Create UserPrincipalName attribute filter in AAD Connect.

In AAD Connect it’s possible to sync only users with specific UserPrincipalName. And here is how to do it.

  1. Open Synchronization Rules Editor
  2. Under Rule Types click on Outbound.
  3. Find the rule named Out to AAD – User Join. Click Edit.
  4. Click Scoping filter on the left hand navigation. Click Add clause and in Attribute select userPrincipalName, in Operator select ENDSWITH, and in Value type @contoso.com.
  5. Click Save.
  6. Perform a full sync: on the Connectors tab, right-click SourceAD, click Run, click Full Synchronization, and then click OK.
  7. Start normal sync or wait for the time period you have specified.

Author: Harri Jaakkonen

Leave a Reply

Your email address will not be published. Required fields are marked *