:::image type="content" source="media/tutorial-group-provision/verify.png" alt-text="Screenshot of the newly provisioned group." lightbox="media/tutorial-group-provision/verify.png":::
## Group provision to AD behavior for SOA converted objects
When you convert the **Source of Authority (SOA)** to cloud for an on-premises group, that group becomes eligible for group provisioning to AD DS.
For example, in the following diagram, **SOATestGroup1** SOA is converted to the cloud.
As a result, it becomes available for the job scope in group provisioning to AD DS.
:::image type="content" border="true" source="media/tutorial-group-provision/group-scope.png" alt-text="Screenshot of job in scope." lightbox="media/tutorial-group-provision/group-scope.png":::
- When a job runs, the SOA-converted group is provisioned successfully.
- In the **Provisioning logs**, you can search for the group name and verify that the group was provisioned.
:::image type="content" border="true" source="media/tutorial-group-provision/provisioning-logs.png" alt-text="Screenshot of the Provisioning logs." lightbox="media/tutorial-group-provision/provisioning-logs.png":::
- The details show that the group was matched with an existing target group.
:::image type="content" source="media/tutorial-group-provision/verify.png" alt-text="Screenshot of the newly provisioned group." lightbox="media/tutorial-group-provision/verify.png":::
## Group provision to AD DS behavior for SOA converted objects
When you convert the Source of Authority (SOA) to cloud for an on-premises group, that group becomes eligible for group provisioning to AD DS.
For example, in the following diagram, the SOA or **SOATestGroup1** is converted to the cloud.
As a result, it becomes available for the job scope in group provisioning to AD DS.
:::image type="content" border="true" source="media/tutorial-group-provision/group-scope.png" alt-text="Screenshot of job in scope." lightbox="media/tutorial-group-provision/group-scope.png":::
- When a job runs, **SOATestGroup1** is provisioned successfully.
- In the **Provisioning logs**, you can search for **SOATestGroup1** and verify that the group was provisioned.
:::image type="content" border="true" source="media/tutorial-group-provision/provisioning-logs.png" alt-text="Screenshot of the Provisioning logs." lightbox="media/tutorial-group-provision/provisioning-logs.png":::
- The details show that **SOATestGroup1** was matched with an existing target group.