I'm trying to find the correct way to get this working, and so far I'm not having any luck. Gemini was in full hallucination mode when I asked it.
We've got GCDS setup and running on our Windows AD server now for several years. No big issues.
However, as we grow more into our Google Workspace I'm looking to make a change:
I've got an OU in AD that I don't want to Sync with GW - and vice-versa.
I'm looking to keep this "Service Accounts" OU separate between the two because each has accounts the other doesn't need.
I don't was GCDS to suspend users in GW if they don't exist in AD. I don't want wants GCDS to create users from this OU in GW if they don't exist. GCDS should just ignore the OU all together - leaving whatever is in there as-is.
I'm also not looking for a solution that involves individually making exemptions on a per-account basis - the idea is to that any account created in either location within that specific OU will just be left alone during the Sync.
Has someone successfully done this? It doesn't seem like it should be tricky but I'm having a hard time getting it to work right.