If you did not expect the object to be skipped,
update provisioning scope to 'Sync all users and groups'
or assign the object to the application with entitlement of provisioning category 
3) This object did not pass a scoping filter. 
If you did not expect the object to be skipped, please review your scoping filters 
and ensure that the object passes your specified scoping criteria. 
The scope evaluation result is: {"On-prem Owned Users.dirSyncEnabled IS TRUE":false}

SkipReason: NotEffectivelyEntitled
IsActive: True
Assigned to the application: False   
IsInProvisioningScope: False
ScopeEvaluationResult: {"On-prem Owned Users.dirSyncEnabled IS TRUE":false}

所有 Entra 用户都会遇到这种情况。 “分配给应用程序:错误”上下文中的应用程序是什么 如果参数“On-prem Owned Users.dirSyncEnabled”当前为 false,我可以在哪里设置它?

谢谢你

azure azure-active-directory active-directory microsoft-entra-id
1个回答
0
投票
If you did not expect the object to be skipped,
assign the object to the application or change your scoping filter to allow all users
and groups to be in scope for provisioning.

根据上述错误消息,未启用

scoping filter
将用户从 On-prem AD 同步到 Azure AD。确保选择范围过滤器下的所有用户以同步所有用户和组。

要使用 Cloud Sync 将用户和组从 On-Prem AD 同步到 Azure AD,您可以按照以下步骤操作。

  1. On-Prem Server 上安装并连接 Cloud Sync 代理。

enter image description here

  1. 完成代理配置后,验证代理状态。

enter image description here

  1. 要将所有用户和组同步到
    Azure AD
    ,请选择 所有用户 选项。

enter image description here

  1. 选择范围过滤器后,重新启动 sync

enter image description here

    用户和组已成功同步到
  1. Azured Ad

enter image description here

enter image description here

如果

Dirsync被禁用,您可以使用以下命令启用Dirsync

Install-Module MSOnline Set-MsolDirSyncEnabled -EnableDirsync $True

enter image description here

参考:

为 Microsoft Entra Cloud Sync 创建新配置

开启目录同步

© www.soinside.com 2019 - 2024. All rights reserved.