Here's how I wish @AzureAD#GroupWriteback worked:
1. Disabled state - Group Writeback is disabled within Azure AD Connect (v2.0.89.0 or later).
a) AAD Groups blade detects disabled state and hides option (or greyed out).
b) "No writeback" forced in each Group, and greyed out.
ALT 1a - Groups blade Settings hides the Writeback options, as the Azure AD Connect configuration reports that the feature is disabled
ALT 1b - Unlike right now, the Groups properties should be greyed out (or hidden) if Group Writeback isn't enabled.
Wait... so this @AzureAD#GroupWriteback feature, even when v2 is enabled, will synchronise EVERY M365 and AAD Security group back to Active Directory? I thought the point of the new Group Writeback drop-down on AAD Groups meant it was opt-in. I can't bring back 3000 groups!