logo
search
Microsoft 365 Migration

VPN Requirements for Migrating Active Directory to Hybrid Identity

Maira MehtabMaira Mehtab Sep 27, 2026 869 views

Question details

The user needs to understand the site-to-site VPN requirements and connectivity prerequisites for connecting an on-premises Active Directory with Microsoft Entra ID using Microsoft Entra Connect.

Product
Microsoft Entra ID
Device & OS
not provided
Scenario
Migrating on-premises Active Directory to a Hybrid Identity environment.
Observed behavior
Seeking proper network configurations to ensure secure and successful synchronization between local domain controllers and cloud identity services.
Before you start

Before configuring your network for hybrid identity, ensure you have global administrator access to your Microsoft Entra ID portal and enterprise administrator rights in your local Active Directory.

Solution 1Recommended

Consult the Microsoft Entra ID Q&A Community for Network Topology

Because site-to-site VPN and synchronization requirements vary heavily based on enterprise firewall rules and network topologies, Microsoft's dedicated Entra ID community is the best resource for exact configurations.

Hybrid Active Directory migrations involve complex routing, proxy setups, and security boundary configurations. While Entra Connect typically requires standard outbound HTTPS access, specific site-to-site VPN routing or ExpressRoute setups should be validated by hybrid identity experts.

1
Access the Microsoft Entra ID Q&A portal

Open a web browser and navigate to the official Microsoft Q&A portal specifically tagged for Entra ID (formerly Azure Active Directory).

2
Search for specific VPN topologies

Use the search function to look for existing threads regarding 'site-to-site VPN requirements for Entra Connect' that match your current firewall vendor.

3
Post your environment details

If you cannot find an exact match, create a new post detailing your on-premises domain controller setup, planned VPN gateway, and synchronization goals so experts can provide tailored routing advice.

Free Microsoft Office alternative

Equip Your Team with WPS Office During Migration

Enterprise infrastructure migrations are complex and costly. Ease your IT budget by switching to WPS Office—a lightweight, highly compatible, and free alternative to Microsoft Office that ensures your team remains productive without heavy license management.

  1. 1. Download the Enterprise Installer: Visit the official WPS Office website and download the installation package suitable for your operating system.
  2. 2. Deploy Across Your Network: Use your standard endpoint management tools to deploy the lightweight WPS Office package to your user devices.
  3. 3. Open Existing Documents: Double-click any existing Microsoft Word, Excel, or PowerPoint file to instantly open and edit it in WPS Office without formatting loss.
Fully compatible with Microsoft Office formats including .docx, .xlsx, and .pptx.Lightweight deployment that won't strain your enterprise network or VPN bandwidth.Familiar user interface that requires zero additional training for your staff.
microsoft office alternative - wps office

Frequently Asked Questions

Does Microsoft Entra Connect strictly require a site-to-site VPN?

No. A site-to-site VPN is not strictly mandatory for Entra Connect to function, provided the server hosting Entra Connect has outbound internet access over port 443 (HTTPS) to reach Microsoft cloud endpoints. However, a VPN or ExpressRoute might be enforced by your organization's internal security policies.

What network ports must be open for Microsoft Entra Connect?

Externally, the server requires outbound port 443 to communicate with Microsoft Entra ID. Internally, it requires ports like 389 (LDAP), 636 (LDAPS), 53 (DNS), and 88 (Kerberos) to communicate effectively with your on-premises domain controllers.

Can I use Azure ExpressRoute instead of a standard VPN?

Yes, Azure ExpressRoute is fully supported and often recommended for large enterprises. It provides a dedicated, private connection to Microsoft cloud services, offering greater reliability, faster speeds, and lower latencies than standard internet-based site-to-site VPNs.