Security & identity

Upgrade Entra Connect Sync to 2.6 with application-based authentication

Entra Connect Sync must run 2.6.84.0 or later with application-based authentication by 7 April 2027. Check each server, upgrade safely, switch to the app identity and remove the old sync account.

12 min read
On this page

To meet the mandatory Microsoft Entra Connect Sync deadline, every sync server, staging servers included, must run version 2.6.84.0 or later and use application-based authentication by 7 April 2027; after that date synchronization fails on any server that doesn't meet both requirements. Download the current build (2.6.92.0 at the time of writing) from the Microsoft Entra admin center, upgrade the staging server first, then run the wizard task Configure application-based authentication to Microsoft Entra ID on each server. Confirm with Get-ADSyncEntraConnectorCredential that ConnectorIdentityType is Application, and only then remove the old Sync_ directory synchronization account.

Who this is for and what you will have at the end

This guide is for administrators who run Microsoft Entra Connect Sync on their own servers and need to meet the 2027 deadline without an outage. It assumes you can sign in to the sync servers as a local administrator and to Microsoft Entra ID as a Hybrid Identity Administrator.

At the end you will have:

  • The version, authentication type and scheduler state of every sync server.
  • Each server upgraded to a supported 2.6 build by an in-place or swing upgrade.
  • Application-based authentication configured, with one application identity per server.
  • The legacy directory synchronization account removed, and a plan for certificate rotation.

What changes and when

Application-based authentication replaces the username and password of the Microsoft Entra Connector account with an application identity that uses the OAuth 2.0 client credentials flow with a certificate. Microsoft also deployed a first-party service principal, Microsoft Entra AD Synchronization Service (application ID 6bf85cfa-ac8a-4be5-b5de-425a0d0dc016), which is visible under Enterprise applications and is required for synchronization.

DateEvent
7 Jul 20262.6.84.0 released for download
16 Sep 20262.6.91.0 released for download
23 Sep 20262.6.92.0 hotfix released for download
23 Oct 20262.5.79.0 reaches end of support
2 Feb 20272.5.190.0 reaches end of support
10 Mar 20272.6.1.0 reaches end of support
7 Apr 20272.6.84.0 or later with application-based authentication required

Each 2.x version retires 12 months after a newer version is released, so plan to repeat upgrades rather than treat 2.6.84.0 as a final target.

Changes in 2.6 that affect the upgrade

  • No silent switch for existing servers. From 2.6.84.0, Entra Connect no longer moves existing servers from the legacy account to application-based authentication during background sync. You must run the wizard task.
  • No fallback. If application-based authentication setup fails, the wizard stops with "Microsoft Entra Connect could not configure application-based authentication for this server. Setup cannot continue." instead of quietly keeping the legacy account.
  • Existing database bug in 2.6.84.0. Installing or upgrading to 2.6.84.0 with an existing ADSync database can fail with error 0xE0474352. Use 2.6.91.0 or later for upgrades.
  • Recalled build. 2.6.79.0 was recalled. If it is installed, uninstall it and install the latest version.
  • Phishing-resistant admin sign-in. From 2.6.91.0, the wizard signs administrators in through Windows Web Account Manager with passkeys, FIDO2 security keys or passwords, enabled by default.
  • Conditional Access. 2.6.91.0 added Microsoft Graph permissions. If you use app-scoped Conditional Access policies, review policies that target Microsoft.Azure.SyncFabric or Microsoft 365 Reporting Service.
  • Password hash sync self-healing removed. PHS no longer re-enables its cloud feature flag automatically. If the flag is disabled, an administrator must re-enable it.

How application-based authentication works

Each server gets its own single-tenant application registration named ConnectSyncProvisioning_<Servername>_<SyncMachineIdentifier>. You choose who manages the application and certificate:

OptionWho manages the applicationWho manages the certificateConfigured with
Managed by Microsoft Entra Connect (default)Entra ConnectEntra Connect, 90-day certificate in the CURRENT_USER store, rotated automaticallyWizard
Bring Your Own Certificate (BYOC)Entra ConnectYou, in the LOCAL_MACHINE storePowerShell
Bring Your Own Application (BYOA)YouYouPowerShell

Microsoft recommends the default option. It also recommends a Trusted Platform Module: when a TPM is available, key operations run in hardware; without one, the certificate goes into the Microsoft Software Key Storage Provider with a non-exportable private key. On Hyper-V, TPM can be enabled only on generation 2 VMs. Get-TPM shows the TPM status.

Automatic rotation runs through the sync scheduler. If the scheduler is suspended, the certificate is not rotated even when Entra Connect manages it.

Prerequisites

  • An account with at least Hybrid Identity Administrator, assigned directly to the user rather than through a group.
  • Local administrator rights on each sync server.
  • .NET Framework 4.7.2 and TLS 1.2, which the mandatory upgrade notice calls out. The ADSyncTools module reads the relevant registry values for you.
  • A PowerShell execution policy that allows signed scripts; Microsoft recommends RemoteSigned during installation.
  • Optional TPM 2.0.
  • A record of any changes made directly to out-of-box sync rules, because an upgrade resets them to default.

Check TLS 1.2 settings with ADSyncTools:

[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
Install-Module -Name ADSyncTools
Import-Module ADSyncTools
Get-ADSyncToolsTls12

Step 1: Check every sync server

Run these on each server, including staging servers. A staging server that stays on an old version or legacy authentication will fail after the deadline and is no longer a usable fallback.

# Version recorded in the server configuration
(Get-ADSyncGlobalSettings).Parameters |
    Where-Object Name -eq 'Microsoft.Synchronize.ServerConfigurationVersion' |
    Select-Object Name, Value
 
# Authentication type: Application or ServiceAccount
Get-ADSyncEntraConnectorCredential
 
# Scheduler state, including StagingModeEnabled and SchedulerSuspended
Get-ADSyncScheduler
 
# Automatic upgrade state: Enabled, Suspended or Disabled
Get-ADSyncAutoUpgrade

Also compare the version in Programs and Features with the configuration version; if they differ, a previous upgrade only partly completed. If Get-ADSyncEntraConnectorCredential isn't recognized, check the installed version; any build below 2.6.84.0 needs the upgrade anyway.

Don't rely on automatic upgrade to meet the deadline. Not every release is offered for automatic upgrade, the 2.6 builds above were released for download, and automatic upgrade only applies to eligible configurations, such as express installations on SQL Server Express LocalDB.

Step 2: Choose in-place or swing upgrade

MethodUse whenWatch out for
In-placeSingle server, fewer than about 100,000 objects, recent versionNo rollback if the upgrade fails; full import and sync may run for hours
Swing migrationTwo or more servers, older versions, an OS upgrade, or custom configuration to testNeeds a separate server; configuration must be moved to it

Microsoft suggests a swing migration for servers that haven't been upgraded in 12 to 18 months. With two servers, upgrade the staging server, verify it, switch it to active, then upgrade the former active server. Fully uninstall or delete any server you retire; a forgotten server that powers up later can overwrite Microsoft Entra data with stale values.

Before an in-place upgrade on a server whose miiserver.exe.config was edited, for example for password hash sync in FIPS environments, read the known issue in the Troubleshooting section.

Step 3: Upgrade the server

  1. Download the installer from the Microsoft Entra admin center: Microsoft Entra Connect > Get started > Manage tab.
  2. Close the Synchronization Service Manager and any open wizard, and wait for the current sync cycle to finish.
  3. Run the installer and follow the upgrade prompts.
  4. To control when the required full import and full sync run, clear Start the synchronization process when configuration completes on the last page.

If you deferred synchronization, inspect and optionally remove the overrides that the upgrade recorded, then resume the scheduler:

Get-ADSyncSchedulerConnectorOverride | Format-List
 
foreach ($connectorOverride in Get-ADSyncSchedulerConnectorOverride)
{
    Set-ADSyncSchedulerConnectorOverride -ConnectorIdentifier $connectorOverride.ConnectorIdentifier.Guid -FullSyncRequired $false -FullImportRequired $false
}
 
Set-ADSyncScheduler -SyncCycleEnabled $true

Run the full import and full sync as soon as convenient, either manually in the Synchronization Service Manager or by adding the overrides back with -FullImportRequired $true -FullSyncRequired $true. While the upgrade runs, the delta scheduler is suspended but password synchronization continues.

If you use Generic LDAP or Generic SQL connectors, refresh their configuration in the Synchronization Service Manager after an in-place upgrade, or their import and export steps fail.

Step 4: Configure application-based authentication

  1. Start the Microsoft Entra Connect wizard on the server.
  2. Go to Additional tasks > Configure application-based authentication to Microsoft Entra ID.
  3. Sign in with your Hybrid Identity Administrator account and follow the prompts.
  4. Repeat on every other sync server.

Each server must end up with its own application. The wizard identifies the application by the server's name, which keeps servers apart. Problems appear when two servers share a custom connector account or one server was cloned from another, because they end up sharing one application and break each other's certificate. The fix for that case is in the ApplicationManagedBy and AADSTS700027 troubleshooting guide.

BYOC and BYOA

If your security policy requires your own certificate or application, configure them in PowerShell after importing the ADSync module from C:\Program Files\Microsoft Azure AD Sync\Bin\ADSync. Microsoft supports certificates with an RSA 2048-bit key, SHA256, DigitalSignature key usage and a non-exportable private key in the LOCAL_MACHINE store, and the ADSync service account needs read access to the private key. With the scheduler disabled, BYOC uses Invoke-ADSyncApplicationCredentialRotation -CertificateSHA256Hash $certHash, and BYOA uses Add-ADSyncApplicationRegistration -CertificateSHA256Hash $certHash -ApplicationAppId $ConnectSyncAppId after you create the application, its service principal and app role assignment for ADSynchronization.ReadWrite.All. Follow Microsoft's procedure exactly; password writeback needs three additional app roles.

Step 5: Verify

Get-ADSyncEntraConnectorCredential   # ConnectorIdentityType should be Application
Get-ADSyncScheduler                  # SyncCycleEnabled True, SchedulerSuspended False
Start-ADSyncSyncCycle -PolicyType Delta

Then check:

  • In the wizard, View or export current configuration shows the application (client) ID and certificate details. Provider name reads Microsoft Platform Crypto Provider for a TPM-backed certificate and Microsoft Software Key Storage Provider otherwise.
  • In the Microsoft Entra admin center, App registrations lists one ConnectSyncProvisioning_ application per server.
  • The delta cycle finishes without export errors in the Synchronization Service Manager run history.
  • Password hash sync and writeback still work, if you use them.

Step 6: Remove the legacy service account

Once sync works on application-based authentication, Microsoft strongly recommends removing the legacy directory synchronization account. The name is the first part of its UPN, so for Sync_Server_id@contoso.onmicrosoft.com use Sync_Server_id:

$HACredential = Get-Credential
Remove-ADSyncAADServiceAccount -AADCredential $HACredential -Name Sync_Server_id

If you used a custom account that can't be removed, remove its Directory Synchronization Accounts role and reduce its privileges instead. Never use a Global Administrator account as the connector account.

Keep certificates rotating

Entra Connect writes a warning, event ID 1011 in the Application log, once the certificate has used 70 percent of its lifetime, around day 63 of 90, and error event 1012 when it has expired. With the default option, no action is needed as long as the scheduler isn't suspended. Monitor for these events, and for an error saying the old certificate couldn't be removed; in that case delete it with Remove-EntraApplicationKey -CertificateId <certificateId>. To rotate manually at any time, run the wizard task Additional tasks > Rotate application certificate.

Rollback

If application-based authentication causes an urgent problem before the deadline, you can return to a service account:

Set-ADSyncScheduler -SyncCycleEnabled $false
Add-ADSyncAADServiceAccount
Get-ADSyncEntraConnectorCredential   # ConnectorIdentityType should be ServiceAccount
Set-ADSyncScheduler -SyncCycleEnabled $true

The recreated account can take up to 15 minutes to become effective, so an "Access Denied" error right after re-enabling the scheduler is expected. Treat rollback as temporary: legacy authentication stops working after 7 April 2027.

Troubleshooting

Upgrade fails with 0xE0474352. This is the existing-database issue in 2.6.84.0. Use 2.6.91.0 or later.

Sync fails after upgrade with System.IO.FileLoadException: Could not load file or assembly 'System.Diagnostics.DiagnosticSource, Version=6.0.0.1'. Applies to 2.5.190.0 and 2.6.1.0 when miiserver.exe.config was modified, so the upgrade left it unchanged. Back up %programfiles%\Microsoft Azure AD Sync\Bin\miiserver.exe.config, add a dependentAssembly entry for System.Diagnostics.DiagnosticSource with public key token cc7b13ffcd2ddd51 and a binding redirect from 0.0.0.0-8.0.0.0 to 8.0.0.0 inside assemblyBinding, save, and restart the ADSync service.

The wizard reports "ApplicationManagedBy isn't set" or event 906 shows AADSTS700027. The application-based authentication parameters were cleared or two servers share one application. See the dedicated fix guide.

Upgrade stops with "the specified MA could not be found". The Microsoft Entra connector with identifier b891884f-051e-4a83-95af-2544101c9083 doesn't exist, and the configuration isn't supported for upgrade. Uninstall and perform a clean installation of the new version.

Automatic upgrade never happens. Run Get-ADSyncAutoUpgrade -Detail to see the suspension reason, such as UpgradeNotSupportedNonLocalDbInstall, and check the Application log for source Microsoft Entra Connect Upgrade with event IDs 300 to 399. Upgrade manually.

Password hash sync stopped after upgrade. The cloud feature flag no longer re-enables itself after 2.6.84.0. Re-enable it explicitly, for example with Customize synchronization options in the wizard.

Set-ADSyncAADPasswordSyncState or Set-ADSyncAADCompanyFeature behaves differently. In 2.6.84.0 these require an explicit -AADUsername; from 2.6.91.0 the parameter can be omitted and the cmdlet opens an interactive sign-in.

Consider Cloud Sync

Microsoft recommends Microsoft Entra Cloud Sync for organizations whose scenarios it supports, and 2.6.91.0 added a guided migration workflow from Connect Sync to Cloud Sync in the Azure public cloud. Check the supported scenarios comparison before you invest in a new Connect Sync server.

Checklist

  • Version, authentication type, scheduler and auto-upgrade state recorded for every server.
  • TLS 1.2 and .NET Framework requirements confirmed.
  • Changes to default sync rules documented.
  • Staging server upgraded and verified first; active server upgraded after the switch.
  • Upgrade done with 2.6.91.0 or later, not the recalled 2.6.79.0.
  • Application-based authentication configured on every server; one application per server.
  • ConnectorIdentityType is Application everywhere; delta sync succeeds.
  • Legacy Sync_ account removed or deprivileged.
  • Events 1011 and 1012 monitored; scheduler never left suspended.

References

Questions people ask

What is the Entra Connect Sync deadline in 2027?

Microsoft requires Microsoft Entra Connect Sync version 2.6.84.0 or later with application-based authentication configured by 7 April 2027. Legacy authentication is being retired, and Microsoft states that all synchronization services fail after that date on servers that don't meet both requirements, until they are upgraded.

Does upgrading to 2.6 switch my server to application-based authentication?

Not on existing servers. From version 2.6.84.0, Entra Connect no longer switches servers from the legacy directory synchronization account during background sync. New installations are configured for application-based authentication during setup, and existing servers must run the wizard task Configure application-based authentication to Microsoft Entra ID.

How do I check whether Entra Connect uses application-based authentication?

Run Get-ADSyncEntraConnectorCredential on the sync server. The ConnectorIdentityType value is Application when the server uses the app identity and ServiceAccount when it still uses the legacy account. The wizard task View or export current configuration also shows the application client ID and certificate details.

Where do I download Entra Connect Sync 2.6?

Only from the Microsoft Entra admin center, on the Manage tab of the Microsoft Entra Connect Get started page. New versions are no longer published to the Microsoft Download Center.

Entra ConnectHybrid identityPowerShellADSyncTools
  1. Fix ApplicationManagedBy isn't set and AADSTS700027 in Entra Connect Sync

    Repair broken application-based authentication on Entra Connect Sync servers: restore cleared connector parameters, separate servers that share one app, and recover from expired certificates.

  2. Entra Cloud Sync vs Connect Sync - choose an engine and migrate safely

    Compare Microsoft Entra Cloud Sync and Entra Connect Sync feature by feature, check migration readiness, and move with the guided tool or a phased OU pilot.

  3. Fix Entra Connect AttributeValueMustBeUnique and duplicate proxy addresses

    Find which object already holds the duplicated proxyAddresses or userPrincipalName value, remove it from the right side, and confirm the next Entra Connect sync exports cleanly.