Events
Apr 9, 3 PM - Apr 10, 12 PM
Code the Future with AI and connect with Java peers and experts at JDConf 2025.
Register NowThis browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
If you have a single-forest topology and use password hash sync for authentication, express settings are a good option to use when you install Microsoft Entra Connect Sync. Express settings the default option to install Microsoft Entra Connect Sync, and it's used for the most commonly deployed scenario. It's only a few short steps to extend your on-premises directory to the cloud.
Before you start installing Microsoft Entra Connect Sync, download Microsoft Entra Connect Sync, and be sure to complete the prerequisite steps in Microsoft Entra Connect: Hardware and prerequisites.
If the express settings installation doesn't match your topology, see Related articles for information about other scenarios.
Transport Layer Security (TLS) protocol version 1.2 is a cryptography protocol that is designed to provide secure communications. The TLS protocol aims primarily to provide privacy and data integrity. TLS has gone through many iterations, with version 1.2 being defined in RFC 5246. The latest version of Microsoft Entra Connect Sync fully supports using only TLS 1.2 for communications with Microsoft Entra ID. Before installing the latest versions of Microsoft Entra Connect Sync, be sure to enable TLS 1.2.
For more information see TLS 1.2 enforcement for Microsoft Entra Connect Sync
FABRIKAM\administrator
or fabrikam.com\administrator
. Select Next.If you see this page, review each domain that's marked Not Added or Not Verified. Make sure that those domains have been verified in Microsoft Entra ID. When you've verified your domains, select the Refresh icon.
Optionally in Ready to configure, you can clear the Start the synchronization process as soon as configuration completes checkbox. You should clear this checkbox if you want to do more configurations, such as to add filtering. If you clear this option, the wizard configures sync but leaves the scheduler disabled. The scheduler doesn't run until you enable it manually by rerunning the installation wizard.
If you leave the Start the synchronization process when configuration completes checkbox selected, a full sync of all users, groups, and contacts to Microsoft Entra ID begins immediately.
If you have Exchange in your instance of Windows Server Active Directory, you also have the option to enable Exchange Hybrid deployment. Enable this option if you plan to have Exchange mailboxes both in the cloud and on-premises at the same time.
For more information about Microsoft Entra Connect Sync, see these articles:
Topic | Link |
---|---|
Microsoft Entra Connect Sync overview | Integrate your on-premises directories with Microsoft Entra ID |
Install by using customized settings | Custom installation of Microsoft Entra Connect Sync |
Upgrade from DirSync | Upgrade from Azure AD Sync tool (DirSync) |
Accounts used for installation | More about Microsoft Entra Connect Sync credentials and permissions |
Events
Apr 9, 3 PM - Apr 10, 12 PM
Code the Future with AI and connect with Java peers and experts at JDConf 2025.
Register NowTraining
Module
Implement directory synchronization tools - Training
This module examines the Microsoft Entra Connect Sync and Microsoft Entra Cloud Sync installation requirements, the options for installing and configuring the tools, and how to monitor synchronization services using Microsoft Entra Connect Health.
Certification
Microsoft Certified: Identity and Access Administrator Associate - Certifications
Demonstrate the features of Microsoft Entra ID to modernize identity solutions, implement hybrid solutions, and implement identity governance.