Advice with AD Sync migration Azure AD Sync

Hi,


Can someone please weigh-in on this to see if I have this right? Slight smile And please state if you have done this before ;)

To migrate from away from AD Sync to Azure AD Sync, do we:

  1. Stop On-Prem AD Sync service
  2. Disable the AD Sync service
  3. Login to Sophos Central
  4. Setup AzureAD Sync
  5. Reassigned the polices to the now-selected and synced Azure AD Groups
  6. Purge AD Sync data via this thread (Purge synchronized Active Directory data - Sophos Central Admin)
  7. Check everything works

???

Or, is it a case that the AD Sync data must be purged before establishing the Azure AD Sync?

Cheers!



Added tags
[edited by: Gladys at 7:32 AM (GMT -7) on 3 Oct 2022]
Parents
  • Hi Trooper,

    Thanks for reaching out to the Sophos Community Forum. 

    It is not a requirement to purge the data before moving from AD Sync to Azure AD Sync. However, you may run into some duplicated entries. 

    The External ID, Immutable ID, and SID are used to verify whether a newly synchronized object will be merged with an existing one. The following items will not be merged. 
    - Public Folder
    - Device 
    - OU
    - Device Group

    If you wish to synchronize the items mentioned here, it may be best to do the purge before the switch.

Reply
  • Hi Trooper,

    Thanks for reaching out to the Sophos Community Forum. 

    It is not a requirement to purge the data before moving from AD Sync to Azure AD Sync. However, you may run into some duplicated entries. 

    The External ID, Immutable ID, and SID are used to verify whether a newly synchronized object will be merged with an existing one. The following items will not be merged. 
    - Public Folder
    - Device 
    - OU
    - Device Group

    If you wish to synchronize the items mentioned here, it may be best to do the purge before the switch.

Children