Microsoft Entra ID
Fundamentals

Provision Entra Id To Active Directory

In brief

The documentation now states that password writeback isn't supported for applications that collect passwords, including applications that authenticate users through an LDAP bind.

What Entra admins need to know

Administrators should review applications that depend on AD DS passwords or LDAP binds when planning authentication for cloud-managed users.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • Provisioning custom security attributes (CSA) to AD.
  • Provisioning Exchange attributes to AD. Because user SOA is in the cloud, Exchange-related information isn't needed in AD. For managing Exchange recipients without an on-premises Exchange Server, see Decommission the last Exchange Server after transferring SOA to cloud and Manage recipients in Exchange hybrid environments using management tools.
  • Mail-enabled groups and distribution groups. Only security groups are supported.
  • Password writeback, which password-based apps, including appsapplications that authentiatecollect a user's password need, isn't supported. This includes applications that authenticate users via LDAP, need.by performing an LDAP bind with the user's password. Cloud-managed users have no AD DS password to present, so the apps must be updated to Kerberos so those users can use passwordless authentication for Kerberos-based applications that support Kerberos instead. For more information, see How cloud-managed users sign in to the application.
  • Complex multi-domain hybrid identity architectures. Provisioning to AD is designed for single-domain identity continuity.

License requirements

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…