You want to sync your on-premises Active Directory with Microsoft Entra. But don’t want to keep the software up to date on-premises and want the cloud to do the work. An excellent tool to accomplish this is to use the Microsoft Entra Cloud Sync. In this article, you will learn how to install and configure Microsoft Entra Cloud Sync.
Table of contents
- What is Microsoft Entra Cloud Sync
- Prerequisites for Microsoft Entra Cloud Sync
- Step 1. Download the Cloud Sync Agent
- Step 2. Install Provisioning Agent on Windows Server
- Step 3. Verify Provisioning Agent status
- Step 4. Set up Microsoft Entra Cloud configuration
- Step 5. Enable Password Writeback
- Step 6. Check Microsoft Entra Cloud Sync logs
- Conclusion
What is Microsoft Entra Cloud Sync
Microsoft Entra Cloud Sync is a lightweight and modern identity synchronization tool designed to enable hybrid identity scenarios. It allows you to sync on-premises Active Directory (AD) users, groups, and contacts to Microsoft Entra ID without the overhead of Microsoft Entra Connect.
This solution is ideal when:
- You have multiple Active Directory forests.
- You want to simplify high availability deployments.
- You need to avoid complex on-prem infrastructure.
- You want faster and more reliable sync with Microsoft Entra ID.
Microsoft Entra Cloud Sync uses a cloud provisioning agent that runs on a Windows Server machine in your on-premises environment. Unlike Microsoft Entra Connect, it offloads most of the sync logic to the cloud, which simplifies management and scaling.
Prerequisites for Microsoft Entra Cloud Sync
Before proceeding, make sure you have:
- A Microsoft Entra ID tenant.
- An Entra ID Global Administrator account for initial setup.
- At least one Windows Server 2016 or later machine (domain-joined) to host the provisioning agent.
- Necessary firewall ports open: HTTPS (443) and HTTP (80) to Microsoft cloud endpoints.
- Proper DNS resolution from the server to your domain controllers and to external internet.
Step 1. Download the Cloud Sync Agent
- Sign in to the Microsoft Entra admin center.
- Navigate to Identity > Show more


- Select Hybrid management > Microsoft Entra Connect
- Click on Cloud Sync


- Select Agents
- Click on Download on-premises agent


- Click on Accept terms & download
- Save the executable file to your Windows Server machine


Step 2. Install Provisioning Agent on Windows Server
- Start File Explorer
- Go to the downloaded Provisioning Agent setup executable file
- Run the downloaded Microsoft Entra Connect Provisioning Agent installer as Administrator


- Accept the license terms and conditions
- Click Install


- The setup starts installing the Microsoft Entra Provisioning Agent


- Click Next in the Welcome to the Microsoft Entra provisioning agent configuration wizard screen


- Select HR-driven provisioning (Workday and SuccessFactors) / Microsoft Entra Cloud Sync
- Click Next


- Click Authenticate
- Sign in with your Microsoft Entra ID administrator credentials


- Select Create gSMA
- Enter your On-Premises domain admin credentials
- Click Next


- Click Next


- Click Confirm


- Click Exit


Step 3. Verify Provisioning Agent status
- Sign in to the Microsoft Entra admin center
- Click Agents and verify that the machine name appears and the status is Active


- Start Windows Services
- Verify that the Microsoft Azure AD Connect Provisioning Agent service is running


- Start Active Directory Users and Computers
- Navigate to Domain (exoip.local) > Managed Service Accounts
- Verify that the provAgentgMSA service account appears


Step 4. Set up Microsoft Entra Cloud configuration
- Sign in to Microsoft Entra admin center
- Click on Configurations
- Select + New configuration > AD to Microsoft Entra ID sync


- Select the Active Directory domain
- Check the checkbox for Enable password hash sync
- Click Create


- Click Overview
- Select Properties
- Click on the pencil icon to edit the Basics


- Configure the basics:
- Enable password hash sync
- Enable Exchange hybrid writeback
- Add email address for notifications
- Enable prevent accidental deletion
- Set accidental deletion treshold to 500
- Select Apply


- Click Scoping filters
- Select Selected organizational units
- Fill in the distinguished name of the on-premises OU that you want to sync with Microsoft Entra ID
- Click Add
- Click Save


- Click Overview
- Click Review and enable


- Click Enable configuration
Note: Cloud provisioning is scheduled to run every 2 mins. Every 2 mins, any user, group, and password hash changes are provisioned to Microsoft Entra ID.


- Verify that the configuration sync from AD to Microsoft Entra ID shows the status Healthy


Step 5. Enable Password Writeback
Allow password changes in Microsoft Entra ID to sync back to On-Premises AD by following the steps below:
- Sign in to the Microsoft Entra admin center
- Go to Protection > Password reset > On-premises integration
- Turn on:
- Enable password write back for synced users
- Write back passwords with Microsoft Entra Connect cloud sync
- Allow users to unlock accounts with resetting their password
- Click Save


Step 6. Check Microsoft Entra Cloud Sync logs
- Sign in to the Microsoft Entra admin center
- Select Provisioning logs


- Sign in to your Windows Server
- Check the logs stored locally on the server where the agent is installed:
C:\ProgramData\Microsoft Entra Connect Provisioning Agent\Logs
That’s it!
Read more: How to check Microsoft Entra Connect version »
Conclusion
You learned how to install and configure Microsoft Entra Cloud Sync. It’s an excellent choice for organizations that want hybrid identity management with minimal overhead. It offers a complete yet lightweight solution for syncing on-premises objects to the cloud.
Did you enjoy this article? You may also like Conditional Access MFA breaks Azure AD Connect synchronization. Don’t forget to follow us and share this article.