To meet the mandatory Microsoft Entra Connect Sync deadline, every sync server, staging servers included, must run version 2.6.84.0 or later and use application-based authentication by 7 April 2027; after that date synchronization fails on any server that doesn't meet both requirements. Download the current build (2.6.92.0 at the time of writing) from the Microsoft Entra admin center, upgrade the staging server first, then run the wizard task Configure application-based authentication to Microsoft Entra ID on each server. Confirm with Get-ADSyncEntraConnectorCredential that ConnectorIdentityType is Application, and only then remove the old Sync_ directory synchronization account.
Who this is for and what you will have at the end
This guide is for administrators who run Microsoft Entra Connect Sync on their own servers and need to meet the 2027 deadline without an outage. It assumes you can sign in to the sync servers as a local administrator and to Microsoft Entra ID as a Hybrid Identity Administrator.
At the end you will have:
- The version, authentication type and scheduler state of every sync server.
- Each server upgraded to a supported 2.6 build by an in-place or swing upgrade.
- Application-based authentication configured, with one application identity per server.
- The legacy directory synchronization account removed, and a plan for certificate rotation.
What changes and when
Application-based authentication replaces the username and password of the Microsoft Entra Connector account with an application identity that uses the OAuth 2.0 client credentials flow with a certificate. Microsoft also deployed a first-party service principal, Microsoft Entra AD Synchronization Service (application ID 6bf85cfa-ac8a-4be5-b5de-425a0d0dc016), which is visible under Enterprise applications and is required for synchronization.
| Date | Event |
|---|---|
| 7 Jul 2026 | 2.6.84.0 released for download |
| 16 Sep 2026 | 2.6.91.0 released for download |
| 23 Sep 2026 | 2.6.92.0 hotfix released for download |
| 23 Oct 2026 | 2.5.79.0 reaches end of support |
| 2 Feb 2027 | 2.5.190.0 reaches end of support |
| 10 Mar 2027 | 2.6.1.0 reaches end of support |
| 7 Apr 2027 | 2.6.84.0 or later with application-based authentication required |
Each 2.x version retires 12 months after a newer version is released, so plan to repeat upgrades rather than treat 2.6.84.0 as a final target.
Changes in 2.6 that affect the upgrade
- No silent switch for existing servers. From 2.6.84.0, Entra Connect no longer moves existing servers from the legacy account to application-based authentication during background sync. You must run the wizard task.
- No fallback. If application-based authentication setup fails, the wizard stops with "Microsoft Entra Connect could not configure application-based authentication for this server. Setup cannot continue." instead of quietly keeping the legacy account.
- Existing database bug in 2.6.84.0. Installing or upgrading to 2.6.84.0 with an existing ADSync database can fail with error
0xE0474352. Use 2.6.91.0 or later for upgrades. - Recalled build. 2.6.79.0 was recalled. If it is installed, uninstall it and install the latest version.
- Phishing-resistant admin sign-in. From 2.6.91.0, the wizard signs administrators in through Windows Web Account Manager with passkeys, FIDO2 security keys or passwords, enabled by default.
- Conditional Access. 2.6.91.0 added Microsoft Graph permissions. If you use app-scoped Conditional Access policies, review policies that target
Microsoft.Azure.SyncFabricor Microsoft 365 Reporting Service. - Password hash sync self-healing removed. PHS no longer re-enables its cloud feature flag automatically. If the flag is disabled, an administrator must re-enable it.
How application-based authentication works
Each server gets its own single-tenant application registration named ConnectSyncProvisioning_<Servername>_<SyncMachineIdentifier>. You choose who manages the application and certificate:
| Option | Who manages the application | Who manages the certificate | Configured with |
|---|---|---|---|
| Managed by Microsoft Entra Connect (default) | Entra Connect | Entra Connect, 90-day certificate in the CURRENT_USER store, rotated automatically | Wizard |
| Bring Your Own Certificate (BYOC) | Entra Connect | You, in the LOCAL_MACHINE store | PowerShell |
| Bring Your Own Application (BYOA) | You | You | PowerShell |
Microsoft recommends the default option. It also recommends a Trusted Platform Module: when a TPM is available, key operations run in hardware; without one, the certificate goes into the Microsoft Software Key Storage Provider with a non-exportable private key. On Hyper-V, TPM can be enabled only on generation 2 VMs. Get-TPM shows the TPM status.
Automatic rotation runs through the sync scheduler. If the scheduler is suspended, the certificate is not rotated even when Entra Connect manages it.
Prerequisites
- An account with at least Hybrid Identity Administrator, assigned directly to the user rather than through a group.
- Local administrator rights on each sync server.
- .NET Framework 4.7.2 and TLS 1.2, which the mandatory upgrade notice calls out. The ADSyncTools module reads the relevant registry values for you.
- A PowerShell execution policy that allows signed scripts; Microsoft recommends
RemoteSignedduring installation. - Optional TPM 2.0.
- A record of any changes made directly to out-of-box sync rules, because an upgrade resets them to default.
Check TLS 1.2 settings with ADSyncTools:
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
Install-Module -Name ADSyncTools
Import-Module ADSyncTools
Get-ADSyncToolsTls12Step 1: Check every sync server
Run these on each server, including staging servers. A staging server that stays on an old version or legacy authentication will fail after the deadline and is no longer a usable fallback.
# Version recorded in the server configuration
(Get-ADSyncGlobalSettings).Parameters |
Where-Object Name -eq 'Microsoft.Synchronize.ServerConfigurationVersion' |
Select-Object Name, Value
# Authentication type: Application or ServiceAccount
Get-ADSyncEntraConnectorCredential
# Scheduler state, including StagingModeEnabled and SchedulerSuspended
Get-ADSyncScheduler
# Automatic upgrade state: Enabled, Suspended or Disabled
Get-ADSyncAutoUpgradeAlso compare the version in Programs and Features with the configuration version; if they differ, a previous upgrade only partly completed. If Get-ADSyncEntraConnectorCredential isn't recognized, check the installed version; any build below 2.6.84.0 needs the upgrade anyway.
Don't rely on automatic upgrade to meet the deadline. Not every release is offered for automatic upgrade, the 2.6 builds above were released for download, and automatic upgrade only applies to eligible configurations, such as express installations on SQL Server Express LocalDB.
Step 2: Choose in-place or swing upgrade
| Method | Use when | Watch out for |
|---|---|---|
| In-place | Single server, fewer than about 100,000 objects, recent version | No rollback if the upgrade fails; full import and sync may run for hours |
| Swing migration | Two or more servers, older versions, an OS upgrade, or custom configuration to test | Needs a separate server; configuration must be moved to it |
Microsoft suggests a swing migration for servers that haven't been upgraded in 12 to 18 months. With two servers, upgrade the staging server, verify it, switch it to active, then upgrade the former active server. Fully uninstall or delete any server you retire; a forgotten server that powers up later can overwrite Microsoft Entra data with stale values.
Before an in-place upgrade on a server whose miiserver.exe.config was edited, for example for password hash sync in FIPS environments, read the known issue in the Troubleshooting section.
Step 3: Upgrade the server
- Download the installer from the Microsoft Entra admin center: Microsoft Entra Connect > Get started > Manage tab.
- Close the Synchronization Service Manager and any open wizard, and wait for the current sync cycle to finish.
- Run the installer and follow the upgrade prompts.
- To control when the required full import and full sync run, clear Start the synchronization process when configuration completes on the last page.
If you deferred synchronization, inspect and optionally remove the overrides that the upgrade recorded, then resume the scheduler:
Get-ADSyncSchedulerConnectorOverride | Format-List
foreach ($connectorOverride in Get-ADSyncSchedulerConnectorOverride)
{
Set-ADSyncSchedulerConnectorOverride -ConnectorIdentifier $connectorOverride.ConnectorIdentifier.Guid -FullSyncRequired $false -FullImportRequired $false
}
Set-ADSyncScheduler -SyncCycleEnabled $trueRun the full import and full sync as soon as convenient, either manually in the Synchronization Service Manager or by adding the overrides back with -FullImportRequired $true -FullSyncRequired $true. While the upgrade runs, the delta scheduler is suspended but password synchronization continues.
If you use Generic LDAP or Generic SQL connectors, refresh their configuration in the Synchronization Service Manager after an in-place upgrade, or their import and export steps fail.
Step 4: Configure application-based authentication
- Start the Microsoft Entra Connect wizard on the server.
- Go to Additional tasks > Configure application-based authentication to Microsoft Entra ID.
- Sign in with your Hybrid Identity Administrator account and follow the prompts.
- Repeat on every other sync server.
Each server must end up with its own application. The wizard identifies the application by the server's name, which keeps servers apart. Problems appear when two servers share a custom connector account or one server was cloned from another, because they end up sharing one application and break each other's certificate. The fix for that case is in the ApplicationManagedBy and AADSTS700027 troubleshooting guide.
BYOC and BYOA
If your security policy requires your own certificate or application, configure them in PowerShell after importing the ADSync module from C:\Program Files\Microsoft Azure AD Sync\Bin\ADSync. Microsoft supports certificates with an RSA 2048-bit key, SHA256, DigitalSignature key usage and a non-exportable private key in the LOCAL_MACHINE store, and the ADSync service account needs read access to the private key. With the scheduler disabled, BYOC uses Invoke-ADSyncApplicationCredentialRotation -CertificateSHA256Hash $certHash, and BYOA uses Add-ADSyncApplicationRegistration -CertificateSHA256Hash $certHash -ApplicationAppId $ConnectSyncAppId after you create the application, its service principal and app role assignment for ADSynchronization.ReadWrite.All. Follow Microsoft's procedure exactly; password writeback needs three additional app roles.
Step 5: Verify
Get-ADSyncEntraConnectorCredential # ConnectorIdentityType should be Application
Get-ADSyncScheduler # SyncCycleEnabled True, SchedulerSuspended False
Start-ADSyncSyncCycle -PolicyType DeltaThen check:
- In the wizard, View or export current configuration shows the application (client) ID and certificate details. Provider name reads
Microsoft Platform Crypto Providerfor a TPM-backed certificate andMicrosoft Software Key Storage Providerotherwise. - In the Microsoft Entra admin center, App registrations lists one
ConnectSyncProvisioning_application per server. - The delta cycle finishes without export errors in the Synchronization Service Manager run history.
- Password hash sync and writeback still work, if you use them.
Step 6: Remove the legacy service account
Once sync works on application-based authentication, Microsoft strongly recommends removing the legacy directory synchronization account. The name is the first part of its UPN, so for Sync_Server_id@contoso.onmicrosoft.com use Sync_Server_id:
$HACredential = Get-Credential
Remove-ADSyncAADServiceAccount -AADCredential $HACredential -Name Sync_Server_idIf you used a custom account that can't be removed, remove its Directory Synchronization Accounts role and reduce its privileges instead. Never use a Global Administrator account as the connector account.
Keep certificates rotating
Entra Connect writes a warning, event ID 1011 in the Application log, once the certificate has used 70 percent of its lifetime, around day 63 of 90, and error event 1012 when it has expired. With the default option, no action is needed as long as the scheduler isn't suspended. Monitor for these events, and for an error saying the old certificate couldn't be removed; in that case delete it with Remove-EntraApplicationKey -CertificateId <certificateId>. To rotate manually at any time, run the wizard task Additional tasks > Rotate application certificate.
Rollback
If application-based authentication causes an urgent problem before the deadline, you can return to a service account:
Set-ADSyncScheduler -SyncCycleEnabled $false
Add-ADSyncAADServiceAccount
Get-ADSyncEntraConnectorCredential # ConnectorIdentityType should be ServiceAccount
Set-ADSyncScheduler -SyncCycleEnabled $trueThe recreated account can take up to 15 minutes to become effective, so an "Access Denied" error right after re-enabling the scheduler is expected. Treat rollback as temporary: legacy authentication stops working after 7 April 2027.
Troubleshooting
Upgrade fails with 0xE0474352. This is the existing-database issue in 2.6.84.0. Use 2.6.91.0 or later.
Sync fails after upgrade with System.IO.FileLoadException: Could not load file or assembly 'System.Diagnostics.DiagnosticSource, Version=6.0.0.1'. Applies to 2.5.190.0 and 2.6.1.0 when miiserver.exe.config was modified, so the upgrade left it unchanged. Back up %programfiles%\Microsoft Azure AD Sync\Bin\miiserver.exe.config, add a dependentAssembly entry for System.Diagnostics.DiagnosticSource with public key token cc7b13ffcd2ddd51 and a binding redirect from 0.0.0.0-8.0.0.0 to 8.0.0.0 inside assemblyBinding, save, and restart the ADSync service.
The wizard reports "ApplicationManagedBy isn't set" or event 906 shows AADSTS700027. The application-based authentication parameters were cleared or two servers share one application. See the dedicated fix guide.
Upgrade stops with "the specified MA could not be found". The Microsoft Entra connector with identifier b891884f-051e-4a83-95af-2544101c9083 doesn't exist, and the configuration isn't supported for upgrade. Uninstall and perform a clean installation of the new version.
Automatic upgrade never happens. Run Get-ADSyncAutoUpgrade -Detail to see the suspension reason, such as UpgradeNotSupportedNonLocalDbInstall, and check the Application log for source Microsoft Entra Connect Upgrade with event IDs 300 to 399. Upgrade manually.
Password hash sync stopped after upgrade. The cloud feature flag no longer re-enables itself after 2.6.84.0. Re-enable it explicitly, for example with Customize synchronization options in the wizard.
Set-ADSyncAADPasswordSyncState or Set-ADSyncAADCompanyFeature behaves differently. In 2.6.84.0 these require an explicit -AADUsername; from 2.6.91.0 the parameter can be omitted and the cmdlet opens an interactive sign-in.
Consider Cloud Sync
Microsoft recommends Microsoft Entra Cloud Sync for organizations whose scenarios it supports, and 2.6.91.0 added a guided migration workflow from Connect Sync to Cloud Sync in the Azure public cloud. Check the supported scenarios comparison before you invest in a new Connect Sync server.
Checklist
- Version, authentication type, scheduler and auto-upgrade state recorded for every server.
- TLS 1.2 and .NET Framework requirements confirmed.
- Changes to default sync rules documented.
- Staging server upgraded and verified first; active server upgraded after the switch.
- Upgrade done with 2.6.91.0 or later, not the recalled 2.6.79.0.
- Application-based authentication configured on every server; one application per server.
ConnectorIdentityTypeisApplicationeverywhere; delta sync succeeds.- Legacy
Sync_account removed or deprivileged. - Events 1011 and 1012 monitored; scheduler never left suspended.
References
- Hardening updates for Microsoft Entra Connect Sync
- Microsoft Entra Connect: Version release history
- Authenticate to Microsoft Entra ID by using application identity
- Microsoft Entra Connect: Upgrade from a previous version
- Microsoft Entra Connect: Prerequisites and hardware
- Microsoft Entra Connect: Automatic upgrade
- Microsoft Entra Connect Sync: Scheduler
- Microsoft Entra Connect: ADSyncTools PowerShell reference
- Microsoft Entra Connect is not working correctly after an automatic upgrade
- Troubleshoot Microsoft Entra Connect Sync application-based authentication