JacobBice (Customer) asked a question.

We are managing a hybrid identity setup with two on-prem Active Directory domains synced to a single entra tenant. Is there documentation available for managing this kind of setup?

Our environment primarily uses on-prem accounts and groups synced up to entra, but we have begun to implement cloud only accounts, as well as cloud only groups that can be granted to either cloud accounts or on-prem accounts. Is there an established best practice in RSA to manage this kind of environment? How can we ensure RSA only provisions and deprovisions the cloud only groups through the entra connector, while managing all on-prem groups and accounts through our active directory connectors?