How Provisioning To Active Directory Works
In brief
The documentation now identifies affected accounts as cloud-managed users and explains that password writeback is unavailable for them. It also states that they can access Kerberos-based applications through passwordless authentication using the AD account created by provisioning.
What Entra admins need to know
Use the clarified terminology when reviewing provisioning and authentication guidance; no administrator action is stated.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Password writeback
Password writeback, which synchronizes password changes in Microsoft Entra ID to the matched AD account, isn't available for cloud-managed users. These users created in Microsoft Entra. Users will only be able to authenticate tocan access Kerberos-based applications,applications through passwordless authentication usingwith the AD account that provisioning creates. For more information, see How cloud-managed users sign in to the application.
Sync frequency
@@ -152,7 +152,7 @@ Delete behavior depends on the object type and lifecycle event. AD user accounts ## Password writeback -Password writeback, which synchronizes password changes in Microsoft Entra ID to the matched AD account, isn't available for users created in Microsoft Entra. Users will only be able to authenticate to Kerberos-based applications, through passwordless authentication using the AD account that provisioning creates. For more information, see [How cloud-managed users sign in to the application](tutorial-users-groups-provisioning-walkthrough.md#how-cloud-managed-users-sign-in-to-the-application).+Password writeback, which synchronizes password changes in Microsoft Entra ID to the matched AD account, isn't available for cloud-managed users. These users can access Kerberos-based applications through passwordless authentication with the AD account that provisioning creates. For more information, see [How cloud-managed users sign in to the application](tutorial-users-groups-provisioning-walkthrough.md#how-cloud-managed-users-sign-in-to-the-application). ## Sync frequency 