Choose Microsoft Entra Cloud Sync when your domains stay under 150,000 objects each, no group exceeds 50,000 members, you filter by OU rather than complex attribute rules, and you don't depend on advanced sync rules, cross-forest references or device writeback; otherwise stay on Entra Connect Sync for now. To migrate, either run the guided Transition to Cloud Sync task from the active Connect Sync server (currently for one forest with up to 2,000 in-scope objects), or pilot by OU: keep objects in Connect Sync scope, add cloudNoFlow and JoinNoFlow rules so Connect Sync stops exporting them, scope a Cloud Sync configuration to the same OU, verify, and repeat batch by batch. Never remove objects from Connect Sync scope before cutover, because that exports reference deletes such as lost group memberships.
Who this is for and what you will have at the end
This guide is for administrators who run Entra Connect Sync today and need to decide whether to move to Cloud Sync, or who are designing hybrid identity for a new forest. It assumes you can sign in to the Connect Sync server and to Microsoft Entra ID as a Hybrid Identity Administrator.
At the end you will have:
- A feature-by-feature view of what each engine supports.
- A readiness decision for your environment.
- A migration procedure, guided or manual, that keeps users, group memberships and manager links intact.
- A verification and rollback plan.
How the two engines differ
Entra Connect Sync is an on-premises sync engine. Its configuration, connector spaces and metaverse live in a SQL Server database on the sync server. Only one server can export at a time; a second server in staging mode is the standby. You manage it with the wizard, the Synchronization Rules Editor and PowerShell on the server.
Entra Cloud Sync splits the work. The Microsoft Entra provisioning agent is a lightweight on-premises agent that keeps an outbound connection through Azure Service Bus and answers requests by reading Active Directory. The Microsoft Entra provisioning service in the cloud holds the configuration, runs the schedule (every two minutes), applies scoping and attribute mappings, and commits changes. You configure everything in the Microsoft Entra admin center, and agents update themselves.
The practical consequences:
- Availability. Several Cloud Sync agents are active at once and fail over automatically. Microsoft recommends three active agents. Connect Sync is a single active server.
- Disconnected forests. Cloud Sync natively handles forests that can't see each other, such as after an acquisition, with dedicated agents per forest. Microsoft describes the same scenario in Connect Sync as requiring complicated configurations or multiple instances.
- Customization. Connect Sync has a full sync rule engine. Cloud Sync uses attribute mappings with an expression builder.
- Direction of new features. Microsoft states that new synchronization features are being developed primarily on Cloud Sync, such as group provisioning to Active Directory.
Feature comparison
These rows come from Microsoft's Cloud Sync decision guide.
| Capability | Connect Sync | Cloud Sync |
|---|---|---|
| Users, groups, contacts | Yes | Yes |
| Multiple connected forests | Yes | Yes |
| Disconnected forests | No | Yes |
| Device sync for Microsoft Entra hybrid join | Yes | Yes (enable device sync separately) |
| Multiple active instances | No | Yes |
| Scale per domain | Unlimited | 150,000 objects |
| Largest group | 250,000 members | 50,000 members |
| Password hash sync | Yes | Yes |
| Password writeback | Yes | Yes |
| Pass-through authentication configuration | Yes | No (configured separately; keeps working) |
| AD FS setup | Yes | No |
| Exchange hybrid attributes | Yes | Yes |
| Directory extensions and custom AD attributes | Yes | Yes |
| Advanced sync rules | Yes | No (expression builder) |
| OU-based filtering | Yes | Yes |
| Attribute-based filtering | Yes | Limited |
| Device writeback | Yes | No |
| Group provisioning to AD | No | Yes |
| Cross-forest references | Yes | No |
| Merge attributes from multiple domains | Yes | No |
| Reconciliation (out-of-band correction) | Yes | No |
| On-demand provisioning for testing | No | Yes |
| Seamless SSO | Yes | Yes |
Microsoft's scenario table also lists a few situations that remain Connect Sync only: user accounts in one forest with mailboxes in a resource forest, Windows Hello for Business, filtering directory objects by attribute values, and syncing domains with more than 250,000 objects. Two scenarios are Cloud Sync only: mergers and acquisitions with disconnected forests, and high availability with multiple active agents.
Decide: migrate now, soon, or later
Ready now if all of these are true:
- Fewer than 150,000 objects per Active Directory domain.
- No group above 50,000 members.
- Password hash sync, or PTA and AD FS that you manage separately from the sync tool.
- OU-based filtering rather than complex attribute rules.
- Single forest or connected forests.
- Device sync included in the plan if you use Microsoft Entra hybrid join.
Plan for later if you depend on advanced attribute filtering, cloud-to-AD user provisioning, more than 150,000 objects per domain, extensive custom sync rules, cross-forest references, or reconciliation. For large environments, Microsoft suggests assessing whether a migration segmented by domain or OU is viable.
Microsoft notifies eligible organizations through in-product messages and email, and the notification states the migration window. If a confirmed blocker prevents you from meeting it, you can request a temporary exception through Microsoft Support with a readiness report and a migration plan. Microsoft's FAQ also says you aren't required to migrate until the features you depend on are available in Cloud Sync.
If you stay on Connect Sync, it still has its own deadline: every server must run version 2.6.84.0 or later with application-based authentication by 7 April 2027. Replacing an old Connect Sync server is covered in the staging mode swing migration guide.
Prerequisites for Cloud Sync
- A Hybrid Identity Administrator account that isn't a guest. Microsoft also recommends a cloud-only Hybrid Identity Administrator so you can manage the configuration if on-premises services fail.
- Domain Administrator or Enterprise Administrator credentials to create the group managed service account (gMSA) the agent runs as, shown as
domain\provAgentgMSA$. - Domain-joined Windows Server hosts for the agents, with at least 4 GB of RAM and .NET Framework 4.7.1 or later. Windows Server 2025 or 2022 is recommended; Server Core isn't supported. A domain controller can host the agent, and the server should be treated as Tier 0.
- TLS 1.2 enabled before the agent is installed.
- PowerShell execution policy set to Undefined or RemoteSigned.
- The
msDS-ExternalDirectoryObjectIdschema attribute, available from Windows Server 2016 schema. - Outbound access on 443 (and 80 for certificate revocation checks) to the documented URLs, including
*.msappproxy.netand*.servicebus.windows.net. ms-ds-consistencyGUIDpopulated on objects in the pilot scope so Cloud Sync hard matches them. Connect Sync doesn't populate it for group objects by default.
Back up the Connect Sync configuration first with the wizard task View or Export Current Configuration.
Option 1: The guided migration tool
Entra Connect Sync 2.6.91.0 and later include a guided workflow that assesses the environment, creates the Cloud Sync configuration, runs a Provision on Demand check, places Connect Sync in staging mode and activates Cloud Sync. It's available only in the Azure public cloud, and only to organizations in the current migration wave.
Current limits:
- One Active Directory forest with no more than 2,000 in-scope objects.
- Additive OU inclusion scoping with no more than 30 included containers per domain.
- No migration-blocking features such as custom sync rules, group filtering, a custom UPN, directory extensions, device synchronization or unsupported writeback.
Supported scenarios are user and group sync, password hash sync, password writeback, Exchange hybrid writeback, and supported domain and OU scoping.
Procedure:
- On the active Connect Sync server (not a staging server), open the wizard, select Configure, then Transition to Cloud Sync.
- Sign in as a Hybrid Identity Administrator and enter Domain Admin credentials for each forest.
- Review the readiness results, including the accidental-deletion threshold. Enter an address for quarantine notifications, download the readiness report, accept the consent and select Start Transition. Don't try to bypass a blocking result.
- Wait while the tool installs and registers the agent and creates one disabled Cloud Sync configuration per domain. Connect Sync keeps exporting during this stage.
- Select Open Entra Portal, open each new configuration, select Provision on demand, enter the distinguished name of an approved test user or group, and review the detailed result. If password writeback is enabled, confirm tenant-level SSPR writeback.
- Select Complete transfer to Cloud Sync. The tool enables the Cloud Sync jobs, puts Connect Sync in staging mode, and starts the initial Cloud Sync cycle.
- On the validation page, compare the Total Objects counts and job health, then manually check representative users, groups, memberships and writeback. Select Complete Migration when everything checks out.
Keep Connect Sync installed for a two-week validation period. Don't uninstall it during initial validation.
Option 2: Phased migration by OU
For environments outside the tool's limits, use the documented pilot pattern. The key rule: objects stay in Connect Sync scope throughout. Custom rules stop Connect Sync from exporting object adds, deletes and non-reference attribute updates for migrated objects, while reference attributes such as member and manager can still flow.
Step 1: Pick the pilot OU and count it
Choose a small OU that's already in Connect Sync scope, or move pilot users into a new OU and let Connect Sync pick them up first. Count the users:
Get-ADUser -Filter * -SearchBase "OU=Finance,OU=UserAccounts,DC=contoso,DC=com" | Measure-ObjectStep 2: Stop the Connect Sync scheduler
Stop-ADSyncSyncCycle
Set-ADSyncScheduler -SyncCycleEnabled $falseStep 3: Create the inbound cloudNoFlow rule
In the Synchronization Rules Editor, set Direction to Inbound and select Add new rule:
- Connected System Object Type: user; Metaverse Object Type: person.
- Link Type: Join; Precedence: a value unique in the system; Tag: empty.
- Scoping filter:
DNENDSWITHthe OU's distinguished name, orISMEMBEROFa pilot security group. - Transformations: a Constant transformation with source value
Truefor thecloudNoFlowattribute.
Repeat for groups and contacts, and for each Active Directory connector or forest.
Step 4: Create the outbound JoinNoFlow rule
Set Direction to Outbound and add a rule for the Microsoft Entra connector:
- Connected System Object Type: user; Metaverse Object Type: person.
- Link Type: JoinNoFlow; Precedence: unique.
- Scoping filter: attribute
cloudNoFlowequalsTrue.
Repeat for groups and contacts.
Step 5: Install the agent and configure Cloud Sync
- In the Microsoft Entra admin center, go to Entra Connect > Cloud Sync > Agents and select Download on-premises agent.
- Run
AADConnectProvisioningAgentSetup.exe, sign in as a Hybrid Identity Administrator, choose Create gMSA (or a custom gMSA), add the domain, and select Confirm. - Check that the agent shows active under Agents, and that the services Microsoft Azure AD Connect Agent Updater and Microsoft Azure AD Connect Provisioning Agent are running.
- Under Entra ID > Entra Connect > Cloud sync, select New configuration, choose the domain and whether to enable password hash sync, and select Create.
- Under Scoping filters, select Selected organizational units, enter the pilot OU, and save.
Install at least two more agents on other servers before you rely on Cloud Sync for production.
Step 6: Verify and restart the scheduler
Use Provision on demand for a pilot user, then compare the number of synced users whose on-premises distinguished name contains the pilot OU with the count from Step 1. Create a test user in the OU and confirm it's provisioned. Then restart Connect Sync:
Set-ADSyncScheduler -SyncCycleEnabled $true
Start-ADSyncSyncCycleStep 7: Migrate the remaining batches and cut over
Repeat Steps 3 to 6 per OU or batch, extending the rule scope and the Cloud Sync scoping filter. When every object and its references are provisioned by Cloud Sync, stop Connect Sync for that scope as the final cutover. Microsoft recommends leaving the Connect Sync server disabled for a period before you uninstall it.
Verification
- Cloud Sync configuration status is healthy, with no quarantine.
- Provisioning logs show creates and updates for migrated objects. These logs don't always distinguish create from update, so check the object itself.
- Group memberships and manager links in Microsoft Entra ID match Active Directory for a sample of objects.
- Password hash sync works for a changed test password, and password writeback works if enabled.
- No Connect Sync exports for migrated objects other than reference attributes.
Troubleshooting
Group memberships or manager references disappeared. Objects were removed from Connect Sync scope while their references were still in coexistence. Add them back to Connect Sync scope and run a full synchronization (Start-ADSyncSyncCycle -PolicyType Initial) to rebuild references. Remove scope again only after Cloud Sync provisions every referenced object.
The pilot misbehaves and you need to back out. Disable the Cloud Sync configuration in the portal, then disable the custom cloudNoFlow and JoinNoFlow rules in the Synchronization Rules Editor. Disabling the rules triggers a full sync on all connectors, and Connect Sync resumes exporting.
Renamed OU or group isn't recognized. Cloud Sync doesn't detect the rename of an in-scope OU or group, and delta sync doesn't remove the affected users. Update the scoping filter.
Scoping configuration fails as you add OUs. The scope is limited to 4 MB, about 50 separate OUs or security groups. Nested OUs under one selected OU are supported, so restructure scope around parent OUs.
Group scope filter misses members. Delta sync with group scope filtering doesn't support more than 50,000 members.
Guided tool won't start. It must run on the active server, and the readiness review lists blocking features. Use the manual OU method, or wait for support of the blocking feature.
Checklist
- Scenario and feature comparison reviewed; readiness category chosen.
- Connect Sync configuration exported.
ms-ds-consistencyGUIDpopulated for objects to migrate, groups included.- Three Cloud Sync agents planned on Tier 0 servers.
- Guided tool used if eligible; otherwise
cloudNoFlowandJoinNoFlowrules created for users, groups and contacts. - Objects kept in Connect Sync scope until their batch is fully migrated.
- Provision on demand, object counts and references verified per batch.
- Connect Sync left installed (two weeks for the guided tool) before uninstalling.
References
- Common hybrid scenarios with Microsoft Entra ID
- What is Microsoft Entra Cloud Sync?
- Microsoft Entra Cloud Sync migration decision guide
- Migrate to Microsoft Entra Cloud Sync
- Migrate to Microsoft Entra Cloud Sync with the migration tool
- Tutorial: Migrate to Microsoft Entra Cloud Sync for a synced Active Directory forest
- Migrate from Microsoft Entra Connect Sync to Cloud Sync FAQ
- Prerequisites for Microsoft Entra Cloud Sync
- Microsoft Entra Connect Sync: Scheduler
- Microsoft Entra Connect: Upgrade from a previous version