Microsoft Entra ID
Provisioning

On-demand provisioning - Microsoft Entra ID to Active Directory

In brief

The guidance now describes testing Entra ID-to-Active Directory changes on a single user or group before enabling them broadly. It adds separate workflows, retains the five-member group limit, and explains result statuses, retries, and testing another object.

What Entra admins need to know

Administrators can validate configurations on targeted objects and inspect each provisioning step; no required action is stated.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

On-demand provisioning - Microsoft Entra ID to Active Directory

Microsoft Entra Connect cloud sync allowsCloud Sync lets you to test configuration changes,changes by applying these changesthem to a group. single user or group before you enable the configuration for all in-scope objects.

You can useUse this test to validate and verify that the changes you made to the configuration were applied properly and that objects are being correctly synchronized to Microsoft Entra ID. Active Directory.

The following document guides you throughThis article covers on-demand provisioning withfor configurations that provision from Microsoft Entra Cloud SyncID to Active Directory. If you're looking for information about provisioning from Active Directory to Microsoft Entra ID. If you're looking for information on provisioning from Microsoft Entra ID to AD,ID, see On-demand provisioning - Active Directory to Microsoft Entra IDOn-demand provisioning - Active Directory to Microsoft Entra ID.

The following is true for on-demand group provisioning:

  • On-demand provisioning of groups supports updating up to five members at a time.
  • The on-demand provisioning request API can only accept a single group with up to five members at a time.

Verify a user or group

To use on-demand provisioning, follow these steps:

[!INCLUDE sign in [!INCLUDE sign in]

  1. Under Configuration, select your configuration.

  2. On the left, select Provision on demand.

  3. Enter

    Select the name of the group in the Selected groupUsers box

  4. From theor Selected usersGroups section, select some userstab, depending on which object type you want to test.

:::::image type="content" source="media/how-to-configure-on-demand-provision-entra-to-active-directory/entra-to-ad-10.provision-on-demand-users-tab.png" alt-text="Screenshot of adding members.the Provision on demand page with the Users and Groups tabs." lightbox="media/how-to-configure-on-demand-provision-entra-to-active-directory/entra-to-ad-10.provision-on-demand-users-tab.png":::

  1. Select Provision.
  2. You should see the group provisioned.

::Then follow the steps for the object type you selected.

Users

  1. In Select a user, search for the user by name, and then select the user.

    :::image type="content" source="media/how-to-configure-on-demand-provision-entra-to-active-directory/entra-to-ad-11.provision-on-demand-select-user.png" alt-text="Screenshot of successful provisioninga user selected on demand.the Users tab of the Provision on demand page." lightbox="media/how-to-configure-on-demand-provision-entra-to-active-directory/entra-to-ad-11.provision-on-demand-select-user.png":::

  2. For more information, see on-demand provisioningSelect Provision.

Groups

  1. In Selected group, search for the group by name, and then select the group.
  2. Under Selected users, select View members only to choose from the group's current members, or View all users to search the whole directory. Then select the members you want to test.

:::image type="content" source="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-select-group.png" alt-text="Screenshot of a group selected on the Groups tab, with the options for choosing which members to test." lightbox="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-select-group.png":::

  1. Select Provision.

Review the result

The result lists four steps: importing the object, evaluating it against your scoping filters, matching it against the target system, and performing the action in Active Directory. Select View details on any step to see what was evaluated.

A step reports Success when it completes, or Skipped when there was nothing to do, such as when the object in Active Directory already matches. To run the same test again, select Retry. To test a different object, select Provision another object.

Users

:::image type="content" source="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-user-result.png" alt-text="Screenshot of the on-demand provisioning result for a user, showing the four steps and their status." lightbox="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-user-result.png":::

Groups

:::image type="content" source="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-group-result.png" alt-text="Screenshot of the on-demand provisioning result for a group, showing the four steps and their status." lightbox="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-group-result.png":::


Next stepsRelated content

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…