logo
search
Others

Fix Azure AD Connect Group Members From Multiple Domains Not Syncing

Partner EditorPartner Editor Sep 30, 2026 868 views

Question details

The user needs to resolve an issue where on-premises Active Directory groups containing users from multiple trusted domains do not sync all their members to Microsoft Entra ID.

Fix Azure AD Connect Group Members From Multiple Domains Not Syncing
Product
Azure AD Connect
Device & OS
not provided
Scenario
Synchronizing multi-domain group memberships to the cloud using Azure AD Connect.
Observed behavior
The group synchronizes to Microsoft Entra ID, but members originating from one or more of the trusted domains are missing or not visible in the cloud.
Before you start

Verify that you have Domain Admin privileges in your on-premises Active Directory and Global Administrator access to Microsoft Entra ID before adjusting group scopes or synchronization rules.

Solution 1Recommended

Change the Active Directory Group Scope to Universal

Domain Local groups often fail to expose members from external trusted domains to Azure AD Connect. Changing the scope to Universal typically resolves this visibility issue.

In multi-domain environments, Azure AD Connect relies on the Global Catalog to read object attributes. Because Domain Local group memberships are not fully replicated to the Global Catalog across all domains, Azure AD Connect may only see a partial member list.

1
Open Active Directory Users and Computers

Log in to your Domain Controller, press Windows + R, type 'dsa.msc', and press Enter to launch Active Directory Users and Computers.

2
Modify Group Properties

Locate the problematic group, right-click it, and select 'Properties'. Navigate to the 'General' tab.

3
Change Scope to Universal

Under the 'Group scope' section, select 'Universal' instead of 'Domain local'. Click 'Apply' and then 'OK' to save the changes.

4
Force a Delta Synchronization

Open PowerShell on your Azure AD Connect server and execute 'Start-ADSyncSyncCycle -PolicyType Delta' to push the updated group membership to Microsoft Entra ID.

Change the Active Directory Group Scope to Universal
Configuration Review: Review your AD replication design before making this change, as Universal groups replicate their memberships to the Global Catalog and may increase replication traffic in large forests.
Free Microsoft Office alternative

Document Your Active Directory Topology with WPS Office

While troubleshooting complex Azure AD Connect issues, you need reliable tools to manage your IT documentation, network diagrams, and synchronization logs. WPS Office is a lightweight, free alternative to Microsoft Office that helps you maintain your IT infrastructure records seamlessly.

  1. 1. Download the Installer: Visit the official WPS Office website and click the Free Download button.
  2. 2. Install WPS Office: Run the downloaded installer and follow the on-screen prompts to set up the suite on your computer.
  3. 3. Open Your IT Documents: Launch WPS Office and directly open your existing DOCX, XLSX, or PPTX documentation files with zero formatting loss.
Keep detailed Active Directory troubleshooting logs organized in a lightweight interfaceFully compatible with Microsoft Word, Excel, and PowerPoint formatsCreate professional IT documentation and network topology diagrams easilyFree, fast-loading office suite with a familiar user interface for seamless migration
microsoft office alternative - wps office

Frequently Asked Questions

Why are cross-domain group members missing in Microsoft Entra ID?

This typically occurs when the on-premises group is set to the 'Domain Local' scope. Azure AD Connect relies on the Global Catalog, which does not store full membership details for Domain Local groups from external trusted domains.

How do I manually trigger an Azure AD Connect synchronization?

You can force a synchronization by opening PowerShell as an Administrator on your Azure AD Connect server and running the command: Start-ADSyncSyncCycle -PolicyType Delta.

Does Azure AD Connect support multi-forest environments?

Yes, Azure AD Connect can synchronize users and groups from multiple forests, provided the necessary trust relationships are established and the appropriate Active Directory connectors are configured in the Synchronization Service Manager.

Where can I view Azure AD Connect synchronization errors?

You can view detailed synchronization errors by opening the Synchronization Service Manager on your Azure AD Connect server and reviewing the operations tab for any failed steps.