Microsoft Entra ID
General

Connect Version History

In brief

The version history page was updated with spelling fixes in existing release and feature descriptions.

What Entra admins need to know

No administrator action is required.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  1. Open miiserver.exe.config and add the following entry inside the assemblyBinding section: `

    `
  2. Save the file.

|Version |End of support date |Release date |

Release status

09/23/2026: Released for download via the Microsoft Entra admin center. This is a hotfix release.

Bug fixes

Updated features

  • Phishing-resistant authentication in the Microsoft Entra Connect setup wizard is now generally available and enabled by default. The Windows Web Account Manager prompt supports passkeys, FIDO2 security keys, and passwords, reuses the signed-in session across Microsoft Entra services, and preserves Seamless Single Sign-On Kerberos key rotation.
  • When you configure Seamless Single Sign-On by using the standalone PowerShell module, you must import ADSync.psd1 before AzureADSSO.psd1. Learn more.
  • Cloud configuration cmdlets no longer require an explicit -AADUserName. When you omit the parameter, Microsoft Entra Connect derives a sign-in hint from the connector configuration and opens an interactive sign-in prompt. This behavior applies to Set-ADSyncAADCompanyFeature, Set-ADSyncAADPasswordSyncState, Enable-ADSyncExportDeletionThreshold, Set-ADSyncScheduler, and Set-ADSyncDirSyncConfiguration.
  • The Select Containers dialog in Synchronization Service Manager is now read-only. You can still use the dialog to view the current selections. To make changes, use Customize synchronization options in the Microsoft Entra Connect wizard. Learn more.

Added features

  • Added support for phishing-resistant authentication methods in the Microsoft Entra Connect setup wizard (preview). Administrators can now sign in using passkeys and FIDO2 security keys through Windows Web Account Manager (WAM) when configuring Microsoft Entra Connect.
  • Added support for the France sovereign cloud environment, including Pass-through Authentication, Seamless Single Sign-On, password writeback, and Health Agent monitoring.

Updated features

Release status

09/01/2025: Released for download via the Microsoft Entra admin center. Existing installations will be auto-upgraded to this build starting September 4, 2025 and will be done in multiple phases.

Added Features

  • Improved the setup process for Application-Based Authentication to handle TPM-backed certificates (certificates protected by a Trusted Platform Module, see What is a TPM?). The system now tests a certificate’s signing capability upfront and automatically falls back to software-based certificates if TPM signature fails.
  • Implemented automatic removal of certificates if an Application-Based Authentication configuration fails after a certificate is created. This prevents unused certificates from lingering on the server in failure scenarios, improving security by avoiding accumulation of orphaned certificates.

Bug fixes

  • Resolved an issue on FIPS-enabled servers that was causing setup failures. Application-Based Authentication now works correctly on servers with FIPS mode enabled by using FIPS-compliant cryptographic algorithms.
  • Fixed an issue where certificate auto-rotation was incorrectly reported as active when the scheduler was suspended. The auto-rotation logic now checks the scheduler’s state before indicating status, ensuring the View or export current configuration wizard accurately reflects whether auto-rotation is enabled.
  • Removed an inappropriate admin audit event that was being logged for automatic certificate operations. These background certificate actions no longer generate administrative audit log entries, resulting in a cleaner audit trail (only actual administrator-initiated changes will appear in the Entra Connect Sync audit logs).

2.5.76.0

Release status

07/31/2025: Released for download via the Microsoft Entra admin center. Existing installations will be auto-upgraded to this build starting August 14th, 2025, and will be done in multiple phases.

Added Features

Bug fixes

  • The issue in selecting and de-selecting child OUs, affecting Active Directory multi-domain scenarios in the Connect Sync wizard, is fixed.
  • The issue where users were prompted to set up Azure MFA instead of on-premises ADFS MFA, due to federated domain settings and MFA flag resets during updates, has been resolved.
  • Resolved an issue that prevented some Microsoft Entra Connect Sync instances from auto-upgrading by ensuring the agent identifier is correctly sourced when missing.
  • Fixed issue in the configuration wizard that resulted in Directory synchronization for this directory currently has a mismatch in sync enabled and sync status error when DirSync Status is in PendingEnabled

Bug fixes

  • Fixed the removal of the SSPR configuration when changes are made on the Azure AD Connector and saved in the Sync Service manager UI
  • Fixed validation for the Global Administrator/Hybrid Identity Administrator role done during Entra Connect Sync installation and users with Global Administrator/Hybrid Identity Administrator through Privileged Identity Management (PIM).
  • Fixed the "no registered protocol handlers" error on Federate with AD FS scenario.
  • Fixed "Relying party must be unique (conflict error)" error on Federate with AD FS scenario.

Bug fixes

  • Fixed an issue with Privileged Identity Management (PIM), Microsoft Entra roles, and PIM for Groups to verify that PIM is enabled and that the user has the Hybrid Identity Administrator role enabled.
  • Fixed an issue where AD FS commands were failing when Connect Sync is installed on a non-ADFS server.

Updated Features

  • The step Connect to Microsoft Entra ID in the Connect Sync Wizard won't require password before redirecting you to the login page.

  • Updated Default Rule: "onPremisesObjectIdentifier" attribute added to the In from AD - User Account Enabled sync rule. Adding this rule allows the sync engine to pick the onPremisesObjectIdentifier attribute from the user who is enabled, in a scenario where:

  • the same user is represented across different forests, and

  • the user is disabled in one of the forests

  • Introduced a registry key that allows you to set the precedence number for custom rules to be more than 100, if needed. The precedence of the first standard rule can be set using the key HLKM:HKLM:\SOFTWARE\Microsoft\Azure AD Connect\FirstStandardRulePrecedence, allowing for more custom rules. If no value is set, 100 is the default.

  • Cmdlets in ADSync PowerShell module that communicate with Microsoft Entra ID now require Microsoft Entra ID login, for example, Add-ADSyncAADServiceAccount or Get-ADSyncExportDeletionThreshold

  • All references to legacy MSOnline PowerShell module have been removed and replaced by equivalent Microsoft Graph API calls.

Miscellaneous

  • The minimum .NET runtime requirement has been increased to 4.7.2.

  • Branding updates to match Microsoft Entra ID branding.

  • Improved Wizard experience to ensure domain validation has to be completed before moving to the next step in the wizard.

  • Improved error messaging when fetching list of domains in a forest

  • Fixed error that made installing with an existing database incompatible with Password Writeback enabled.

  • Fixed credential issue with ADConnectivityTool module that could occur if NTLM is set to deny-all.

  • Fixed error around localization string that could occur when prompting for Enterprise Admin.

  • Fixed an issue where the re-running the Wizard would display initial OU configuration instead of the correct configuration.

  • Fixed an issue where auto upgrade could fail when trying to get the service account.

  • Fixed an error that could occur if a join rule contains an attribute name with a hyphen.

  • Improved error messaging in the Wizard when TLS settings don't meet the prerequisites.

  • Fixed a bug with the password hash not syncing on changing the SMART CARD REQUIRED bit flag. This fix won't allow the passwords in Microsoft Entra ID and Active Directory to be in sync for scenarios where smart card is used as an authentication method. Learn more

  • Fixed a bug where auto upgrade endpoints were configured incorrectly for some clouds.

2.1.20.0

Release status:

11/9/2022: Released for download

Bug fixes

2.1.19.0

Release status:

11/2/2022: Released for download

Functional changes

2.1.18.0

Release status:

10/5/2022: Released for download

Bug fixes

  • we fixed a bug where upgrade from version 1.6 to version 2.1 got stuck in a loop due to IsMemberOfLocalGroup enumeration.
  • we fixed a bug where the Microsoft Entra Connect Configuration Wizard was sending incorrect credentials (username format) while validating if Enterprise Admin.

2.1.16.0

Release status

7/6/2022: Released for download.

Functional changes

  • We made the following Accessibility fixes:
  • Fixed a bug where Focus is lost during keyboard navigation on Domain and OU Filtering page.
  • We updated the accessible name of Clear Runs drop down.
  • We fixed a bug where the tooltip of the "Help" button isn't accessible through keyboard if navigated with arrow keys.
  • We fixed a bug where the underline of hyperlinks was missing on the Welcome page of the wizard.
  • We fixed a bug in Sync Service Manager's About dialog where the Screen reader isn't announcing the information about the data appearing under the "About" dialog box.
  • We fixed a bug where the Management Agent Name wasn't mentioned in logs when an error occurred while validating MA Name.

Functional changes

  • We updated the Microsoft Entra Connect Health component in this release from version 3.1.110.0 to version 3.2.1823.12. This new version provides compliance of the Microsoft Entra Connect Health component with the Federal Information Processing Standards (FIPS) requirements.

2.0.89.0

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…