Microsoft Entra ID
Provisioning

Plan Cloud Sync Topologies

In brief

The documentation updates diagram descriptions and the provisioning example link. It also clarifies that AD-provisioned group members must have AD accounts, including eligible cloud-managed users and cloud-created security groups; synchronized users still require onPremisesObjectIdentifier.

What Entra admins need to know

Administrators can use the revised guidance to understand which group members Cloud Sync provisions to AD and the attribute requirement for synchronized users.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Multi-forest, single Microsoft Entra tenant

Diagram that shows a multi-forest topology with a single Microsoft Entra tenant.

Multiple AD forests are a common topology, with one or multiple domains, and a single Microsoft Entra tenant.

Piloting Microsoft Entra Cloud Sync in an existing hybrid AD forest

Diagram that shows a single-forest topology with a single Microsoft Entra tenant.

The piloting scenario involves the existence of both Microsoft Entra Connect and Microsoft Entra Cloud Sync in the same forest and scoping the users and groups accordingly. NOTE: An object should be in scope in only one of the tools.

(Public Preview)

Diagram that shows attributes of a single user being merged from two disconnected Active Directory forests.

In this scenario, the attributes of a user are contributed to by two disconnected Active Directory forests.

:::image type="content" source="media/plan-cloud-provisioning-topologies/single-forest-group-writeback.png" alt-text="Conceptual diagram of single forest writeback." lightbox="media/plan-cloud-provisioning-topologies/single-forest-group-writeback.png":::

The simplest group provisioning topology is a single on-premises forest, with one or multiple domains, and a single Microsoft Entra tenant. For an example of this scenarioscenario, see Provision groups to Active DirectoryProvision users and groups from Microsoft Entra ID to Active Directory.

Multi-forest group provisioning to Active Directory

This configuration is advanced and there are a few things to remember with this topology:

  • GroupsGroup membership provisioned to AD using cloud syncincludes only members that have an AD account. Those members can only containbe on-premises synchronized users, cloud-managed users and /that Cloud Sync provisions to AD because they're in scope of user provisioning, or additionalother cloud created security groups.
  • All of theseOn-premises synchronized users must have the onPremisesObjectIdentifier attribute set on their account.
  • The onPremisesObjectIdentifier must match a corresponding objectGUID in the target AD environment.
  • An on-premises users objectGUID attribute to a cloud users onPremisesObjectIdentifier attribute can be synchronized using either Microsoft Entra Cloud Sync (1.1.1370.0) or Microsoft Entra Connect Sync (2.2.8.0)
  • Inside your tenant you may share a common group that contains users from both forests.
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…