Ties an on-premises AD object for good to its twin in Microsoft Entra, normally with ms-DS-ConsistencyGuid as the source. Once written it is fixed, and hard matching depends on it.
Also called immutableId.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains sourceAnchor in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra
The umbrella brand covering Microsoft's identity and network access portfolio. Internet Access, Private Access, External ID and ID Governance all belong to it, built on top of the core directory service, Entra ID.
- ms-DS-ConsistencyGuid
Microsoft Entra Connect 1.1.524.0 onwards anchors users on this Active Directory attribute as their immutableID, filling a blank value from objectGUID. Connect's account has to be allowed to write it, and after import the anchor cannot be changed.
Related terms
- Hard match
When syncing, an on-premises object is first paired with one already in the cloud using sourceAnchor and immutableId. Only when that pairing doesn't work does sync fall back to a soft match on UPN or primary SMTP address.
- Soft match
If matching on sourceAnchor fails and the cloud account lacks an immutableId, Microsoft Entra Connect tries to join an on-premises user to an existing cloud one using their primary SMTP address or userPrincipalName.