Microsoft Entra ID
Provisioning

Plan Cloud Sync Topologies

In brief

The page updates diagram descriptions and explains that provisioned group members must have an AD account. Eligible members include synchronized users, cloud-managed users in scope for user provisioning, and cloud-created security groups. The provisioning example link was also updated.

What Entra admins need to know

Use the revised guidance when planning Cloud Sync group provisioning. No administrator action is stated.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Multi-forest, single Microsoft Entra tenant

Diagram that shows a multi-forest topology with a single Microsoft Entra tenant.

Multiple AD forests are a common topology, with one or multiple domains, and a single Microsoft Entra tenant.

Piloting Microsoft Entra Cloud Sync in an existing hybrid AD forest

Diagram that shows a single-forest topology with a single Microsoft Entra tenant.

The piloting scenario involves the existence of both Microsoft Entra Connect and Microsoft Entra Cloud Sync in the same forest and scoping the users and groups accordingly. NOTE: An object should be in scope in only one of the tools.

(Public Preview)

Diagram that shows attributes of a single user being merged from two disconnected Active Directory forests.

In this scenario, the attributes of a user are contributed to by two disconnected Active Directory forests.

:::image type="content" source="media/plan-cloud-provisioning-topologies/single-forest-group-writeback.png" alt-text="Conceptual diagram of single forest writeback." lightbox="media/plan-cloud-provisioning-topologies/single-forest-group-writeback.png":::

The simplest group provisioning topology is a single on-premises forest, with one or multiple domains, and a single Microsoft Entra tenant. For an example of this scenarioscenario, see Provision groups to Active DirectoryProvision users and groups from Microsoft Entra ID to Active Directory.

Multi-forest group provisioning to Active Directory

This configuration is advanced and there are a few things to remember with this topology:

  • GroupsGroup membership provisioned to AD using cloud syncincludes only members that have an AD account. Those members can only containbe on-premises synchronized users, cloud-managed users and /that Cloud Sync provisions to AD because they're in scope of user provisioning, or additionalother cloud created security groups.
  • All of theseOn-premises synchronized users must have the onPremisesObjectIdentifier attribute set on their account.
  • The onPremisesObjectIdentifier must match a corresponding objectGUID in the target AD environment.
  • An on-premises users objectGUID attribute to a cloud users onPremisesObjectIdentifier attribute can be synchronized using either Microsoft Entra Cloud Sync (1.1.1370.0) or Microsoft Entra Connect Sync (2.2.8.0)
  • Inside your tenant you may share a common group that contains users from both forests.
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…