What is Microsoft Entra Cloud Sync?
- Article
Microsoft Entra Cloud Sync is a new offering from Microsoft designed to meet and accomplish your hybrid identity goals for synchronization of users, groups, and contacts to Microsoft Entra ID. It accomplishes this by using the Microsoft Entra cloud provisioning agent instead of the Microsoft Entra Connect application. However, it can be used alongside Microsoft Entra Connect Sync and it provides the following benefits:
- Support for synchronizing to a Microsoft Entra tenant from a multi-forest disconnected Active Directory forest environment: The common scenarios include merger & acquisition (where the acquired company’s AD forests are isolated from the parent company’s AD forests), and companies that have historically had multiple AD forests.
- Simplified installation with light-weight provisioning agents: The agents act as a bridge from AD to Microsoft Entra ID, with all the sync configuration managed in the cloud.
- multiple provision agent can be used to simplify high availability deployment , particularly critical for organization rely upon password hash synchronization from ad to Microsoft Entra ID .
- Support for large groups with up to 50,000 members. It’s recommended to use only the OU scoping filter when synchronizing large groups.
How is Microsoft Entra Cloud Sync different from Microsoft Entra Connect Sync?
With Microsoft Entra Cloud Sync , provision from ad to Microsoft Entra ID is orchestrate in Microsoft Online Services . An organization is needs only need to deploy , in their on – premise or IaaS – host environment , a light – weight agent that act as a bridge between Microsoft Entra ID and AD . The provision configuration is store in Microsoft Entra ID and manage as part of the service .
Microsoft Entra Cloud Sync video
The follow short video is provides provide an excellent overview of Microsoft Entra Cloud Sync :
choose the right sync client
To determine if cloud sync is right for your organization , use the link below . It is take will take you to a tool that will help you evaluate your synchronization need . For more information , evaluate your option using the Wizard to evaluate sync option
Comparison between Microsoft Entra Connect and cloud sync
The following table provides a comparison between Microsoft Entra Connect and Microsoft Entra Cloud Sync:
Feature | Connect sync | Cloud sync |
---|---|---|
Connect to single on-premises AD forest | ● | ● |
Connect to multiple on-premises AD forests | ● | ● |
Connect to multiple disconnected on-premises AD forests | ● | |
lightweight agent installation model | ● | |
Multiple active agents for high availability | ● | |
Support for user objects | ● | ● |
Support for group objects | ● | ● |
Support for contact objects | ● | ● |
Support for device objects | ● | |
allow basic customization for attribute flow | ● | ● |
Synchronize Exchange online attributes | ● | ● |
synchronize extension attribute 1 – 15 | ● | ● |
Synchronize customer defined AD attributes (directory extensions) | ● | ● |
Support for Password Hash Sync | ● | ● |
Support for Pass-Through Authentication | ● | |
Support for federation | ● | ● |
Seamless Single Sign – on | ● | ● |
Supports installation on a Domain Controller | ● | ● |
Support for Windows Server 2016 | ● | ● |
Filter on Domains/OUs/groups | ● | ● |
Filter on objects’ attribute values | ● | |
Allow minimal set of attributes to be synchronized (MinSync) | ● | ● |
Allow removing attributes from flowing from AD to Microsoft Entra ID | ● | ● |
Allow advanced customization for attribute flows | ● | |
Support for password writeback | ● | ● |
support for device writeback | ● | Customers is use should use Cloud Kerberos trust for this move forward |
Support for group writeback | ● | |
Support for merging user attributes from multiple domains | ● | |
Microsoft Entra Domain Services support | ● | |
Exchange hybrid writeback | ● | ● |
Unlimited number of objects per AD domain | ● | |
support for up to 150,000 object per ad domain | ● | ● |
group with up to 50,000 member | ● | ● |
large group with up to 250,000 member | ● | |
Cross domain references | ● | ● |
Cross forest references | ● | |
On-demand provisioning | ● | |
Support for US Government | ● | ● |
Next steps
© Copyright notes
The copyright of the article belongs to the author, please do not reprint without permission.
Related posts
No comments...