Microsoft Entra ID

Ad Group Enforcement

In brief

.\Set-CloudSyncSOAPolicy.ps1 -EnforcementMode Audit -Credential (Get-Credential -Message "Enter Domain Admin credentials (format: DOMAIN\Username)")

Documentation change

.\Set-CloudSyncSOAPolicy.ps1 -EnforcementMode Audit -Credential (Get-Credential -Message "Enter Domain Admin credentials (format: DOMAIN\Username)")


Add a break-glass account

You can add the SID of an additional authorized user to the policy so that the user can make changes to enforced groups on-premises.