Microsoft Entra ID
Provisioning

Common hybrid scenarios with Microsoft Entra ID

In brief

The comparison table now lists Microsoft Entra Cloud Sync as supporting Microsoft Entra hybrid join and links to Cloud Sync device synchronization instructions. The article also expands comparisons across Cloud Sync, Connect Sync, MIM, and ECMA Host.

What Entra admins need to know

Administrators evaluating hybrid identity tools can now identify Cloud Sync as an option for hybrid join and access device synchronization guidance.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Hybrid scenarios

The following document describesCompare Microsoft Entra Cloud Sync, Connect Sync, Microsoft Identity Manager (MIM), and the commonECMA Host connector to find a tool that supports your hybrid identity and supported hybrid syncprovisioning scenarios.

Supported sync scenarios

The following table outlines the most common and supported sync scenarios.

Scenario Supported with cloud syncCloud Sync Supported with connect syncConnect Sync Supported with MIM and the Graph Connector Supported with ECMA Host connector
New Hybrid customers managing identities ● ● ● N/A
Mergers and acquisitions (disconnected forest) ● N/A ● N/A
High availability - latency (I need high availability) ● N/A ● N/A
Migration from connect syncConnect Sync to cloud syncCloud Sync ● ● N/A N/A
Microsoft Entra hybrid join N/A● ● N/A N/A
Exchange hybrid ● ● N/A N/A
User accounts in one forest / mailboxes in resource forest N/A ● N/A N/A
Sync large domains with more than 250K objects N/A ● ● N/A
Synchronize from cloud to on-premises LDAP N/A N/A ● ●
Synchronize from cloud to on-premises SQL N/A N/A ● ●

For steps to configure device synchronization in Cloud Sync, see Configure device sync with Microsoft Entra Cloud Sync.

Supported provisioning scenarios

The following table outlines the common and supported provisioning scenarios.

Scenario Supported with cloud syncCloud Sync Supported with connect syncConnect Sync Supported with MIM and the Graph Connector Supported with ECMA Host connector
Group provisioning to Active Directory ● N/A ● N/A

For more information, see Supported topologies for Cloud Sync and Supported topologies for Connect Sync.

Additional information

  • You can syncsynchronize users &and groups from the same domain by using Connect Sync and cloud syncCloud Sync if:
    • Scoping filters in each sync is mutually exclusive
    • If inclusive, don’t have the same attributes values clashing (Precedence isn’t supported)
  • You can syncsynchronize users &and groups usingwith Connect Sync while using cloud sync’Cloud Sync's net new capabilities (*called out in Roadmap)capabilities.
  • You can sync objects from a single AD to multiple Azure ADs if writeback capabilities are enabled only in a single Microsoft Entra tenant.

Cloud syncSync and connect syncConnect Sync in parallel

You can run cloud syncCloud Sync and Microsoft Entra Connect in the same forest. You may decide to do allow cloud sync to handle 80%For example, you might use Cloud Sync for most scenarios and use Microsoft Entra Connect for some of your more obscure, 20% scenarios.scenarios that require its features. The tutorial,tutorial Migrate to Microsoft Entra Cloud Sync for an existing synced AD forest shows an example of how you wouldto run each.both tools.

Common authentication methods and scenarios

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…