VPN Requirements for Migrating Active Directory to Hybrid Identity
Question details
The user needs to understand the site-to-site VPN requirements and connectivity prerequisites for connecting an on-premises Active Directory with Microsoft Entra ID using Microsoft Entra Connect.
- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Migrating on-premises Active Directory to a Hybrid Identity environment.
- Observed behavior
- Seeking proper network configurations to ensure secure and successful synchronization between local domain controllers and cloud identity services.
Before configuring your network for hybrid identity, ensure you have global administrator access to your Microsoft Entra ID portal and enterprise administrator rights in your local Active Directory.
Consult the Microsoft Entra ID Q&A Community for Network Topology
Because site-to-site VPN and synchronization requirements vary heavily based on enterprise firewall rules and network topologies, Microsoft's dedicated Entra ID community is the best resource for exact configurations.
Hybrid Active Directory migrations involve complex routing, proxy setups, and security boundary configurations. While Entra Connect typically requires standard outbound HTTPS access, specific site-to-site VPN routing or ExpressRoute setups should be validated by hybrid identity experts.
Open a web browser and navigate to the official Microsoft Q&A portal specifically tagged for Entra ID (formerly Azure Active Directory).
Use the search function to look for existing threads regarding 'site-to-site VPN requirements for Entra Connect' that match your current firewall vendor.
If you cannot find an exact match, create a new post detailing your on-premises domain controller setup, planned VPN gateway, and synchronization goals so experts can provide tailored routing advice.
Equip Your Team with WPS Office During Migration
Enterprise infrastructure migrations are complex and costly. Ease your IT budget by switching to WPS Office—a lightweight, highly compatible, and free alternative to Microsoft Office that ensures your team remains productive without heavy license management.
- 1. Download the Enterprise Installer: Visit the official WPS Office website and download the installation package suitable for your operating system.
- 2. Deploy Across Your Network: Use your standard endpoint management tools to deploy the lightweight WPS Office package to your user devices.
- 3. Open Existing Documents: Double-click any existing Microsoft Word, Excel, or PowerPoint file to instantly open and edit it in WPS Office without formatting loss.

Frequently Asked Questions
Does Microsoft Entra Connect strictly require a site-to-site VPN?
No. A site-to-site VPN is not strictly mandatory for Entra Connect to function, provided the server hosting Entra Connect has outbound internet access over port 443 (HTTPS) to reach Microsoft cloud endpoints. However, a VPN or ExpressRoute might be enforced by your organization's internal security policies.
What network ports must be open for Microsoft Entra Connect?
Externally, the server requires outbound port 443 to communicate with Microsoft Entra ID. Internally, it requires ports like 389 (LDAP), 636 (LDAPS), 53 (DNS), and 88 (Kerberos) to communicate effectively with your on-premises domain controllers.
Can I use Azure ExpressRoute instead of a standard VPN?
Yes, Azure ExpressRoute is fully supported and often recommended for large enterprises. It provides a dedicated, private connection to Microsoft cloud services, offering greater reliability, faster speeds, and lower latencies than standard internet-based site-to-site VPNs.




