Tools used for synchronization
In brief
The comparison article now includes devices among supported synchronization scenarios and notes that Cloud Sync can synchronize computer objects for Microsoft Entra hybrid join when device sync is enabled. It also adds a comparison table and selection wizard.
What Entra admins need to know
Administrators can use the updated guidance to evaluate synchronization tools and determine whether Cloud Sync fits their hybrid identity and device synchronization needs.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Tools used for synchronization
The followingThis article briefly describescompares Microsoft Entra Cloud Sync, Connect Sync, Microsoft Identity Manager (MIM), and the Microsoft tools that current exist todayECMA host connector. Use the comparison to choose a tool for synchronization. synchronizing identities or provisioning users to on-premises applications.
List of tools
Cloud
syncSync and the provisioning agent - Microsoft Entra Cloud Syncis the newest offering from Microsoft designed to meet and accomplish your hybrid identity goals for synchronization ofsynchronizes users, groups, and contacts from Active Directory to Microsoft Entra ID.ItWhen device sync is enabled, it can also synchronize computer objects for Microsoft Entra hybrid join. Cloud Sync uses thelight-weightlightweight provisioning agent and isfullyconfigurableviathrough theportal.Microsoft Entra admin center. For more information, see What is Microsoft Entra Cloud Sync?, What is the provisioning agent?, andWhat is the provisioning agent?Configure device sync with Microsoft Entra Cloud Sync.Connect
syncSync - Microsoft Entra Connect is an on-premises application for synchronizing identities with Microsoftapplication designed to meet and accomplish your hybrid identity goals.Entra ID. For more information, see What is Microsoft Entra Connect?.Microsoft Identity Manager with the Graph connector - Microsoft's on-premises identity and access management solution that provides advanced inter-directory provisioning to achieve hybrid identity environments for Active Directory, Microsoft Entra ID, and other directories. For more information, see Microsoft Identity Manager. MIM is slowly being deprecated and should only be used in advanced scenarios. For more information, see Deprecated Features and planning for the future
ECMA Host connector - The ECMA host works with the provisioning agent to provision and synchronize users from the cloud into on-premises applications such as SQL and LDAP. For more information, see Microsoft Entra on-premises application identity provisioning architecture and What is the provisioning agent?
Selecting the right tool
Each of theseThese tools can accomplish similar results. So selectingsupport different hybrid identity scenarios. Compare their capabilities in the right tool is essential. For most scenarios, cloud sync is going to be the recommended tool. Then connect sync and for advanced/complex scenarios, MIM. For on-premises applications, the ECMA Host would be the preferred tool. For more information, supported sync scenarios table. To determine which tool is right for you, you should, then use the wizard at the sync tool selection wizard site.to choose a tool.
Next steps
@@ -1,27 +1,29 @@ --- title: 'Tools used for synchronization'-description: This article introduces the various tools that can be used to synchronize the cloud with on-premises environments.+description: Compare Microsoft identity synchronization tools for users, groups, contacts, and devices to choose an approach for hybrid identity with Active Directory. ms.topic: concept-article ms.tgt_pltfrm: na-ms.date: 04/09/2025-ms.subservice: hybrid+ms.date: 10/06/2026+ms.custom: msecd-doc-authoring-1023+ai-usage: ai-assisted+#customer intent: As an IT administrator, I want to compare Microsoft identity synchronization tools so that I can choose an approach for my hybrid identity environment. --- # Tools used for synchronization- The following article briefly describes the Microsoft tools that current exist today for synchronization. +This article compares Microsoft Entra Cloud Sync, Connect Sync, Microsoft Identity Manager (MIM), and the ECMA host connector. Use the comparison to choose a tool for synchronizing identities or provisioning users to on-premises applications. ## List of tools -- **Cloud sync and the provisioning agent** - Microsoft Entra Cloud Sync is the newest offering from Microsoft designed to meet and accomplish your hybrid identity goals for synchronization of users, groups, and contacts to Microsoft Entra ID. It uses the light-weight provisioning agent and is fully configurable via the portal. For more information, see [What is cloud sync?](cloud-sync/what-is-cloud-sync.md) and [What is the provisioning agent?](cloud-sync/what-is-provisioning-agent.md)+- **Cloud Sync and the provisioning agent** - Microsoft Entra Cloud Sync synchronizes users, groups, and contacts from Active Directory to Microsoft Entra ID. When device sync is enabled, it can also synchronize computer objects for Microsoft Entra hybrid join. Cloud Sync uses the lightweight provisioning agent and is configurable through the Microsoft Entra admin center. For more information, see [What is Microsoft Entra Cloud Sync?](cloud-sync/what-is-cloud-sync.md), [What is the provisioning agent?](cloud-sync/what-is-provisioning-agent.md), and [Configure device sync with Microsoft Entra Cloud Sync](cloud-sync/device-sync.md). -- **Connect sync** - Microsoft Entra Connect is an on-premises Microsoft application designed to meet and accomplish your hybrid identity goals. For more information, see [What is Microsoft Entra Connect?](connect/whatis-azure-ad-connect-v2.md).+- **Connect Sync** - Microsoft Entra Connect is an on-premises application for synchronizing identities with Microsoft Entra ID. For more information, see [What is Microsoft Entra Connect?](connect/whatis-azure-ad-connect-v2.md). - **Microsoft Identity Manager with the Graph connector** - Microsoft's on-premises identity and access management solution that provides advanced inter-directory provisioning to achieve hybrid identity environments for Active Directory, Microsoft Entra ID, and other directories. For more information, see [Microsoft Identity Manager](/microsoft-identity-manager/microsoft-identity-manager-2016). MIM is slowly being deprecated and should only be used in advanced scenarios. For more information, see [Deprecated Features and planning for the future](/microsoft-identity-manager/microsoft-identity-manager-2016-deprecated-features) - **ECMA Host connector** - The ECMA host works with the provisioning agent to provision and synchronize users from the cloud into on-premises applications such as SQL and LDAP. For more information, see [Microsoft Entra on-premises application identity provisioning architecture](~/identity/app-provisioning/on-premises-application-provisioning-architecture.md) and [What is the provisioning agent?](cloud-sync/what-is-provisioning-agent.md) ## Selecting the right tool-Each of these tools can accomplish similar results. So selecting the right tool is essential. For most scenarios, cloud sync is going to be the recommended tool. Then connect sync and for advanced/complex scenarios, MIM. For on-premises applications, the ECMA Host would be the preferred tool. For more information, [see the supported sync scenarios table](common-scenarios.md#supported-sync-scenarios). To determine which tool is right for you, you should use the wizard at the [Choosing the right sync tool](common-scenarios.md) site.+These tools support different hybrid identity scenarios. Compare their capabilities in the [supported sync scenarios table](common-scenarios.md#supported-sync-scenarios), then use the [sync tool selection wizard](common-scenarios.md) to choose a tool. ## Next steps - [Common scenarios](common-scenarios.md) 