Azure AD Connect: Next steps and how to manage Azure AD Connect - Microsoft Entra (2023)

  • Article
  • 2 minutes to read

Use the operational procedures in this article to customize Azure Active Directory (Azure AD) Connect to meet your organization's needs and requirements.

Add additional sync admins

By default, only the user who did the installation and local admins are able to manage the installed sync engine. For additional people to be able to access and manage the sync engine, locate the group named ADSyncAdmins on the local server and add them to this group.

Assign licenses to Azure AD Premium and Enterprise Mobility Suite users

Now that your users have been synchronized to the cloud, you need to assign them a license so they can get going with cloud apps such as Microsoft 365.

To assign an Azure AD Premium or Enterprise Mobility Suite License

  1. Sign in to the Azure portal as an admin.
  2. On the left, select Active Directory.
  3. On the Active Directory page, double-click the directory that has the users you want to set up.
  4. At the top of the directory page, select Licenses.
  5. On the Licenses page, select Active Directory Premium or Enterprise Mobility Suite, and then click Assign.
  6. In the dialog box, select the users you want to assign licenses to, and then click the check mark icon to save the changes.

Verify the scheduled synchronization task

Use the Azure portal to check the status of a synchronization.

To verify the scheduled synchronization task

  1. Sign in to the Azure portal as an admin.
  2. On the left, select Active Directory.
  3. On the left, select Azure AD Connect
  4. At the top of the page, note the last synchronization.

Azure AD Connect: Next steps and how to manage Azure AD Connect - Microsoft Entra (1)

Start a scheduled synchronization task

If you need to run a synchronization task, you can do this by:

  1. Double-click on the Azure AD Connect desktop shortcut to start the wizard.
  2. Click Configure.
  3. On the tasks screen, select the Customize synchronization options and click Next
  4. Enter your Azure AD credentials
  5. Click Next. Click Next. Click Next.
  6. On the Ready to Configure screen, ensure that the Start the synchronization process when configuration completes box is selected.
  7. Click Configure.

For more information on the Azure AD Connect sync Scheduler, see Azure AD Connect Scheduler.

Additional tasks available in Azure AD Connect

After your initial installation of Azure AD Connect, you can always start the wizard again from the Azure AD Connect start page or desktop shortcut. You will notice that going through the wizard again provides some new options in the form of additional tasks.

The following table provides a summary of these tasks and a brief description of each task.

Azure AD Connect: Next steps and how to manage Azure AD Connect - Microsoft Entra (2)

Additional taskDescription
Privacy SettingsView what telemetry data is being shared with Microsoft.
View current configurationView your current Azure AD Connect solution. This includes general settings, synchronized directories, and sync settings.
Customize synchronization optionsChange the current configuration like adding additional Active Directory forests to the configuration, or enabling sync options such as user, group, device, or password write-back.
Configure device optionsDevice options available for synchronization
Refresh directory schemaAllows you to add new on-premises directory objects for synchronization
Configure Staging ModeStage information that is not immediately synchronized and is not exported to Azure AD or on-premises Active Directory. With this feature, you can preview the synchronizations before they occur.
Change user sign-inChange the authentication method users are using to sign-in
Manage federationManage your AD FS infrastructure, renew certificates, and add AD FS servers
TroubleshootHelp with troubleshooting Azure AD Connect issues

Next steps

Learn more about integrating your on-premises identities with Azure Active Directory.


How do I manage Azure AD Connect? ›

Start a scheduled synchronization task

Double-click on the Azure AD Connect desktop shortcut to start the wizard. Click Configure. On the tasks screen, select the Customize synchronization options and click Next. Enter your Azure AD credentials.

Which actions can you perform with Microsoft Azure Active Directory Connect? ›

Microsoft AAD Connect can connect to multiple on-premises forests and can exchange organizations and synchronized the customer defined attributes but cannot use Forefront Identity Management synchronization rules. It takes care of all management processes and describes the configuration model.

How many instances of Azure AD Connect are needed? ›

Azure AD Connect supports syncing from multiple forests. However, it supports only one instance of Azure AD Connect syncing to AAD. Therefore, in cases where Azure AD is already installed in one forest, the existing instance of AAD Connect must be updated to sync from the additional forest.

What are the three primary components of Azure Active Directory ad connect? ›

Azure Active Directory Connect is made up of three primary components: the synchronization services, the optional Active Directory Federation Services component, and the monitoring component named Azure AD Connect Health.

What is Azure AD Connect and how it works? ›

Azure Active Directory (Azure AD) Connect Health provides robust monitoring of your on-premises identity infrastructure. It enables you to maintain a reliable connection to Microsoft 365 and Microsoft Online Services. This reliability is achieved by providing monitoring capabilities for your key identity components.

How do I connect Active Directory to Azure Active Directory? ›

Connect your organization to Azure AD
  1. Select. ...
  2. Select Azure Active Directory, and then select Connect directory.
  3. Select a directory from the dropdown menu, and then select Connect. ...
  4. Select Sign out. ...
  5. Confirm that the process is complete.
Oct 4, 2022

What are the two types of data movement to Microsoft Azure? ›

The data movement can be of the following types: Offline transfer using shippable devices - Use physical shippable devices when you want to do offline one-time bulk data transfer.

Does Azure AD Connect need domain admin? ›

AD DS Enterprise Admin credentials

If you are upgrading from DirSync, the AD DS Enterprise Admins credentials are used to reset the password for the account used by DirSync. You also need Azure AD Global Administrator credentials.

What are the different types of Azure AD Connect? ›

Azure AD Connect has two installation types for new installation: Express and customized. This topic helps you to decide which option to use during installation.

Can you have 2 Azure AD Connect server? ›

Having multiple Azure AD Connect sync servers connected to the same Azure AD tenant is not supported, except for a staging server. It's unsupported even if these servers are configured to synchronize with a mutually exclusive set of objects.

How many Azure AD Connect can you have? ›

There should only be one active Azure AD Connect sync server at any time.

What is the limit of Azure AD Connect? ›

By default, the number of members in a group that you can synchronize from your on-premises Active Directory to Azure Active Directory by using Azure AD Connect is limited to 50,000 members.

What are the 4 most important benefits of Active Directory? ›

Advantages and Benefits of Active Directory

Centralized resources and security administration. Single logon for access to global resources. Simplified resource location.

What are the 3 main identity types used in Azure AD? ›

- [Instructor] The exam may test your knowledge of the identity types available in Azure Active Directory. And for the exam, there are four different identity types that you'll want to be familiar with: the user, service principle, managed identity, and device.

What is the difference between AD Sync and AD Connect? ›

Azure AD Connect Cloud Sync is the preferred way to synchronize on-premises AD to Azure AD, assuming you can get by with its limitations. Azure AD Connect provides the most feature-rich synchronization capabilities, including Exchange hybrid support.

What are the two primary components Azure AD Connect is made up of? ›

The sync service consists of two components, the on-premises Azure AD Connect sync component and the service side in Azure AD called Azure AD Connect sync service.

What are the benefits of Azure AD Connect? ›

Key benefits of using Azure AD Pass-through Authentication
  • Great user experience. Users use the same passwords to sign into both on-premises and cloud-based applications. ...
  • Easy to deploy & administer. No need for complex on-premises deployments or network configuration. ...
  • Secure. ...
  • Highly available.
Jan 26, 2023

How does Azure AD Connect work with Office 365? ›

If you have a paid subscription to Microsoft 365, you also have a free Azure AD subscription. You can use Azure AD to create and manage user and group accounts. To activate this subscription, you have to complete a one-time registration. Afterward, you can access Azure AD from your Microsoft 365 admin center.

How to synchronize users from Active Directory to Azure AD? ›

To open Synchronization Service Manager, go to Start menu and type Synchronization Service. It should appear under the Azure AD Connect. In the Synchronization Service Manager console, under Operations tab, you can monitor the synchronization progress.

How do I connect my local domain to my Azure AD? ›

Add your custom domain name to Azure AD

After you create your directory, you can add your custom domain name. Sign in to the Azure portal using a Global administrator account for the directory. Search for and select Azure Active Directory from any page. Then select Custom domain names > Add custom domain.

How do I enable SSO in Azure AD Connect? ›

Sign in to the Azure Active Directory administrative center with the Hybrid Identity Administrator or hybrid identity administrator credentials for your tenant. Select Azure Active Directory in the left pane. Select Azure AD Connect. Verify that the Seamless single sign-on feature appears as Enabled.

What are two Azure management tools? ›

In addition to the graphical user interface offered at the Azure Portal, we have the ability to manage and interact with Azure via Azure Powershell, Azure Command Line Interface (CLI), Azure Cloud Shell, and the Azure Mobile Application available on iOS and Android platforms.

What are the three types of role basic access controls in Microsoft Azure? ›

The way you control access to resources using Azure RBAC is to assign Azure roles. This is a key concept to understand – it's how permissions are enforced. A role assignment consists of three elements: security principal, role definition, and scope.

What are the 3 deployment modes that can be used for Azure? ›

Azure supports three approaches to deploying cloud resources - public, private, and the hybrid cloud.

Does Azure AD Connect require SQL Server? ›

Azure AD Connect requires a SQL Server database to store identity data. By default, a SQL Server 2019 Express LocalDB (a light version of SQL Server Express) is installed. SQL Server Express has a 10-GB size limit that enables you to manage approximately 100,000 objects.

Does Azure AD Connect need a VPN? ›

Azure AD authentication is supported only for OpenVPN® protocol connections and requires the Azure VPN Client.

Do I need a domain controller if I have Azure AD? ›

Azure Active Directory Domain Services (Azure AD DS), part of Microsoft Entra, enables you to use managed domain services—such as Windows Domain Join, group policy, LDAP, and Kerberos authentication—without having to deploy, manage, or patch domain controllers.

What is the newest version of Azure AD Connect? ›

Looking for the latest versions? You can upgrade your Azure AD Connect server from all supported versions with the latest versions: You can download the latest version of Azure AD Connect 2.0 from the Microsoft Download Center.

Does Azure AD Connect update automatically? ›

Azure AD Connect automatic upgrade is a feature that regularly checks for newer versions of Azure AD Connect. If your server is enabled for automatic upgrade and a newer version is found for which your server is eligible, it will perform an automatic upgrade to that newer version.

How do I sync multiple domains to Azure AD? ›

Use the following steps to add the new top-level domain using Azure AD Connect.
  1. Launch Azure AD Connect from the desktop or start menu.
  2. Choose “Add an additional Azure AD Domain”
  3. Enter your Azure AD and Active Directory credentials.
  4. Select the second domain you wish to configure for federation.
  5. Click Install.
Jan 26, 2023

Can Azure AD have multiple domains? ›

Yes, you can sync users from multiple domains, in multiple forests to single Azure AD tenant. When you have multiple forests, all forests must be reachable by a single Azure AD Connect sync server.

Can I have 2 domain controllers on the same domain? ›

We can have many domain controllers in same domain. Do you have two domain controllers on same domaine or two domain using the same name? If you have two domain controllers in same domain, you don't need to migrate objects , because all domain controllers in same domain share the same objects.

Is Azure AD Connect a one way sync? ›

The synchronization process is one way / unidirectional by design. There's no reverse synchronization of changes from Azure AD DS back to Azure AD.

Does Azure AD Connect require a license? ›

No licensing is needed to install AAD Connect and get all your AD users and groups syncing with AAD.

Can one ad have multiple tenants? ›

A directory can have many subscriptions associated with it, but only one tenant.

What service account is used by Azure AD Connect? ›

It can run under a Virtual Service Account (VSA), a Managed Service Account (gMSA/sMSA), or a regular User Account. The supported options were changed with the 2017 April release and 2021 March release of Azure AD Connect when you do a fresh installation.

How do you get 99.99 Availability in Azure? ›

We guarantee that Azure Firewall will be available at least 99.95% of the time, when deployed within a single Availability Zone. We guarantee that Azure Firewall will be available at least 99.99% of the time, when deployed within two or more Availability Zones in the same Azure region.

How many objects will be allowed in your Azure AD instance? ›

The object limit for Azure AD Free version is by default 50,000. If you add a custom domain to your Azure AD tenant, this limit is extended to 300,000 automatically.

What is the maximum number of users in Active Directory? ›

Users, groups, and computer accounts (security principals) can be members of a maximum of approximately 1,015 groups.

What are the 3 basic Active Directory roles? ›

Active Directory has five FSMO roles:
  • Schema Master.
  • Domain Naming Master.
  • Infrastructure Master.
  • Relative ID (RID) Master.
  • PDC Emulator.
Nov 30, 2021

What are the 3 main components of an Active Directory? ›

AD has three main tiers: domains, trees and forests. A domain is a group of related users, computers and other AD objects, such as all the AD objects for your company's head office. Multiple domains can be combined into a tree, and multiple trees can be grouped into a forest.

What are the three main features of Active Directory? ›

The Active Directory structure is comprised of three main components: domains, trees, and forests. Several objects, like users or devices that use the same AD database, can be grouped into a single domain. Domains have a domain name system (DNS) structure.

How many types of authentication methods are there in Azure AD connect? ›

With cloud authentication, you can choose from two options: Azure AD password hash synchronization. The simplest way to enable authentication for on-premises directory objects in Azure AD. Users can use the same username and password that they use on-premises without having to deploy any additional infrastructure.

How many types of authentication are there in Active Directory? ›

AD Authentication and LAPD

The simple authentication method involves three approaches: anonymous authentication, unauthenticated authentication, and name/password authentication.

Does ad connect use LDAP? ›

Custom Connector: A Generic LDAP Connector enables you to integrate the Azure AD Connect synchronization service with an LDAP v3 server. It sits on Azure AD Connect. Active Directory: Active Directory is a directory service included in most Windows Server operating systems.

What are the types of ad connect? ›

Azure AD Connect has two installation types for new installation: Express and customized. This topic helps you to decide which option to use during installation.

Does ad connect need global admin? ›

The Global Administrator role is not required after the initial setup and the only required account will be the Directory Synchronization Accounts role account.

How do I open Azure AD Connect Sync service manager? ›

To open Synchronization Service Manager, go to Start menu and type Synchronization Service. It should appear under the Azure AD Connect. In the Synchronization Service Manager console, under Operations tab, you can monitor the synchronization progress.

How do I check my Azure AD Connect service account? ›

The user name shows the Azure AD Connector account. Another way to check the Azure AD Connector account is to sign in to Microsoft 365 admin center. Navigate to Health > Directory sync status. The Directory sync service account shows the Azure AD Connector account.

How do I update Azure Active Directory connect? ›

If you want to install a newer version of Azure AD Connect: close the Azure AD Connect wizard, uninstall the existing Azure AD Connect, and perform a clean install of the newer Azure AD Connect.

What is the difference between Azure AD Connect and Azure AD Sync? ›

Azure AD Connect Cloud Sync has many of the same features and capabilities as Azure AD Connect with the following differences: Lightweight agent installation model. Adds high availability using multiple agents. Synchronizes directory changes more frequently than Azure AD Connect.

How do you check if Azure AD Connect is syncing? ›

Verifying Azure AD Connect in the Azure AD Admin Center

First, log in to the portal. Then, go to Azure Active Directory —> Azure AD Connect. Under the Azure AD Connect sync section, you should see the current status of the directory sync.

What is the difference between full sync and Delta Sync in Azure AD Connect? ›

A full sync checks all objects across AD. A delta sync only checks and syncs changes since the last run. To start a full sync, you can use the Start-AdSyncSyncCycle cmdlet. Use the PolicyType parameter to choose either Full or Delta depending on the sync you'd like to initiate.

How many Azure AD Connect servers are there? ›

There should only be one active Azure AD Connect sync server at any time.

Where is Azure AD Connect configuration stored? ›

Export Azure AD Connect settings

By default, the settings are exported to %ProgramData%\AADConnect. You also can choose to save the settings to a protected location to ensure availability if a disaster occurs.

How do I verify ad connect? ›

To verify this, follow these steps:
  1. Step 1: Determine whether automatic upgrade recently tried to upgrade Azure AD Connect. ...
  2. Step 2: Determine whether Azure AD Connect is partially upgraded. ...
  3. Step 3: Compare the installed version of Azure AD Connect with the version in the server configuration.
Apr 20, 2022

How do I fix my Azure AD sync problem? ›

Start the Azure AD Connect wizard. Navigate to the Additional Tasks page, select Troubleshoot, and click Next. On the Troubleshooting page, click Launch to start the troubleshooting menu in PowerShell. In the main menu, select Troubleshoot Object Synchronization.

How do I fix Azure AD Connect sync errors? ›

To resolve this issue:
  1. Remove the Azure AD account (owner) from all admin roles.
  2. Hard delete the quarantined object in the cloud.
  3. The next sync cycle will take care of soft-matching the on-premises user to the cloud account because the cloud user is now no longer a Hybrid Identity Administrator.
Jan 19, 2023


Top Articles
Latest Posts
Article information

Author: Edmund Hettinger DC

Last Updated: 08/10/2023

Views: 6511

Rating: 4.8 / 5 (58 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Edmund Hettinger DC

Birthday: 1994-08-17

Address: 2033 Gerhold Pine, Port Jocelyn, VA 12101-5654

Phone: +8524399971620

Job: Central Manufacturing Supervisor

Hobby: Jogging, Metalworking, Tai chi, Shopping, Puzzles, Rock climbing, Crocheting

Introduction: My name is Edmund Hettinger DC, I am a adventurous, colorful, gifted, determined, precious, open, colorful person who loves writing and wants to share my knowledge and understanding with you.