Microsoft Entra ID
Fundamentals

Provision Entra Id To Active Directory

In brief

The guidance now specifies that password-based apps, including LDAP-authenticated apps, must be updated to Kerberos for cloud-managed users to use passwordless authentication.

What Entra admins need to know

Review affected apps and plan updates to Kerberos where passwordless authentication is required.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • Provisioning custom security attributes (CSA) to AD.
  • Provisioning Exchange attributes to AD. Because user SOA is in the cloud, Exchange-related information isn't needed in AD. For managing Exchange recipients without an on-premises Exchange Server, see Decommission the last Exchange Server after transferring SOA to cloud and Manage recipients in Exchange hybrid environments using management tools.
  • Mail-enabled groups and distribution groups. Only security groups are supported.
  • Password writeback, which LDAP and password-based apps, including apps that authentiate users via LDAP, need. Cloud-managed users have no AD DS password to present, so the apps must be updated to Kerberos so those users can use passwordless authentication for Kerberos-based applications instead. For more information, see How cloud-managed users sign in to the application.
  • Complex multi-domain hybrid identity architectures. Provisioning to AD is designed for single-domain identity continuity.

License requirements

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…