I need to implement a .NET solution that is supposed to inspect local domain in regards to its integration with Azure. The software will be run on a File Server (joined to local domain) with Windows Server. We expect that the local Active Directory will be synced with Azure Active Directory. We need to inspect this sync, i.e. gather as much information as possible from the local domain without reaching out to Azure. I would like to gather information about users and security groups synced to Azure AD, about the details of the synchronization to Azure - AD, which Azure AD directory has been used for synchronization with the local Active Directory.
So far I've been doing my research and I have a feeling I'm just touching the surface with my fingers. I have found that the ms-DS-ConsistencyGuid attribute is used in newer Azure-AD integrations as an anchor attribute for users, and objectGuid is used for other types (details on ms-DS-ConsistencyGui). This attribute I can find on users in the local Active Directory domain and then I know that these users have been synced to Azure AD.
Questions:
- Is it possible to find which Azure AD directory has been used for synchronization with the local Active Directory? How to fetch this information from the local machine without reaching to Azure?
- Is it possible to find more details about the synchronization configuration and setup between the local AD and Azure AD? How to fetch this information from the local machine without reaching to Azure?
- Is there any Azure-specific attributes can I focus on when browsing objects in the local Active Directory?
- Is it possible somehow to query information about Azure synchronization from the local DNS server? I tried to do so but to no avail.