Fix Azure AD Connect Group Members From Multiple Domains Not Syncing
Question details
The user needs to resolve an issue where on-premises Active Directory groups containing users from multiple trusted domains do not sync all their members to Microsoft Entra ID.

- Product
- Azure AD Connect
- Device & OS
- not provided
- Scenario
- Synchronizing multi-domain group memberships to the cloud using Azure AD Connect.
- Observed behavior
- The group synchronizes to Microsoft Entra ID, but members originating from one or more of the trusted domains are missing or not visible in the cloud.
Verify that you have Domain Admin privileges in your on-premises Active Directory and Global Administrator access to Microsoft Entra ID before adjusting group scopes or synchronization rules.
Change the Active Directory Group Scope to Universal
Domain Local groups often fail to expose members from external trusted domains to Azure AD Connect. Changing the scope to Universal typically resolves this visibility issue.
In multi-domain environments, Azure AD Connect relies on the Global Catalog to read object attributes. Because Domain Local group memberships are not fully replicated to the Global Catalog across all domains, Azure AD Connect may only see a partial member list.
Log in to your Domain Controller, press Windows + R, type 'dsa.msc', and press Enter to launch Active Directory Users and Computers.
Locate the problematic group, right-click it, and select 'Properties'. Navigate to the 'General' tab.
Under the 'Group scope' section, select 'Universal' instead of 'Domain local'. Click 'Apply' and then 'OK' to save the changes.
Open PowerShell on your Azure AD Connect server and execute 'Start-ADSyncSyncCycle -PolicyType Delta' to push the updated group membership to Microsoft Entra ID.

Consult Microsoft Entra ID Community Specialists
If changing the group scope is restricted by your topology or does not resolve the issue, specialized connector configurations or filtering rules may be blocking the sync.
Document Your Active Directory Topology with WPS Office
While troubleshooting complex Azure AD Connect issues, you need reliable tools to manage your IT documentation, network diagrams, and synchronization logs. WPS Office is a lightweight, free alternative to Microsoft Office that helps you maintain your IT infrastructure records seamlessly.
- 1. Download the Installer: Visit the official WPS Office website and click the Free Download button.
- 2. Install WPS Office: Run the downloaded installer and follow the on-screen prompts to set up the suite on your computer.
- 3. Open Your IT Documents: Launch WPS Office and directly open your existing DOCX, XLSX, or PPTX documentation files with zero formatting loss.

Frequently Asked Questions
Why are cross-domain group members missing in Microsoft Entra ID?
This typically occurs when the on-premises group is set to the 'Domain Local' scope. Azure AD Connect relies on the Global Catalog, which does not store full membership details for Domain Local groups from external trusted domains.
How do I manually trigger an Azure AD Connect synchronization?
You can force a synchronization by opening PowerShell as an Administrator on your Azure AD Connect server and running the command: Start-ADSyncSyncCycle -PolicyType Delta.
Does Azure AD Connect support multi-forest environments?
Yes, Azure AD Connect can synchronize users and groups from multiple forests, provided the necessary trust relationships are established and the appropriate Active Directory connectors are configured in the Synchronization Service Manager.
Where can I view Azure AD Connect synchronization errors?
You can view detailed synchronization errors by opening the Synchronization Service Manager on your Azure AD Connect server and reviewing the operations tab for any failed steps.




