How to setup Microsoft Entra Connect Cloud Sync (manual)

When Microsoft launched Azure AD/Entra ID we could synchronize with the Azure AD connector. Since a few years there is a new solution to synchronize on-premise resources with Entra ID. In this manual we will show you how to setup Entra Cloud Sync.

image

What are the differences between Cloud Sync and the Connector sync?

Cloud Sync (recommended)Solution for a multi-national org that wants to consolidate your identities or if you are building a cloud strategy to reduce your on-premises footprint.Connect SyncOn-premises solution that takes all the operations that are related to synchronize identity data between your on-premises environment and Microsoft Entra ID.
Sync cycle10 minutes30 minutes
Connect to single and multiple on-premises AD forestsYesYes
Connect to multiple on-premises AD forestsYesYes
Connect to multiple disconnected on-premises AD forestsYesNo
Lightweight agent installation modelYesNo
Multiple active agents for high availabilityYesNo
Connect to LDAP directoriesNoYes
Synchronize Exchange Online attributesYesYes
Support for Password Hash SyncYesYes
Support for writeback (passwords, devices, groups)YesYes
On-demand provisioningYesYes

Scenarios supported by Cloud Sync

  • Single forest, single Microsoft Entra tenant
  • Multi-forest, single Microsoft Entra tenant
  • Existing forest with Microsoft Entra Connect, new forest with cloud provisioning
  • Piloting Microsoft Entra Connect cloud sync in an existing hybrid AD forest

Manual:

STEP 1: Download provisioning Agent.

From the Azure Portal download the provisioning agent: https://portal.azure.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/~/GetStarted

image

STEP 2: Install the agent on a desired server. This may be a Domain controller or another server.

Now execute the installation wizard on the desired server.

image
image

STEP 3: Configure the Agent

Now we are going to configure the provisioning agent. Before we begin make sure that the logged in user is a admin account with enough permissions! (Domain/Enterprise admin) Make sure to select the checkbox to connect to your on-premises domain:

image

Now login with an Entra Global admin account to setup a link with your tenant:

image

After successful logging in to your tenant we need to create an group managed service account with the wizard.

image

Now make sure that your domain is visible and click Next

image

in the last step confirm the configuration, after confirming it can take up to 10 minutes to finalize the process, so please be patient.

image

STEP 4: configure Cloud sync

Now we need to configure the cloud sync itself. Again go to the Azure portal: https://portal.azure.com/#view/Microsoft_AAD_Connect_Provisioning/CloudSyncMenuBlade/~/CloudSyncConfigurations

image

Now select the domain matching the on-premises environment and click Create at the bottom of the page.

image

After completing the above steps the sync isn’t enabled yet. We now need to configure the filters and enable the sync. From the overview page click on Add scoping filters if you don’t want to synchronize all objects.

image

You can choose to use All users, security groups or organizational units.

image

Before enabling synchronisation it is recommended to test the setup first. From the overview page you can run the test:

image

Now fill in a test user. Use the UPN.

image

When the test is completed without warnings or errors continue with the enablement of the connector:

image

Add a Comment

Your email address will not be published. Required fields are marked *