Microsoft Entra Connect
Microsoft Entra Connect is an on-premises Microsoft application that links an organization's local Active Directory with Microsoft Entra ID (Microsoft's cloud identity service). It synchronizes identity information between the two so that users and their accounts can be recognized consistently across on-premises and cloud environments. This helps organizations achieve what Microsoft calls hybrid identity goals.
Microsoft Entra Connect is an on-premises Microsoft application that integrates on-premises Active Directory with Microsoft Entra ID to support hybrid identity scenarios. It acts as a synchronization bridge that provisions and reconciles identity data between the on-premises directory and Entra ID; the specific synchronization behavior, authentication options, and installation paths depend on how the tool is configured and installed. According to the evidence, it is deployed and installed on-premises, with installation options documented in Microsoft's Entra Connect installation roadmap. The evidence does not detail the specific protocols, sync engine internals, or authentication methods (for example, password hash synchronization versus pass-through authentication), so those aspects are out of scope for this definition.
Why it matters
Most enterprises that adopt Microsoft's cloud identity service do not start from a clean slate; they operate an existing on-premises Active Directory that already governs employee accounts, groups, and access. Microsoft Entra Connect matters because it is the component that reconciles these two worlds, allowing the same user identities to be recognized consistently across on-premises and cloud environments. Without such a synchronization bridge, organizations would face duplicate identities, inconsistent account states, and manual reconciliation between directories, which increases both administrative burden and the risk of orphaned or mismatched accounts.
Because Entra Connect sits at the boundary between on-premises Active Directory and Entra ID and moves identity data between them, it is a high-value part of the identity infrastructure. Its configuration determines how identity information flows across environments, which makes correct installation and ongoing operation an important concern for security architects and administrators. The evidence does not detail specific authentication methods or sync engine internals, so claims about particular security properties or failure modes tied to those mechanisms are out of scope here; teams should evaluate them against Microsoft's own documentation for their chosen configuration.
For identity governance and operational teams, the practical significance is that Entra Connect underpins hybrid identity scenarios, the coexistence of directory-based on-premises identity and cloud identity. Any organization pursuing what Microsoft calls hybrid identity goals typically depends on this tool functioning correctly, and changes to its configuration can have broad downstream effects on which accounts exist and how they are represented in the cloud.
Who it's relevant to
Inside Microsoft Entra Connect
Common questions
Answers to the questions practitioners most commonly ask about Microsoft Entra Connect.
