Keeps Microsoft Entra ID in step with an on-premises Active Directory by synchronising its identities to the cloud.
Also called Azure AD Connect, Azure AD Connect, Entra Connect.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104SC-500AZ-900SC-900SC-300MD-102
Each book explains Microsoft Entra Connect in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- AD
Short for Active Directory, the directory service built into Windows Server (AD DS). Entra Connect synchronises on-premises forests to Microsoft Entra ID.
Related terms
- Hybrid Identity Administrator
The Entra role for managing federation, PHS, PTA, cloud sync and Entra Connect settings. It is the cloud role with the least privilege that still covers Entra Connect.
- Microsoft Entra Connect Health
Watches the health of AD FS, AD DS and Entra Connect sync, reporting on it and sending alerts by email.
- Microsoft Entra Connect Sync
Previously named Azure AD Connect sync. This engine runs on your own servers, keeps a database and rules of its own, and copies AD DS objects, devices included, up to Microsoft Entra ID; Microsoft would rather you used Cloud Sync if it is enough.
- ms-DS-ConsistencyGuid
Microsoft Entra Connect 1.1.524.0 onwards anchors users on this Active Directory attribute as their immutableID, filling a blank value from objectGUID. Connect's account has to be allowed to write it, and after import the anchor cannot be changed.
- Pass-through Authentication
Sign-in option in Microsoft Entra Connect where agents running on-premises, using outbound port 443 only, check passwords against AD. No password hashes are kept in the cloud.
- Password hash sync
Sign-in option in Microsoft Entra Connect that copies password hashes to the cloud, so Microsoft Entra ID itself handles authentication and lockout.
- RODC
Microsoft Entra Connect can't work against this kind of DC because it needs to write, and Password Protection agents aren't put on one either: its copy of Active Directory can only be read.
- SCP
Created in Active Directory by Microsoft Entra Connect, this object tells domain-joined machines which tenant to register with during hybrid join.