What is Microsoft Entra Cloud Sync?
In brief
The article now explains that enabled device synchronization can sync Active Directory computer objects to Microsoft Entra ID so devices can become hybrid joined, and links to configuration steps.
What Entra admins need to know
Administrators can use the updated guidance when evaluating or configuring Cloud Sync; no required action is stated.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
What is Microsoft Entra Cloud sync?Sync?
Microsoft Entra Cloud Sync is a hybrid identity synchronization service thatservice. It provides modern, cloud-managed synchronization of users, groups, and contacts between Active Directory and Microsoft Entra ID. It representsWhen device sync is enabled, Cloud Sync can synchronize Active Directory computer objects to Microsoft's strategic direction for Entra ID so devices can become Microsoft Entra hybrid identity, offering a lightweight, agent-based approach that simplifies deployment and management while enabling advanced scenarios like disconnected forest synchronization.joined.
Cloud Sync solves common challenges organizations face with hybrid identity infrastructure by eliminating single points of failure, reducing on-premises management overhead,uses the Microsoft Entra provisioning agent. The following sections describe its architecture and enabling complex multi-forest scenarios that support organizational growth and change.supported scenarios.
Core architecture and components
Cloud syncSync is built on a modern, cloud-first architecture with two key components:
Microsoft Entra provisioning agent: A lightweight, on-premises agent that acts as a secure bridge between Active Directory and Microsoft Entra ID. The agent uses the same proven technology as Microsoft Entra Application Proxy and Pass-Through Authentication, requiring only outbound connections and providing automatic updates from the cloud.
:::image type="content" source="media/what-is-cloud-sync/architecture-2.png" alt-text="Diagram of basic cloud sync." lightbox="media//what-is-cloud-sync/architecture-2.png":::
How Cloud syncSync works
Cloud sync leverages the System for Cross-domain Identity Management (SCIM) standard to ensure reliable and standards-based identity management. The synchronization process follows this flow:
| Cloud-managed configuration | All synchronization configuration is stored and managed in Microsoft Entra ID through the Microsoft Entra admin center. Administrators can modify settings, monitor status, and troubleshoot issues from any location without VPN access. | | High availability through multi-agent support | Cloud sync supports multiple active provisioning agents deployed across different servers, providing automatic failover without configuration changes. Synchronization continues seamlessly when individual agents become unavailable. | | Disconnected forest synchronization | Cloud sync natively handles multiple disconnected Active Directory forests without requiring complex configurations or multiple synchronization instances. This capability supports mergers and acquisitions, historical multi-forest environments, and scenarios where forests cannot be connected. | | Device synchronization | Cloud Sync can synchronize Active Directory computer objects to Microsoft Entra ID so devices can become Microsoft Entra hybrid joined. For configuration steps, see Configure device sync with Microsoft Entra Cloud Sync. | | Simplified installation and management | The lightweight agent model requires minimal server resources and can be deployed on domain controllers or dedicated servers. Agents automatically receive security updates and patches from Microsoft. | | Advanced provisioning scenarios | Cloud sync enables cloud-to-AD provisioning scenarios, including group provisioning to Active Directory for governing on-premises applications. This bidirectional capability supports modern identity architectures where Microsoft Entra ID serves as the authoritative identity source. |
How is Microsoft Entra Cloud syncSync different from Microsoft Entra Connect sync?Sync?
With Microsoft Entra Cloud Sync, provisioning orchestration occurs entirely in Microsoft Online Services rather than on-premises infrastructure. Organizations deploy lightweight agents in their on-premises or Infrastructure-as-a-Service (IaaS) environments that act as secure bridges between Microsoft Entra ID and Active Directory. All provisioning configuration, monitoring, and management is handled through the cloud service, eliminating the complexity of on-premises sync server management.
Microsoft Entra Cloud syncSync video
The following short video provides an excellent overview of Microsoft Entra Cloud Sync:
[!VIDEO https://learn-video.azurefd.net/vod/player?id=2b0047aa-84ba-430d-8ce9-39cfdc55276d]
When to consider Cloud syncSync
Cloud Sync is designed to modernize hybrid identity infrastructure and enable scenarios that traditional synchronization approaches cannot support effectively. Key scenarios include:
@@ -1,26 +1,29 @@ ----title: What is Microsoft Entra Cloud sync?-description: Describes Microsoft Entra Cloud sync.+title: What is Microsoft Entra Cloud Sync?+description: Learn how Microsoft Entra Cloud Sync synchronizes users, groups, and contacts from Active Directory to Microsoft Entra ID, and how enabled device sync supports hybrid join. ms.topic: overview-ms.date: 02/17/2025+ms.date: 10/06/2026 ms.subservice: hybrid-cloud-sync+ms.custom: msecd-doc-authoring-1023+ai-usage: ai-assisted+#customer intent: As an IT administrator, I want to understand Microsoft Entra Cloud Sync capabilities so that I can choose a synchronization approach for my organization. --- -# What is Microsoft Entra Cloud sync?+# What is Microsoft Entra Cloud Sync? > [!VIDEO https://www.youtube.com/embed/9T6lKEloq0Q] -Microsoft Entra Cloud Sync is a hybrid identity synchronization service that provides modern, cloud-managed synchronization of users, groups, and contacts between Active Directory and Microsoft Entra ID. It represents Microsoft's strategic direction for hybrid identity, offering a lightweight, agent-based approach that simplifies deployment and management while enabling advanced scenarios like disconnected forest synchronization.+Microsoft Entra Cloud Sync is a hybrid identity synchronization service. It provides cloud-managed synchronization of users, groups, and contacts between Active Directory and Microsoft Entra ID. When device sync is enabled, Cloud Sync can synchronize Active Directory computer objects to Microsoft Entra ID so devices can become Microsoft Entra hybrid joined. -Cloud Sync solves common challenges organizations face with hybrid identity infrastructure by eliminating single points of failure, reducing on-premises management overhead, and enabling complex multi-forest scenarios that support organizational growth and change.+Cloud Sync uses the Microsoft Entra provisioning agent. The following sections describe its architecture and supported scenarios. > [!NOTE]-> Cloud sync can be used for tenants in the Microsoft Commercial, US Government, and [21Vianet (China)](/office365/servicedescriptions/office-365-platform-service-description/microsoft-365-operated-by-21vianet) clouds. SSPR for on-prem identities is not yet available to be used with Cloud Sync in the 21 Vianet (China) cloud.+> Cloud Sync can be used for tenants in the Microsoft Commercial, US Government, and [21Vianet (China)](/office365/servicedescriptions/office-365-platform-service-description/microsoft-365-operated-by-21vianet) clouds. SSPR for on-premises identities isn't available with Cloud Sync in the 21Vianet (China) cloud. ## Core architecture and components -Cloud sync is built on a modern, cloud-first architecture with two key components:+Cloud Sync is built on a cloud-first architecture with two key components: **Microsoft Entra provisioning agent**: A lightweight, on-premises agent that acts as a secure bridge between Active Directory and Microsoft Entra ID. The agent uses the same proven technology as Microsoft Entra Application Proxy and Pass-Through Authentication, requiring only outbound connections and providing automatic updates from the cloud. @@ -28,7 +31,7 @@ Cloud sync is built on a modern, cloud-first architecture with two key component :::image type="content" source="media/what-is-cloud-sync/architecture-2.png" alt-text="Diagram of basic cloud sync." lightbox="media//what-is-cloud-sync/architecture-2.png"::: -## How Cloud sync works+## How Cloud Sync works Cloud sync leverages the System for Cross-domain Identity Management (SCIM) standard to ensure reliable and standards-based identity management. The synchronization process follows this flow: @@ -44,12 +47,13 @@ Cloud sync leverages the System for Cross-domain Identity Management (SCIM) stan | Cloud-managed configuration | All synchronization configuration is stored and managed in Microsoft Entra ID through the Microsoft Entra admin center. Administrators can modify settings, monitor status, and troubleshoot issues from any location without VPN access. | | High availability through multi-agent support | Cloud sync supports multiple active provisioning agents deployed across different servers, providing automatic failover without configuration changes. Synchronization continues seamlessly when individual agents become unavailable. | | Disconnected forest synchronization | Cloud sync natively handles multiple disconnected Active Directory forests without requiring complex configurations or multiple synchronization instances. This capability supports mergers and acquisitions, historical multi-forest environments, and scenarios where forests cannot be connected. |+| Device synchronization | Cloud Sync can synchronize Active Directory computer objects to Microsoft Entra ID so devices can become Microsoft Entra hybrid joined. For configuration steps, see [Configure device sync with Microsoft Entra Cloud Sync](device-sync.md). | | Simplified installation and management | The lightweight agent model requires minimal server resources and can be deployed on domain controllers or dedicated servers. Agents automatically receive security updates and patches from Microsoft. | | Advanced provisioning scenarios | Cloud sync enables cloud-to-AD provisioning scenarios, including group provisioning to Active Directory for governing on-premises applications. This bidirectional capability supports modern identity architectures where Microsoft Entra ID serves as the authoritative identity source. | <a name='how-is-azure-ad-connect-cloud-sync-different-from-azure-ad-connect-sync'></a> -## How is Microsoft Entra Cloud sync different from Microsoft Entra Connect sync?+## How is Microsoft Entra Cloud Sync different from Microsoft Entra Connect Sync? With Microsoft Entra Cloud Sync, provisioning orchestration occurs entirely in Microsoft Online Services rather than on-premises infrastructure. Organizations deploy lightweight agents in their on-premises or Infrastructure-as-a-Service (IaaS) environments that act as secure bridges between Microsoft Entra ID and Active Directory. All provisioning configuration, monitoring, and management is handled through the cloud service, eliminating the complexity of on-premises sync server management. @@ -59,13 +63,13 @@ For a detailed feature comparison table, see [Cloud Sync and Microsoft Entra Con <a name='azure-ad-connect-cloud-sync-video'></a> -## Microsoft Entra Cloud sync video+## Microsoft Entra Cloud Sync video The following short video provides an excellent overview of Microsoft Entra Cloud Sync: > [!VIDEO https://learn-video.azurefd.net/vod/player?id=2b0047aa-84ba-430d-8ce9-39cfdc55276d] -## When to consider Cloud sync+## When to consider Cloud Sync Cloud Sync is designed to modernize hybrid identity infrastructure and enable scenarios that traditional synchronization approaches cannot support effectively. Key scenarios include: 