Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

3.4.1. Entra Connect Sync and Cloud Sync

💡 First Principle: A sync engine's job is faithful projection: read AD objects, filter to scope, map attributes, and write matching Entra objects — repeatedly and idempotently. The two engines differ in where the logic lives: Connect Sync computes on a beefy on-prem server you own; Cloud Sync moves the brain to Entra and leaves only lightweight agents on-prem.

Connect Sync (the veteran): full-featured — device writeback scenarios, group writeback (legacy), Exchange hybrid, complex multi-forest topologies, granular attribute filtering and custom sync rules, password writeback, staging-mode servers for failover. Costs: one heavyweight server (plus staging standby you fail over manually), upgrade burden on you.

Cloud Sync (the direction of travel): lightweight provisioning agents (multiple, auto-failover — HA by default), configuration in the portal, multi-forest-friendly including disconnected forests, faster setup, supports password hash sync and password writeback (agent-based). Gaps to memorize: no device writeback, no Exchange hybrid writeback, limited filtering (OU/group-based; no attribute-value filters or custom rules), no passthrough of some complex scenarios. The two can coexist — different domains/forests served by different engines — a common migration posture.

Decision tells: "disconnected forest / merger, sync quickly with minimal infrastructure" → Cloud Sync; "device writeback / Exchange hybrid / custom sync rules" → Connect Sync; "high availability for sync without standby servers" → Cloud Sync agents. Shared concepts either way: source anchor immutably links AD and Entra objects; soft match / hard match reconnects existing cloud users to synced identities; scoping filters keep service accounts and privileged AD accounts out of sync (never sync your break-glass or Tier-0 accounts).

⚠️ Exam Trap: Cloud Sync's agent model gives HA automatically; Connect Sync's answer to HA is a staging mode second server requiring manual switchover. If the stem demands "no single point of failure with least effort," Cloud Sync is being fished for.

Reflection Question: Your org acquires a company whose AD forest has no network trust with yours, and needs their users in your tenant within a week. Which engine, and which three features of it make it the fit?

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications