Hardening update to Microsoft Entra Connect Sync
In brief
The documentation updates the name or identifier of the dedicated first-party service principal used to synchronize Active Directory with Microsoft Entra ID.
What Entra admins need to know
Administrators can use the corrected reference when identifying this service principal in their tenant.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Hardening update to Microsoft Entra Connect Sync
As part of increasing the security posture of Microsoft Entra Connect, Microsoft deployed a dedicated first-party application to enable the synchronization between Active Directory and Microsoft Entra ID. This new application will manifest as a first party service principal called the "Microsoft Entra AD Synchronization Service" (Application Id: ) and will be visible in the Enterprise Applications experience within the Microsoft Entra admin center. This application is critical for the continued operation of on-premises to Microsoft Entra ID synchronization functionality through Entra Connect.00001111-aaaa-2222-bbbb-3333cccc44446bf85cfa-ac8a-4be5-b5de-425a0d0dc016
We have since released a new version (2.5.79.0) of Microsoft Entra Connect that contains this service change. All customers are required to upgrade to the minimum versions by September 30, 2026 to avoid service disruptions.
@@ -10,7 +10,7 @@ ms.subservice: hybrid-connect --- # Hardening update to Microsoft Entra Connect Sync -As part of increasing the security posture of Microsoft Entra Connect, Microsoft deployed a dedicated first-party application to enable the synchronization between Active Directory and Microsoft Entra ID. This new application will manifest as a first party service principal called the "Microsoft Entra AD Synchronization Service" (Application Id: `00001111-aaaa-2222-bbbb-3333cccc4444`) and will be visible in the Enterprise Applications experience within the Microsoft Entra admin center. This application is critical for the continued operation of on-premises to Microsoft Entra ID synchronization functionality through Entra Connect.+As part of increasing the security posture of Microsoft Entra Connect, Microsoft deployed a dedicated first-party application to enable the synchronization between Active Directory and Microsoft Entra ID. This new application will manifest as a first party service principal called the "Microsoft Entra AD Synchronization Service" (Application Id: `6bf85cfa-ac8a-4be5-b5de-425a0d0dc016`) and will be visible in the Enterprise Applications experience within the Microsoft Entra admin center. This application is critical for the continued operation of on-premises to Microsoft Entra ID synchronization functionality through Entra Connect. We have since released a new version (2.5.79.0) of Microsoft Entra Connect that contains this service change. All customers are required to upgrade to the minimum versions by September 30, 2026 to avoid service disruptions. 