To configure Active Roles to manage Hybrid AD objects, perform the following tasks:
- Create an Azure AD tenant.
- Create the Azure AD application.
- Provide the administrator consent for the Azure AD application.
- Enforce the Built-in Policy - Azure - Default Rules to Generate Properties Policy Object to the on-premises Active Directory containers, which are synchronized to Azure AD.
NOTE:
-
After an upgrade the edsvaAzureOffice365Enabled is not available for viewing or editing from Organizational Unit | Advanced Properties or through the management shell command-let, however the organizational unit container continues to be an Azure enabled container as the azure policy is already applied.
For more information on Azure custom policies, see Changes to Azure O365 Policies in Active Roles after 7.4.1.