The administration of a hybrid deployment that connects on-premises Exchange Server with Exchange Online, enabling seamless integration and centralized control.
You may want to review the newer Group Source of Authority (SOA) Conversion feature in Microsoft Entra ID. Historically, converting synchronized groups to cloud-managed objects required disabling directory synchronization for the entire tenant. Microsoft has introduced Group SOA Conversion, which allows eligible synchronized groups to be converted to cloud-managed objects while keeping Microsoft Entra Connect synchronization enabled for the rest of the organization.
Since your issue involves a single group that became synchronized after an incorrect OU was brought into scope, it may be worth checking whether this group is eligible for SOA conversion instead of disabling directory synchronization tenant-wide. If the group meets the documented prerequisites, you can transfer its source of authority to Microsoft Entra ID and manage it as a cloud-managed group while continuing to synchronize the remaining on-premises objects. You can refer to Embrace cloud-first posture and convert Group Source of Authority (SOA) to the cloud - Microsoft En…
I hope this information is helpful.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.