Browse learn

How Active Directory and Microsoft Entra ID Work Together

Learn how Active Directory and Entra ID divide directory and authentication responsibilities in hybrid environments and how identities synchronize.

On this page

The Landscape of Hybrid Identity

Most enterprises today find themselves spanning two identity worlds: the tried-and-true on-premises Active Directory Domain Services (AD DS) and the cloud-native Microsoft Entra ID. A hybrid identity architecture—where these systems interoperate—is now standard for organizations seeking unified access to legacy systems and modern SaaS services like Microsoft 365.

Hybrid identity, in practice, is the bridge enabling users to log in with a single authoritative identity across on-prem and cloud resources. For developers, architects, and identity engineers, understanding how AD DS and Entra ID integrate—especially through directory synchronization and hybrid authentication—is essential for modernizing access management without breaking legacy integrations.

Active Directory vs. Microsoft Entra ID: Scope and Responsibilities

Before planning or troubleshooting an integration, it's crucial to recognize what sets AD DS and Microsoft Entra ID apart.

Active Directory Domain Services (AD DS):

  • On-premises, Windows Server–based directory service.
  • Authoritative for user accounts, groups, computers, and group policies in the local network.
  • Supports traditional authentication protocols (Kerberos, NTLM, LDAP).
  • Highly granular administrative boundaries via domains, forests, and organizational units (OUs).

Microsoft Entra ID:

  • Multi-tenant, cloud-based directory (formerly Azure Active Directory).
  • Source of identity for cloud apps (Microsoft 365, Azure, SaaS).
  • Enables single sign-on (SSO) and access management using modern protocols like OpenID Connect (OIDC) and SAML.
  • Employs role-based access control (RBAC), dynamic groups, and entitlement management.
CapabilityAD DSMicrosoft Entra ID
Where managedOn-premisesCloud (Microsoft managed)
Auth protocolsKerberos, NTLM, LDAPOIDC, SAML, password hash sync
Admin boundariesDomains, OUs, Group PolicyRBAC, Administrative Units
Group managementStatic, security/distributionDynamic, entitlement, M365 groups
Protocol supportLegacy (NTLM/Kerberos/LDAP)Cloud-modern (OIDC/SAML)
Write-backOn-prem to cloud (mostly)Limited (Exchange hybrid scenarios)

For most organizations, neither system alone is sufficient: AD DS remains critical for legacy apps, Group Policy, and Windows-based device management; Entra ID empowers cloud access, Zero Trust, and automation scenarios.

The Role of Directory Synchronization (Connect & Cloud Sync)

The foundation of hybrid identity is directory synchronization—copying users and groups from AD DS into Entra ID. This process is typically handled by either Microsoft Entra Connect Sync or Cloud Sync.

Synchronization Flow:

  • Source: On-premises AD DS is the authoritative source for user and group objects.
  • Sync Engine: Microsoft Entra Connect Sync (more feature-rich, mature) or Cloud Sync (lighter, cloud-managed) extracts objects and attributes.
  • Target: Objects are provisioned in Entra ID, enabling cloud authentication and access.

Topologies and Considerations:

  • Single-forest or multi-forest: Supports environments with multiple AD domains and forests.
  • Attribute Merging: In multi-forest sync, objects must be uniquely identified—merging attributes across forests requires careful mapping and management.
  • One-way nature: Sync is generally one-way (AD ➔ Entra ID). By default, objects created or changed in Entra ID do not write back to on-prem AD, except in certain Exchange hybrid scenarios.
  • Pilot and migration scenarios: Both Connect and Cloud Sync support pilot phases for gradual rollout, but only supported topologies should be used to avoid inconsistent or unsupported states.

Example: An enterprise with HR data in a separate forest must ensure the provisioning rules in Connect or Cloud Sync correctly bring in authoritative user information, without attribute collisions.

Authentication Protocols: From LDAP and Kerberos to OIDC and SAML

Central to hybrid identity is protocol support. AD DS and Entra ID speak fundamentally different authentication languages.

  • AD DS: Traditional protocols—Kerberos, NTLM, LDAP—used by most on-prem Windows applications and many legacy third-party systems. These protocols are not natively supported by Entra ID.
  • Entra ID: Cloud-centric protocols—OpenID Connect (OIDC), OAuth 2.0, SAML—supporting enterprise SaaS and cloud-native applications, along with modern access controls like multi-factor authentication (MFA) and conditional access.

Bridging the Protocol Gap: Microsoft Entra Domain Services

For cloud-hosted applications that still require legacy protocols (e.g., an app needing LDAP or Kerberos after being moved to Azure), Microsoft Entra Domain Services (Entra DS) provides a managed domain controller service. Entra DS sources its identities from Entra ID (which itself is fed by AD DS, if directory sync is configured), exposing the necessary legacy endpoints (LDAP, NTLM, Kerberos) for workloads that cannot be modernized immediately.

Example: A legacy ERP app is lifted into Azure. By enabling Entra Domain Services, the app continues authenticating users over LDAP, with those users’ credentials managed via Entra ID—no need to deploy domain controllers in Azure or maintain network trust back to the on-prem AD.

Administrative Boundaries and Delegation: OUs, RBAC, and Management Models

How administrators delegate, scope, and control permissions differs sharply between AD DS and Entra ID:

  • AD DS: Uses organizational units (OUs), nested group delegation, and group policies to manage administrative scope and permissions. Delegation can be highly granular (e.g., HR can reset passwords only in the ‘Employees’ OU).
  • Entra ID: Employs RBAC (role-based access control) and, to a more limited extent, administrative units to define scopes. Roles are assigned globally or to specific units, with entitlement management automating access workflows. Granularity is generally coarser, though dynamic access and privileged identity management expand the model for cloud workflows.
FeatureAD DSMicrosoft Entra ID
Delegation mechanismOU-level, permission-basedRole-based (RBAC), admin units
Group managementStatic groups in OUsDynamic, rules-based, entitlement-managed
Automated lifecycleLimitedExtensive via dynamic groups, access packages

Example: In AD DS, an OU admin can be delegated password reset rights only for a subset of users; in Entra ID, helpdesk admin roles are more global unless explicitly limited by administrative units.

Hybrid Identity in Practice: Example Scenarios and Decision Points

Scenario 1 – Office 365 Modernization:
A company running on-prem AD DS wants to enable access to Microsoft 365. By configuring directory synchronization (e.g., Entra Connect), users are provisioned into Entra ID. Staff can use their existing credentials for SSO across desktop logon and cloud services.

Scenario 2 – Hybrid with Legacy Workloads:
An organization migrates a business-critical application to Azure. The app depends on Kerberos authentication, which Entra ID does not provide. By enabling Entra Domain Services, the company offers managed Kerberos/LDAP authentication in Azure, sourced from Entra ID identities, without fully extending the on-prem AD into the cloud.

Scenario 3 – Multi-forest Enterprise:
A multinational merges separate AD forests, each with unique HR and IT attributes. Directory synchronization must be carefully planned to avoid attribute collisions, with clear rules for which forest is the source of truth for each user or group property.

Key Decision Points:

  • Use Entra Domain Services only when legacy protocols are required in the cloud; otherwise, favor direct modernization to cloud protocols.
  • Evaluate whether RBAC and dynamic group functionality in Entra ID are sufficient for administrative and access needs—or if finer OU-based delegation remains necessary.
  • Plan synchronization scope tightly: only synchronize users, groups, and attributes required for cloud functions to minimize security and operational risks.

Pitfalls, Misconceptions, and Best Practices

Misconception: Microsoft Entra ID fully replaces Active Directory for all workloads.
Reality: Many legacy features—Group Policy, computer account management, NTLM/Kerberos auth—require AD DS or Entra Domain Services.

Misconception: Directory synchronization is bi-directional.
Reality: Standard synchronization flows from AD DS to Entra ID. Cloud-side changes do not populate on-prem AD except in limited, explicitly configured hybrid scenarios.

Misconception: All authentication protocols are available everywhere.
Reality: Entra ID natively offers cloud protocols (OIDC/SAML). Legacy protocols are not available unless Entra Domain Services is deployed, and even then only within that managed instance.

Pitfalls to watch:

  • Unsanctioned attribute merges in multi-forest sync can cause inconsistent user objects.
  • Overbroad synchronization scope may inadvertently expose sensitive data or create orphaned cloud identities.
  • Relying on default admin roles in Entra ID risks excessive privilege; always review and customize RBAC assignments.
  • Deploying unsupported sync topologies leads to operational instability and unsupported states.

Best Practices:

  • Plan synchronization with minimal, well-defined scoping and attribute mapping.
  • Avoid maintaining legacy protocol support longer than needed—move toward modern authentication where possible.
  • Use RBAC and administrative units in Entra ID to restrict cloud privileges appropriately.
  • Thoroughly document and validate sync rules, especially when merging multiple forests or domains.

Building for Secure and Future-proof Hybrid Identity

Hybrid identity is the backbone of secure, flexible enterprise IT in a world where both legacy and modern workloads must often coexist. By understanding the distinct roles of AD DS and Microsoft Entra ID, using the right synchronization approach, and deploying Entra Domain Services only when necessary, practitioners can deliver seamless user experiences without sacrificing security or manageability.

The most resilient hybrid architectures are built on an explicit mapping of capabilities, deliberate synchronization design, clear administrative boundaries, and a roadmap to retire legacy dependencies. Practitioners should consult official Microsoft guidance and plan integrations with equal care for immediate technical needs and future cloud adoption.

Sources:

  • Compare Active Directory to Microsoft Entra ID
  • Microsoft Entra Cloud Sync supported topologies and scenarios
  • Overview of Microsoft Entra Domain Services
  • What is hybrid identity with Microsoft Entra ID?
  • Microsoft Entra Connect Sync: Understand and customize synchronization

Sources