Skip to content

Commit

Permalink
crosslink two articles
Browse files Browse the repository at this point in the history
  • Loading branch information
markwahl-msft committed Oct 25, 2023
1 parent 8ea1a8d commit 1caca41
Show file tree
Hide file tree
Showing 2 changed files with 2 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ Using group writeback, you can now sync security groups that are part of access

1. Launch Active Directory Users and Computers, and wait for the resulting new AD group to be created in the AD domain. When it's present, record the distinguished name, domain, account name and SID of the new AD group.

1. Configure the application to use the new group, either by updating the application or adding the group as a member of an existing group, as described in [Govern on-premises Active Directory based apps (Kerberos) using Microsoft Entra ID Governance](../hybrid/cloud-sync/govern-on-premises-groups.md).
1. Configure the application to use the new group, either by updating the application or adding the group as a member of an existing group, as described in [Govern on-premises Active Directory based apps (Kerberos) using Microsoft Entra ID Governance](../identity/hybrid/cloud-sync/govern-on-premises-groups.md).

1. Assign the user to the access package. See [View, add, and remove assignments for an access package](entitlement-management-access-package-assignments.md#directly-assign-a-user) for instructions to directly assign a user.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ ms.author: billmath

**Scenario:** Manage on-premises applications with Active Directory groups that are provisioned from and managed in the cloud. Microsoft Entra cloud sync allows you to fully govern application assignments in AD while taking advantage of Microsoft Entra ID Governance features to control and remediate any access related requests.

With the release of provisioning agent [1.1.1367.0](reference-version-history.md#1113670), cloud sync now has the ability to provision groups directly to your on-premises Active Directory environment.
With the release of provisioning agent [1.1.1367.0](reference-version-history.md#1113670), cloud sync now has the ability to provision groups directly to your on-premises Active Directory environment. With this, you can use identity governance features to govern access to AD-based applications, such as by including a [group in an entitlement management access package](../../../id-governance/entitlement-management-group-writeback.md).

:::image type="content" source="media/govern-on-premises-groups/on-premises-group-writeback.png" alt-text="Conceptual drawing of Microsoft Entra Cloud Sync's Group Provision to AD." lightbox="media/govern-on-premises-groups/on-premises-group-writeback.png":::

Expand Down

0 comments on commit 1caca41

Please sign in to comment.