Entra Connect Sync is on its way out. Start planning for Cloud Sync.
Microsoft has started a phased move of identity sync from Entra Connect Sync to Cloud Sync, and has closed a privilege takeover route in hybrid sync. Here's what both changes mean for you.
On this page
If you run hybrid identity, two changes this year deserve your attention. Microsoft is moving customers off Entra Connect Sync for identity synchronisation, and it has blocked a technique attackers could use to take over privileged cloud accounts through sync.
- 01Message Center notice
- 02Inventory sync rules and features
- 03Check the feature comparison
- 04Pilot Cloud Sync
- 05Transition identity sync
The move to Cloud Sync
Entra Cloud Sync replaces the heavy Connect Sync server with lightweight provisioning agents, with configuration held in the cloud. Microsoft is now transitioning customers to it in phases:
- Notifications started in July 2026, through the Message Center, Connect Health and targeted emails. Each tenant gets its own timeline.
- Simple tenants go first. Early waves target organisations whose needs Cloud Sync already covers. Large directories and those using advanced Connect Sync features come later, as Cloud Sync gains capabilities.
- You can test first. Microsoft provides guidance and a transition tool, and you can move and test sync in Cloud Sync before anything permanent changes.
- Hybrid authentication stays. Features that let on-premises credentials reach cloud resources remain available through the Connect Sync configuration wizard. Cloud Sync takes over the identity sync job.
Entra Connect Sync
The traditional sync server
- Full server with a local SQL database
- Configuration lives on the server
- One active server, with staging mode for standby
- Rich custom sync rules
- Syncs devices for hybrid join
Entra Cloud Sync
Lightweight agents
- Small provisioning agent on domain-joined servers
- Configuration held in the cloud
- Several agents for high availability
- Works with disconnected forests
- Gaining features over time
Get ready before your notification lands
- Inventory your current setup. List the custom sync rules, filtering, writeback options and other features you depend on.
- Check the feature comparison. Microsoft publishes a comparison between Connect Sync and Cloud Sync. Anything you rely on that Cloud Sync lacks probably puts you in a later wave.
- Read the migration guide and try Cloud Sync in a test environment or on a pilot OU.
- Look at Source of Authority. Moving the source of authority for users or groups from AD to the cloud is a separate option, and you don't have to migrate sync first. For groups that no longer need to live in AD, it's worth considering.
- Inventory sync rules, filters, writeback and device sync
- Compare against the Cloud Sync feature list and note any gaps
- Install agents and test Cloud Sync on a scoped OU
- Follow your tenant's timeline from Microsoft
- Move identity sync, keep hybrid authentication features
Running both side by side
Connect Sync and Cloud Sync can run in the same tenant as long as they sync different objects. That's how most pilots work: scope Cloud Sync to a test OU, and exclude the same OU from Connect Sync. Never let both engines manage the same user, or they'll fight over its attributes.
Questions to answer in your inventory
- Which OUs and groups are in scope, and is any attribute filtering used?
- Are there custom sync rules, and what do they do?
- Is password writeback, group writeback or device writeback in use?
- Are computer objects synced for hybrid join?
- Which authentication method: password hash sync, pass-through or federation?
- Is Exchange hybrid in use, with its attribute writeback?
Hard match is now blocked for privileged users
When sync adds an AD object, Entra looks for an existing cloud object with a matching OnPremisesImmutableId. If it finds one, sync takes over that cloud object and overwrites it with the AD object's properties. This is a hard match.
That's useful when connecting existing cloud accounts to AD. It's also an attack path: someone with control over AD attributes could hard-match to a privileged cloud-only admin and take it over.
Since 1 June 2026, Entra blocks sync from hard-matching a new AD user to a cloud user that holds an Entra role. Soft matching, hard matching for users without roles, and existing synced objects are unaffected.
Do I have to move to Cloud Sync straight away?
No. Microsoft is moving tenants in phases and will tell you when yours is due. Use the time to inventory and pilot so there are no surprises.
What about pass-through authentication and seamless SSO?
Hybrid authentication features stay available through the Connect Sync configuration wizard. Cloud Sync takes over identity synchronisation.
Is device sync for hybrid join covered?
Check the current feature comparison. If you rely on syncing computer objects, look at Entra join for new devices, or the Entra Kerberos hybrid join preview.