Security & identity

Entra Cloud Sync vs Connect Sync - choose an engine and migrate safely

Compare Microsoft Entra Cloud Sync and Entra Connect Sync feature by feature, check migration readiness, and move with the guided tool or a phased OU pilot.

13 min read
On this page

Choose Microsoft Entra Cloud Sync when your domains stay under 150,000 objects each, no group exceeds 50,000 members, you filter by OU rather than complex attribute rules, and you don't depend on advanced sync rules, cross-forest references or device writeback; otherwise stay on Entra Connect Sync for now. To migrate, either run the guided Transition to Cloud Sync task from the active Connect Sync server (currently for one forest with up to 2,000 in-scope objects), or pilot by OU: keep objects in Connect Sync scope, add cloudNoFlow and JoinNoFlow rules so Connect Sync stops exporting them, scope a Cloud Sync configuration to the same OU, verify, and repeat batch by batch. Never remove objects from Connect Sync scope before cutover, because that exports reference deletes such as lost group memberships.

Who this is for and what you will have at the end

This guide is for administrators who run Entra Connect Sync today and need to decide whether to move to Cloud Sync, or who are designing hybrid identity for a new forest. It assumes you can sign in to the Connect Sync server and to Microsoft Entra ID as a Hybrid Identity Administrator.

At the end you will have:

  • A feature-by-feature view of what each engine supports.
  • A readiness decision for your environment.
  • A migration procedure, guided or manual, that keeps users, group memberships and manager links intact.
  • A verification and rollback plan.

How the two engines differ

Entra Connect Sync is an on-premises sync engine. Its configuration, connector spaces and metaverse live in a SQL Server database on the sync server. Only one server can export at a time; a second server in staging mode is the standby. You manage it with the wizard, the Synchronization Rules Editor and PowerShell on the server.

Entra Cloud Sync splits the work. The Microsoft Entra provisioning agent is a lightweight on-premises agent that keeps an outbound connection through Azure Service Bus and answers requests by reading Active Directory. The Microsoft Entra provisioning service in the cloud holds the configuration, runs the schedule (every two minutes), applies scoping and attribute mappings, and commits changes. You configure everything in the Microsoft Entra admin center, and agents update themselves.

The practical consequences:

  • Availability. Several Cloud Sync agents are active at once and fail over automatically. Microsoft recommends three active agents. Connect Sync is a single active server.
  • Disconnected forests. Cloud Sync natively handles forests that can't see each other, such as after an acquisition, with dedicated agents per forest. Microsoft describes the same scenario in Connect Sync as requiring complicated configurations or multiple instances.
  • Customization. Connect Sync has a full sync rule engine. Cloud Sync uses attribute mappings with an expression builder.
  • Direction of new features. Microsoft states that new synchronization features are being developed primarily on Cloud Sync, such as group provisioning to Active Directory.

Feature comparison

These rows come from Microsoft's Cloud Sync decision guide.

CapabilityConnect SyncCloud Sync
Users, groups, contactsYesYes
Multiple connected forestsYesYes
Disconnected forestsNoYes
Device sync for Microsoft Entra hybrid joinYesYes (enable device sync separately)
Multiple active instancesNoYes
Scale per domainUnlimited150,000 objects
Largest group250,000 members50,000 members
Password hash syncYesYes
Password writebackYesYes
Pass-through authentication configurationYesNo (configured separately; keeps working)
AD FS setupYesNo
Exchange hybrid attributesYesYes
Directory extensions and custom AD attributesYesYes
Advanced sync rulesYesNo (expression builder)
OU-based filteringYesYes
Attribute-based filteringYesLimited
Device writebackYesNo
Group provisioning to ADNoYes
Cross-forest referencesYesNo
Merge attributes from multiple domainsYesNo
Reconciliation (out-of-band correction)YesNo
On-demand provisioning for testingNoYes
Seamless SSOYesYes

Microsoft's scenario table also lists a few situations that remain Connect Sync only: user accounts in one forest with mailboxes in a resource forest, Windows Hello for Business, filtering directory objects by attribute values, and syncing domains with more than 250,000 objects. Two scenarios are Cloud Sync only: mergers and acquisitions with disconnected forests, and high availability with multiple active agents.

Decide: migrate now, soon, or later

Ready now if all of these are true:

  • Fewer than 150,000 objects per Active Directory domain.
  • No group above 50,000 members.
  • Password hash sync, or PTA and AD FS that you manage separately from the sync tool.
  • OU-based filtering rather than complex attribute rules.
  • Single forest or connected forests.
  • Device sync included in the plan if you use Microsoft Entra hybrid join.

Plan for later if you depend on advanced attribute filtering, cloud-to-AD user provisioning, more than 150,000 objects per domain, extensive custom sync rules, cross-forest references, or reconciliation. For large environments, Microsoft suggests assessing whether a migration segmented by domain or OU is viable.

Microsoft notifies eligible organizations through in-product messages and email, and the notification states the migration window. If a confirmed blocker prevents you from meeting it, you can request a temporary exception through Microsoft Support with a readiness report and a migration plan. Microsoft's FAQ also says you aren't required to migrate until the features you depend on are available in Cloud Sync.

If you stay on Connect Sync, it still has its own deadline: every server must run version 2.6.84.0 or later with application-based authentication by 7 April 2027. Replacing an old Connect Sync server is covered in the staging mode swing migration guide.

Prerequisites for Cloud Sync

  • A Hybrid Identity Administrator account that isn't a guest. Microsoft also recommends a cloud-only Hybrid Identity Administrator so you can manage the configuration if on-premises services fail.
  • Domain Administrator or Enterprise Administrator credentials to create the group managed service account (gMSA) the agent runs as, shown as domain\provAgentgMSA$.
  • Domain-joined Windows Server hosts for the agents, with at least 4 GB of RAM and .NET Framework 4.7.1 or later. Windows Server 2025 or 2022 is recommended; Server Core isn't supported. A domain controller can host the agent, and the server should be treated as Tier 0.
  • TLS 1.2 enabled before the agent is installed.
  • PowerShell execution policy set to Undefined or RemoteSigned.
  • The msDS-ExternalDirectoryObjectId schema attribute, available from Windows Server 2016 schema.
  • Outbound access on 443 (and 80 for certificate revocation checks) to the documented URLs, including *.msappproxy.net and *.servicebus.windows.net.
  • ms-ds-consistencyGUID populated on objects in the pilot scope so Cloud Sync hard matches them. Connect Sync doesn't populate it for group objects by default.

Back up the Connect Sync configuration first with the wizard task View or Export Current Configuration.

Option 1: The guided migration tool

Entra Connect Sync 2.6.91.0 and later include a guided workflow that assesses the environment, creates the Cloud Sync configuration, runs a Provision on Demand check, places Connect Sync in staging mode and activates Cloud Sync. It's available only in the Azure public cloud, and only to organizations in the current migration wave.

Current limits:

  • One Active Directory forest with no more than 2,000 in-scope objects.
  • Additive OU inclusion scoping with no more than 30 included containers per domain.
  • No migration-blocking features such as custom sync rules, group filtering, a custom UPN, directory extensions, device synchronization or unsupported writeback.

Supported scenarios are user and group sync, password hash sync, password writeback, Exchange hybrid writeback, and supported domain and OU scoping.

Procedure:

  1. On the active Connect Sync server (not a staging server), open the wizard, select Configure, then Transition to Cloud Sync.
  2. Sign in as a Hybrid Identity Administrator and enter Domain Admin credentials for each forest.
  3. Review the readiness results, including the accidental-deletion threshold. Enter an address for quarantine notifications, download the readiness report, accept the consent and select Start Transition. Don't try to bypass a blocking result.
  4. Wait while the tool installs and registers the agent and creates one disabled Cloud Sync configuration per domain. Connect Sync keeps exporting during this stage.
  5. Select Open Entra Portal, open each new configuration, select Provision on demand, enter the distinguished name of an approved test user or group, and review the detailed result. If password writeback is enabled, confirm tenant-level SSPR writeback.
  6. Select Complete transfer to Cloud Sync. The tool enables the Cloud Sync jobs, puts Connect Sync in staging mode, and starts the initial Cloud Sync cycle.
  7. On the validation page, compare the Total Objects counts and job health, then manually check representative users, groups, memberships and writeback. Select Complete Migration when everything checks out.

Keep Connect Sync installed for a two-week validation period. Don't uninstall it during initial validation.

Option 2: Phased migration by OU

For environments outside the tool's limits, use the documented pilot pattern. The key rule: objects stay in Connect Sync scope throughout. Custom rules stop Connect Sync from exporting object adds, deletes and non-reference attribute updates for migrated objects, while reference attributes such as member and manager can still flow.

Step 1: Pick the pilot OU and count it

Choose a small OU that's already in Connect Sync scope, or move pilot users into a new OU and let Connect Sync pick them up first. Count the users:

Get-ADUser -Filter * -SearchBase "OU=Finance,OU=UserAccounts,DC=contoso,DC=com" | Measure-Object

Step 2: Stop the Connect Sync scheduler

Stop-ADSyncSyncCycle
Set-ADSyncScheduler -SyncCycleEnabled $false

Step 3: Create the inbound cloudNoFlow rule

In the Synchronization Rules Editor, set Direction to Inbound and select Add new rule:

  • Connected System Object Type: user; Metaverse Object Type: person.
  • Link Type: Join; Precedence: a value unique in the system; Tag: empty.
  • Scoping filter: DN ENDSWITH the OU's distinguished name, or ISMEMBEROF a pilot security group.
  • Transformations: a Constant transformation with source value True for the cloudNoFlow attribute.

Repeat for groups and contacts, and for each Active Directory connector or forest.

Step 4: Create the outbound JoinNoFlow rule

Set Direction to Outbound and add a rule for the Microsoft Entra connector:

  • Connected System Object Type: user; Metaverse Object Type: person.
  • Link Type: JoinNoFlow; Precedence: unique.
  • Scoping filter: attribute cloudNoFlow equals True.

Repeat for groups and contacts.

Step 5: Install the agent and configure Cloud Sync

  1. In the Microsoft Entra admin center, go to Entra Connect > Cloud Sync > Agents and select Download on-premises agent.
  2. Run AADConnectProvisioningAgentSetup.exe, sign in as a Hybrid Identity Administrator, choose Create gMSA (or a custom gMSA), add the domain, and select Confirm.
  3. Check that the agent shows active under Agents, and that the services Microsoft Azure AD Connect Agent Updater and Microsoft Azure AD Connect Provisioning Agent are running.
  4. Under Entra ID > Entra Connect > Cloud sync, select New configuration, choose the domain and whether to enable password hash sync, and select Create.
  5. Under Scoping filters, select Selected organizational units, enter the pilot OU, and save.

Install at least two more agents on other servers before you rely on Cloud Sync for production.

Step 6: Verify and restart the scheduler

Use Provision on demand for a pilot user, then compare the number of synced users whose on-premises distinguished name contains the pilot OU with the count from Step 1. Create a test user in the OU and confirm it's provisioned. Then restart Connect Sync:

Set-ADSyncScheduler -SyncCycleEnabled $true
Start-ADSyncSyncCycle

Step 7: Migrate the remaining batches and cut over

Repeat Steps 3 to 6 per OU or batch, extending the rule scope and the Cloud Sync scoping filter. When every object and its references are provisioned by Cloud Sync, stop Connect Sync for that scope as the final cutover. Microsoft recommends leaving the Connect Sync server disabled for a period before you uninstall it.

Verification

  • Cloud Sync configuration status is healthy, with no quarantine.
  • Provisioning logs show creates and updates for migrated objects. These logs don't always distinguish create from update, so check the object itself.
  • Group memberships and manager links in Microsoft Entra ID match Active Directory for a sample of objects.
  • Password hash sync works for a changed test password, and password writeback works if enabled.
  • No Connect Sync exports for migrated objects other than reference attributes.

Troubleshooting

Group memberships or manager references disappeared. Objects were removed from Connect Sync scope while their references were still in coexistence. Add them back to Connect Sync scope and run a full synchronization (Start-ADSyncSyncCycle -PolicyType Initial) to rebuild references. Remove scope again only after Cloud Sync provisions every referenced object.

The pilot misbehaves and you need to back out. Disable the Cloud Sync configuration in the portal, then disable the custom cloudNoFlow and JoinNoFlow rules in the Synchronization Rules Editor. Disabling the rules triggers a full sync on all connectors, and Connect Sync resumes exporting.

Renamed OU or group isn't recognized. Cloud Sync doesn't detect the rename of an in-scope OU or group, and delta sync doesn't remove the affected users. Update the scoping filter.

Scoping configuration fails as you add OUs. The scope is limited to 4 MB, about 50 separate OUs or security groups. Nested OUs under one selected OU are supported, so restructure scope around parent OUs.

Group scope filter misses members. Delta sync with group scope filtering doesn't support more than 50,000 members.

Guided tool won't start. It must run on the active server, and the readiness review lists blocking features. Use the manual OU method, or wait for support of the blocking feature.

Checklist

  • Scenario and feature comparison reviewed; readiness category chosen.
  • Connect Sync configuration exported.
  • ms-ds-consistencyGUID populated for objects to migrate, groups included.
  • Three Cloud Sync agents planned on Tier 0 servers.
  • Guided tool used if eligible; otherwise cloudNoFlow and JoinNoFlow rules created for users, groups and contacts.
  • Objects kept in Connect Sync scope until their batch is fully migrated.
  • Provision on demand, object counts and references verified per batch.
  • Connect Sync left installed (two weeks for the guided tool) before uninstalling.

References

Questions people ask

What is the difference between Entra Cloud Sync and Entra Connect Sync?

Connect Sync is a full sync engine with its own SQL database and configuration on an on-premises server. Cloud Sync moves configuration and orchestration into Microsoft Entra ID and uses lightweight provisioning agents on-premises, with several agents active at once for high availability. Connect Sync still covers more advanced scenarios, while new features are being built primarily for Cloud Sync.

What are the Cloud Sync limits?

Microsoft's decision guide lists up to 150,000 objects per Active Directory domain and groups of up to 50,000 members for Cloud Sync, compared with no per-domain limit and 250,000-member groups for Connect Sync. Cloud Sync also doesn't support advanced sync rules, cross-forest references, merging attributes from several domains or device writeback.

Can I run Cloud Sync and Connect Sync at the same time?

Yes, in the same forest, but Microsoft doesn't support both tools managing the same objects. During migration each OU or batch is handled by one tool at a time: objects stay in Connect Sync scope, and custom cloudNoFlow and JoinNoFlow rules stop Connect Sync exporting them while Cloud Sync takes over.

Do I have to migrate from Connect Sync to Cloud Sync?

Microsoft notifies eligible organizations of their migration window through in-product messages and email, and exceptions can be requested through support. Microsoft's FAQ also states that you aren't required to migrate until the features your organization depends on are supported in Cloud Sync, so you can keep using Connect Sync in the meantime.

Entra Cloud SyncEntra ConnectActive DirectoryHybrid identity
  1. Fix Entra Connect AttributeValueMustBeUnique and duplicate proxy addresses

    Find which object already holds the duplicated proxyAddresses or userPrincipalName value, remove it from the right side, and confirm the next Entra Connect sync exports cleanly.

  2. Replace an Entra Connect sync server with a staging mode swing migration

    Move Microsoft Entra Connect Sync to a new server without a sync outage: build it in staging mode, import the configuration, verify pending exports, then switch roles.

  3. Upgrade Entra Connect Sync to 2.6 with application-based authentication

    Entra Connect Sync must run 2.6.84.0 or later with application-based authentication by 7 April 2027. Check each server, upgrade safely, switch to the app identity and remove the old sync account.