Microsoft Entra Connect is the cornerstone tool for integrating on-premises Active Directory environments with Microsoft Entra ID (formerly Azure AD), enabling hybrid identity for organizations moving toward the cloud. This article unpacks Entra Connect’s architecture, features, deployment considerations, its relationship with Entra Cloud Sync, and clarifies common misconceptions—equipping you to make informed technical decisions about hybrid directory integration.
What is Microsoft Entra Connect?
Microsoft Entra Connect is an on-premises synchronization engine designed to bridge traditional Active Directory (AD) and modern cloud-based Microsoft Entra ID. It enables a unified hybrid identity by automatically syncing users, groups, and selected devices from local AD to Microsoft Entra ID. With Entra Connect, organizations can provide seamless, consistent sign-in and resource access experiences across on-premises and cloud applications.
This hybrid identity model is essential for organizations running complex legacy systems, regulated workloads, or requiring gradual migration to the cloud. Entra Connect is particularly relevant in environments with:
- An on-premises Active Directory forest or multiple forests
- Requirements for unified authentication and directory synchronization
- The need to leverage Microsoft 365, Entra ID–based SSO, or cloud application access based on on-premises identities
Key Features and How They Work
Directory Synchronization
Entra Connect’s primary function is syncing identities from Active Directory to Microsoft Entra ID. This synchronization supports users, groups, contacts, and (optionally) some device objects. It operates via a scheduled sync cycle, moving changes from on-premises AD to the cloud. Filtering rules enable administrators to restrict synchronization by organizational unit, domain, or specific object attributes.
Authentication Options
Entra Connect supports multiple authentication paradigms, each with distinct architectural and security implications:
- Password Hash Synchronization: AD password hashes (not plaintext passwords) are regularly synchronized to Entra ID. Users authenticate directly against the cloud directory, with no dependency on local AD for sign-in availability.
- Pass-Through Authentication (PTA): User sign-in requests are securely routed from Entra ID back to on-premises domain controllers through an authentication agent. This allows cloud-based sign-in that verifies credentials against local AD in real time.
- Federation (Active Directory Federation Services, AD FS): Instead of relying on hash or pass-through, users are redirected to AD FS for authentication. This enables true SSO, with local policies enforced during sign-in.
Write-Back Capabilities
Entra Connect supports select write-back features, enabling cloud-side changes to propagate back to on-premises systems:
- Password Write-Back: Allows users to reset or change their password in Entra ID, and have it written back to AD, supporting hybrid self-service password reset (SSPR).
- Group Write-Back: Selected Microsoft 365 groups can be written back to Active Directory for hybrid group management.
Monitoring with Connect Health
The Entra Connect Health service provides operational monitoring, alerting, and central visibility into directory sync, authentication agents, and AD FS infrastructure. This helps proactively surface and resolve sync or sign-in issues.
Supported Architectures and Topologies
Microsoft officially supports several deployment topologies, each targeting specific directory layouts and business requirements:
- Single AD Forest, Single Entra Tenant: The simplest model; one on-prem AD forest synced to one Entra tenant.
- Multiple Forests, Single Tenant: Supports organizations with several AD forests desiring a unified cloud identity.
- Account-Resource Forests: Useful for complex resource/account separation use-cases.
- Staging Mode Server: Optional secondary Entra Connect server operating in ‘standby.’ Only one server is actively synchronizing at a time, but the standby can assume the role if needed.
Unsupported Topologies:
- Multiple active Entra Connect sync servers targeting the same tenant (except staged mode for failover).
- Installations against read-only domain controllers (RODCs).
- Multiple Entra Connect installations writing to a single Entra tenant in parallel.
Deploying unsupported topologies can result in unsupported states and disrupt both synchronization and Microsoft support eligibility.
Deployment Prerequisites and System Requirements
Before deploying Microsoft Entra Connect, organizations must meet several technical requirements:
- Operating System: Windows Server 2016 or newer is required. Installing on domain controllers is supported but not recommended in production; a dedicated, hardened server is preferred.
- Hardware: Minimum 1.6 GHz CPU, at least 6 GB RAM, and 70 GB of free disk space.
- Active Directory: The forest must be at Windows Server 2003 functional level or higher, with a writable domain controller available.
- Domains: The domains to be synchronized must be verified in Microsoft Entra ID.
- Directory Health: Run the IdFix utility pre-deployment to identify and remediate problematic objects or attributes in AD.
- Security: The Entra Connect server should reside in a secure network segment and treated as a Tier 0 asset, as it holds credentials and moves sensitive identity data.
- Software: .NET Framework as specified by documentation; PowerShell 5.x; TLS 1.2 enforced for all communications.
- Licensing: Certain advanced features (like write-back) require Microsoft Entra ID P1/P2 or corresponding Microsoft 365 licenses.
Lifecycle Mandates: Organizations must ensure Entra Connect Sync is at version 2.5.79.0 or later by September 30, 2026, to remain supported and avoid sync disruption.
Feature Comparison: Entra Connect vs. Cloud Sync
| Feature | Entra Connect | Entra Cloud Sync |
|---|---|---|
| Deployment Model | On-premises sync engine | Lightweight agent with cloud logic |
| Directory Source Support | Multi-forest (incl. advanced joins) | Single forest; limited multi-forest |
| Filtering | OU, domain, and attribute-based | OU/domain; limited attribute support |
| Write-Back (password, group) | Supported (requires proper licensing) | Password write-back; group not yet |
| Device Object Sync | Supported | Not supported |
| Custom Attribute Flows | Supported | Limited |
| Staging/Failover | Staging mode supported | Supported via agent redundancy |
| Monitoring | Connect Health | Monitored in Entra portal |
| Ideal For | Complex or legacy hybrid scenarios | Simple/modern hybrid with cloud-first ops |
| Licensing & Scale | Higher complexity, more flexibility | Lower overhead, evolving capabilities |
Key distinctions: Entra Connect remains essential for advanced topologies (multi-forest, device write-back, complex attribute flows) and hybrid write-back scenarios. Entra Cloud Sync is the strategic, lightweight solution for straightforward sync needs, with easier agent management and rapid deployment.
Limits, Write-Back Scenarios, and Filtering Options
- Object and Service Limits: By default, a Microsoft Entra ID tenant allows up to 50,000 objects. Verifying a custom domain raises this to 300,000. Exceeding these limits requires additional eligible licensing and a support request.
- Write-Back Boundaries: Password write-back is supported in both Entra Connect and Cloud Sync (subject to configuration and licensing). Group write-back is currently supported only in Entra Connect.
- Filtering: Entra Connect provides granular scope controls—organizational unit (OU), domain, and attribute filtering at the sync engine level. Filtering enables controlling which identities and groups flow to Entra ID, improving security and compliance.
Common Misconceptions and Pitfalls
- Myth: Entra Connect and Cloud Sync are interchangeable.
- Reality: Feature parity has not yet been reached. Only Entra Connect supports advanced topologies, device write-back, and many custom sync options.
- Myth: Multiple active Entra Connect sync servers improve redundancy.
- Reality: Only one server may actively synchronize to an Entra tenant. Use ‘staging mode’ for a hot standby, not for parallel sync. Multiple actives will break support and risk directory integrity.
- Myth: It’s safe to install Entra Connect on a domain controller.
- Reality: While technically supported, best practice is a dedicated, hardened Windows Server. The Entra Connect server should be treated as highly privileged (Tier 0)—isolated from general workloads.
- Myth: Cloud Sync provides every capability available in Entra Connect.
- Reality: Cloud Sync is advancing quickly but cannot yet cover advanced filtering, device write-back, some write-back scenarios, or all multi-forest joins. Verify current feature support before migrating or implementing.
References and Further Reading
- Microsoft Learn: What is Microsoft Entra Connect and Connect Health
- Microsoft Learn: Microsoft Entra Connect – Prerequisites and hardware
- Microsoft Learn: Microsoft Entra Connect Sync service features
- Microsoft Learn: Microsoft Entra Connect – Supported topologies
- Microsoft Learn: Migrate from Microsoft Entra Connect to Cloud Sync
- Microsoft Learn: Microsoft Entra service limits and restrictions
Sources
- learn.microsoft.com — whatis-azure-ad-connect
- learn.microsoft.com — how-to-connect-install-prerequisites
- learn.microsoft.com — how-to-connect-syncservice-features
- learn.microsoft.com — plan-connect-topologies
- learn.microsoft.com — connect-to-cloud-sync-decision-guide
- learn.microsoft.com — directory-service-limits-restrictions