How to Synchronize On-Premises Active Directory with Microsoft 365
Question details
The user needs to securely synchronize an on-premises Active Directory with an existing Microsoft 365 tenant using Microsoft Entra Connect.
- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Planning and deploying directory synchronization between on-premises environments and cloud tenants.
- Observed behavior
- Requires careful planning around account matching, source-of-authority, and deletion rules before deployment.
Before enabling synchronization, ensure you have full administrative access to both your on-premises Active Directory and the Microsoft 365 tenant, and verify that you have assessed your current directory states.
Perform Pre-Synchronization Assessment and Controlled Testing
Assess your cloud and on-premises identities to prevent accidental deletions or account duplication before syncing.
Microsoft Entra Connect handles the synchronization process, but improper configuration can lead to duplicated accounts or loss of data. Planning account matching, source-of-authority changes, and deletion rules is highly recommended.
Audit both cloud and on-premises identities, verifying UPNs, proxy addresses, and immutable IDs to identify any duplicate accounts or mismatched records.
Consult with an identity administrator to review Microsoft Entra Connect's matching and filtering behaviors to ensure users link correctly.
Enable accidental deletion prevention in Microsoft Entra Connect. This feature protects production users from bulk deletions if an organizational unit is accidentally removed from scope.
Run a pilot synchronization in an isolated staging environment before applying changes to the production tenant.

Simplify Your Team's Productivity with WPS Office
While managing Microsoft 365 migrations and Active Directory synchronization can be complex, providing your team with powerful productivity tools doesn't have to be. WPS Office is a free, lightweight, and highly compatible alternative to Microsoft Office apps.

Frequently Asked Questions
What happens if I synchronize without checking immutable IDs?
If immutable IDs do not match properly, Microsoft Entra Connect may create duplicate cloud accounts or fail to link existing Microsoft 365 accounts with their on-premises counterparts.
How do I prevent accidental bulk deletions during AD sync?
Microsoft Entra Connect includes a feature called 'Prevent accidental deletes' which is enabled by default. It stops exports that would delete more than a specified threshold of objects (default is 500) in a single sync cycle.
Can I sync multiple on-premises forests to a single Microsoft 365 tenant?
Yes, Microsoft Entra Connect supports multi-forest topologies. However, you must configure it properly to ensure users represented in multiple forests are consolidated into a single identity in the cloud.
What is the source-of-authority once synchronization is enabled?
Once synchronized, the on-premises Active Directory generally becomes the source of authority. This means most attribute updates and password changes must be performed on-premises and then synced to the cloud.




