On-demand provisioning - Microsoft Entra ID to Active Directory
In brief
The article now documents selecting a group and up to five members for testing. User-specific instructions and result-review details were removed, and provisioning-direction references were updated.
What Entra admins need to know
When testing a group, select its members manually, up to the five-member limit. Use the linked guidance for provisioning from Microsoft Entra ID to Active Directory.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
On-demand provisioning - Microsoft Entra ID to Active Directory
Microsoft Entra Cloud Sync letsConnect cloud sync allows you to test configuration changeschanges, by applying themthese changes to a single user or group before you enable the configuration for all in-scope objects.group.
UseYou can use this test to validate and verify that the changes you made to the configuration were applied properly and that objects are being correctly synchronized to Active Directory.Microsoft Entra ID.
This article coversThe following document guides you through on-demand provisioning for configurations that provision fromwith Microsoft Entra ID to Active Directory. If you're lookingCloud Sync for information about provisioning from Active Directory to Microsoft Entra ID,ID. If you're looking for information on provisioning from Microsoft Entra ID to AD, see On-demand provisioning - Active Directory to Microsoft Entra ID. On-demand provisioning - Active Directory to Microsoft Entra ID
The following is true for on-demand group provisioning:
- On-demand provisioning of groups supports updating up to five members at a time.
- The on-demand provisioning request API can only accept a single group with up to five members at a time.
Verify a user or group
[!INCLUDE sign in [!INCLUDE sign inTo use on-demand provisioning, follow these steps:
Under Configuration, select your configuration.
On the left, select Provision on demand.
SelectEnter the name of the group in theUsersSelected grouporbox- From the
GroupsSelected userstab, depending on which object type you wantsection, select some users to test.
:: :::image type="content" source="media/how-to-on-demand-provision-configure-entra-to-active-directory/provision-on-demand-users-tab.entra-to-ad-10.png" alt-text="Screenshot of the Provision on demand page with the Users and Groups tabs.adding members." lightbox="media/how-to-on-demand-provision-configure-entra-to-active-directory/provision-on-demand-users-tab.entra-to-ad-10.png":::
- Select Provision.
- You should see the group provisioned.
Then follow the steps for the object type you selected.
Users
InSelect a user, search for the user by name, and then select the user.:::::image type="content" source="media/how-to-on-demand-provision-configure-entra-to-active-directory/provision-on-demand-select-user.entra-to-ad-11.png" alt-text="Screenshot ofa user selectedsuccessful provisioning onthe Users tab of the Provision on demand page.demand." lightbox="media/how-to-on-demand-provision-configure-entra-to-active-directory/provision-on-demand-select-user.entra-to-ad-11.png":::SelectProvisionFor more information, see on-demand provisioning.
Groups
InSelected group, search for the group by name, and then select the group.UnderSelected users, selectView members onlyto choose from the group's current members, orView all usersto search the whole directory. Then select the members you want to test.
:::image type="content" source="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-select-group.png" alt-text="Screenshot of a group selected on the Groups tab, with the options for choosing which members to test." lightbox="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-select-group.png":::
- Select Provision.
Review the result
The result lists four steps: importing the object, evaluating it against your scoping filters, matching it against the target system, and performing the action in Active Directory. Select View details on any step to see what was evaluated.
A step reports Success when it completes, or Skipped when there was nothing to do, such as when the object in Active Directory already matches. To run the same test again, select Retry. To test a different object, select Provision another object.
Users
:::image type="content" source="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-user-result.png" alt-text="Screenshot of the on-demand provisioning result for a user, showing the four
Next steps and their status." lightbox="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-user-result.png":::Groups
:::image type="content" source="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-group-result.png" alt-text="Screenshot of the on-demand provisioning result for a group, showing the four steps and their status." lightbox="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-group-result.png":::
Related content
Configure Microsoft Entra ID to Active Directory provisioningTest and enable provisioning to Active Directory- Group writeback with Microsoft Entra Cloud Sync
- Govern on-premises Active Directory based apps (Kerberos) using Microsoft Entra ID Governance
- Migrate Microsoft Entra Connect Sync group writeback V2 to Microsoft Entra Cloud Sync
@@ -2,21 +2,19 @@ title: 'On-demand provisioning - Microsoft Entra ID to Active Directory' description: This article describes how to use on-demand provisioning when provisioning from Microsoft Entra ID to Active Directory. ms.topic: how-to-ms.date: 08/24/2026+ms.date: 04/09/2025 ms.subservice: hybrid-cloud-sync-ms.custom: sfi-image-nochange, msecd-doc-authoring-1023-ai-usage: ai-assisted+ms.custom: sfi-image-nochange --- # On-demand provisioning - Microsoft Entra ID to Active Directory+Microsoft Entra Connect cloud sync allows you to test configuration changes, by applying these changes to a group. -Microsoft Entra Cloud Sync lets you test configuration changes by applying them to a single user or group before you enable the configuration for all in-scope objects.+You can use this test to validate and verify that the changes made to the configuration were applied properly and are being correctly synchronized to Microsoft Entra ID. -Use this test to validate and verify that the changes you made to the configuration were applied properly and that objects are correctly synchronized to Active Directory.--This article covers on-demand provisioning for configurations that provision from Microsoft Entra ID to Active Directory. If you're looking for information about provisioning from Active Directory to Microsoft Entra ID, see [On-demand provisioning - Active Directory to Microsoft Entra ID](how-to-on-demand-provision.md).+The following document guides you through on-demand provisioning with Microsoft Entra Cloud Sync for provisioning from Active Directory to Microsoft Entra ID. If you're looking for information on provisioning from Microsoft Entra ID to AD, see [ On-demand provisioning - Active Directory to Microsoft Entra ID](how-to-on-demand-provision-entra-to-active-directory.md) The following is true for on-demand group provisioning: - On-demand provisioning of groups supports updating up to five members at a time.@@ -25,62 +23,30 @@ The following is true for on-demand group provisioning: - The on-demand provisioning request API can only accept a single group with up to five members at a time. -<a name='verify-a-group'></a>+## Verify a group+To use on-demand provisioning, follow these steps: -## Verify a user or group+>[!NOTE]+>When using on-demand provisioning, members aren't automatically provisioned. You need to select which members you wish to test on and there's a five member limit. [!INCLUDE [sign in](../../../includes/cloud-sync-sign-in.md)] 3. Under **Configuration**, select your configuration. 4. On the left, select **Provision on demand**.- 5. Select the **Users** or **Groups** tab, depending on which object type you want to test.-- :::image type="content" source="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-users-tab.png" alt-text="Screenshot of the Provision on demand page with the Users and Groups tabs." lightbox="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-users-tab.png":::--Then follow the steps for the object type you selected.--# [Users](#tab/users)--1. In **Select a user**, search for the user by name, and then select the user.-- :::image type="content" source="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-select-user.png" alt-text="Screenshot of a user selected on the Users tab of the Provision on demand page." lightbox="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-select-user.png":::--1. Select **Provision**.--# [Groups](#tab/groups)--1. In **Selected group**, search for the group by name, and then select the group.-1. Under **Selected users**, select **View members only** to choose from the group's current members, or **View all users** to search the whole directory. Then select the members you want to test.-- > [!NOTE]- > Members aren't provisioned automatically. Select the members you want to test, up to five at a time.-- :::image type="content" source="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-select-group.png" alt-text="Screenshot of a group selected on the Groups tab, with the options for choosing which members to test." lightbox="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-select-group.png":::+ 5. Enter the name of the group in the **Selected group** box+ 6. From the **Selected users** section, select some users to test.+ + :::image type="content" source="media/how-to-configure-entra-to-active-directory/entra-to-ad-10.png" alt-text="Screenshot of adding members." lightbox="media/how-to-configure-entra-to-active-directory/entra-to-ad-10.png"::: -1. Select **Provision**.+ 7. Select **Provision**.+ 8. You should see the group provisioned.+ + :::image type="content" source="media/how-to-configure-entra-to-active-directory/entra-to-ad-11.png" alt-text="Screenshot of successful provisioning on demand." lightbox="media/how-to-configure-entra-to-active-directory/entra-to-ad-11.png"::: ------## Review the result--The result lists four steps: importing the object, evaluating it against your scoping filters, matching it against the target system, and performing the action in Active Directory. Select **View details** on any step to see what was evaluated.--A step reports **Success** when it completes, or **Skipped** when there was nothing to do, such as when the object in Active Directory already matches. To run the same test again, select **Retry**. To test a different object, select **Provision another object**.--# [Users](#tab/users)--:::image type="content" source="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-user-result.png" alt-text="Screenshot of the on-demand provisioning result for a user, showing the four steps and their status." lightbox="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-user-result.png":::--# [Groups](#tab/groups)--:::image type="content" source="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-group-result.png" alt-text="Screenshot of the on-demand provisioning result for a group, showing the four steps and their status." lightbox="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-group-result.png":::----- -## Related content+For more information, see [on-demand provisioning](how-to-on-demand-provision.md). -- [Configure Microsoft Entra ID to Active Directory provisioning](how-to-configure-entra-to-active-directory.md)-- [Test and enable provisioning to Active Directory](how-to-test-and-enable-provisioning-entra-to-active-directory.md)-- [Group writeback with Microsoft Entra Cloud Sync](../group-writeback-cloud-sync.md)+## Next steps +- [Group writeback with Microsoft Entra Cloud Sync ](../group-writeback-cloud-sync.md) - [Govern on-premises Active Directory based apps (Kerberos) using Microsoft Entra ID Governance](govern-on-premises-groups.md) - [Migrate Microsoft Entra Connect Sync group writeback V2 to Microsoft Entra Cloud Sync](migrate-group-writeback.md) 