If you want to manage hybrid Azure objects (such as hybrid Azure users) in your Organization Unit (OU), then use the built-in Azure - Default Rules to Generate Properties Policy Object of the Active Roles Console (also known as the MMC Interface) to provision the default properties and accepted values or hybrid objects.
To configure the built-in Azure - Default Rules to Generate Properties policy
- 
In the Active Roles Console, navigate to Configuration > Policies > Administration > BuiltIn. 
- 
Right-click on Built-in Policy - Azure - Default Rules to Generate Properties and click Policy Scope. 
- 
To open the Select Objects dialog for specifying the OU for provisioning, click Add. 
- 
To specify the OU for provisioning hybrid Azure users, click Add, browse the OU you want to provision, and click Add. TIP: If no elements are displayed in the Select Objects dialog, select Click here to display objects. 
NOTE: The new provisioning policy settings will be applied automatically only to objects created after configuring the Azure - Default Rules to Generate Properties policy object.
To create cloud Azure users for existing on-premises users, you must configure the cloud Azure users manually for each existing on-premises user on the Active Roles Web Interface. To do so:
- 
Navigate to the folder of the hybrid users of the OU under Directory Management > Tree > Active Directory > <your-AD-folder> > <your-OU-folder>. 
- 
Select the on-premises user for which you want to create a cloud Azure user. 
- 
To open the New Azure User dialog, on the right pane, click Create Azure User. For more information on the steps of creating a new cloud Azure user, see Creating a new cloud-only Azure user. 
