Microsoft Entra ID
Provisioning

On-demand provisioning - Microsoft Entra ID to Active Directory

In brief

The article now documents selecting a group and up to five members for testing. User-specific instructions and result-review details were removed, and provisioning-direction references were updated.

What Entra admins need to know

When testing a group, select its members manually, up to the five-member limit. Use the linked guidance for provisioning from Microsoft Entra ID to Active Directory.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

On-demand provisioning - Microsoft Entra ID to Active Directory

Microsoft Entra Cloud Sync letsConnect cloud sync allows you to test configuration changeschanges, by applying themthese changes to a single user or group before you enable the configuration for all in-scope objects.group.

UseYou can use this test to validate and verify that the changes you made to the configuration were applied properly and that objects are being correctly synchronized to Active Directory.Microsoft Entra ID.

This article coversThe following document guides you through on-demand provisioning for configurations that provision fromwith Microsoft Entra ID to Active Directory. If you're lookingCloud Sync for information about provisioning from Active Directory to Microsoft Entra ID,ID. If you're looking for information on provisioning from Microsoft Entra ID to AD, see On-demand provisioning - Active Directory to Microsoft Entra ID. On-demand provisioning - Active Directory to Microsoft Entra ID

The following is true for on-demand group provisioning:

  • On-demand provisioning of groups supports updating up to five members at a time.
  • The on-demand provisioning request API can only accept a single group with up to five members at a time.

Verify a user or group

[!INCLUDE sign inTo use on-demand provisioning, follow these steps:

[!INCLUDE sign in]

  1. Under Configuration, select your configuration.

  2. On the left, select Provision on demand.

  3. SelectEnter the name of the group in the UsersSelected group orbox

  4. From the GroupsSelected users tab, depending on which object type you wantsection, select some users to test.

:: :::image type="content" source="media/how-to-on-demand-provision-configure-entra-to-active-directory/provision-on-demand-users-tab.entra-to-ad-10.png" alt-text="Screenshot of the Provision on demand page with the Users and Groups tabs.adding members." lightbox="media/how-to-on-demand-provision-configure-entra-to-active-directory/provision-on-demand-users-tab.entra-to-ad-10.png":::

  1. Select Provision.
  2. You should see the group provisioned.

Then follow the steps for the object type you selected.

Users

  1. In Select a user, search for the user by name, and then select the user.

    :: :::image type="content" source="media/how-to-on-demand-provision-configure-entra-to-active-directory/provision-on-demand-select-user.entra-to-ad-11.png" alt-text="Screenshot of a user selectedsuccessful provisioning on the Users tab of the Provision on demand page.demand." lightbox="media/how-to-on-demand-provision-configure-entra-to-active-directory/provision-on-demand-select-user.entra-to-ad-11.png":::

  2. Select ProvisionFor more information, see on-demand provisioning.

Groups

  1. In Selected group, search for the group by name, and then select the group.
  2. Under Selected users, select View members only to choose from the group's current members, or View all users to search the whole directory. Then select the members you want to test.

:::image type="content" source="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-select-group.png" alt-text="Screenshot of a group selected on the Groups tab, with the options for choosing which members to test." lightbox="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-select-group.png":::

  1. Select Provision.

Review the result

The result lists four steps: importing the object, evaluating it against your scoping filters, matching it against the target system, and performing the action in Active Directory. Select View details on any step to see what was evaluated.

A step reports Success when it completes, or Skipped when there was nothing to do, such as when the object in Active Directory already matches. To run the same test again, select Retry. To test a different object, select Provision another object.

Users

:::image type="content" source="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-user-result.png" alt-text="Screenshot of the on-demand provisioning result for a user, showing the four

Next steps and their status." lightbox="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-user-result.png":::

Groups

:::image type="content" source="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-group-result.png" alt-text="Screenshot of the on-demand provisioning result for a group, showing the four steps and their status." lightbox="media/how-to-on-demand-provision-entra-to-active-directory/provision-on-demand-group-result.png":::


Related content

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…