Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Central Azure AD Sync, Filter by group membership??

Im driving myself crazy at the moment as i managed to Filter the Azure AD sync by group membership a while ago by modifying the Sophos Sync Azure app manifest.  But stupidly i deleted the Sophos app and now ive setup my Azure AD sync again I cant remember how i managed to get the sync to only sync users in a specific group.

Like i say i know its done within the Azure app manifest file, can someone remind me or let me know what im missing?? 

I only want to sync users of 1 specific Azure AD group.

Thanks in advance.



This thread was automatically locked due to age.
  •  did you get this figured out again? Any insight? 

     

    Thanks.

  • No basically, I I managed to do it once but for some reason I deleted the azure application so had to reset it up again but I didn't make note of howi I achieved it. Its been a while since I last tried it so I hope it's now configurable or at least tells you how to sync only certain group members now. All I can remember was I managed to find the manifest string that meant that application would only sync specific users. It wasn't just assigned groups either but as I say that may have changed since. But I ended up and still use jumpcloud ad Saad offering which is free and allows me to set the specific users via that now which net my needs which was to have the single cloud based Ad which was accessible by Sophos Xg and fit in alongside my azure ad without using syncing and also allowed me to set SAM as the default username layout and not upn as aad does which at the time I set this up synchronised user Id was using on sophos xg.

    I may take another crack at sophos aad sync now though to see if it's changed the way I needed it too yet. I as even though the solution I put into place a while back still works it would be great to not have a 3rd party directory service if sophos can do it now.

    If I do have another crack at it I'll be sure to reply again.

    JK

  • I found one of my old posts which if I remember right does syncing of assigned members to the azure ad app which if I remember right can be users or groups but this wasn't exactly what I was looking for but it might do what you were wanting to do?

    Jk

    JK