Edit

Share via


Hardening update to Microsoft Entra Connect Sync

As part of increasing the security posture of Microsoft Entra Connect, Microsoft deployed a dedicated first-party application to enable the synchronization between Active Directory and Microsoft Entra ID. This new application will manifest as a first party service principal called the "Microsoft Entra AD Synchronization Service" (Application Id: 6bf85cfa-ac8a-4be5-b5de-425a0d0dc016) and will be visible in the Enterprise Applications experience within the Microsoft Entra admin center. This application is critical for the continued operation of on-premises to Microsoft Entra ID synchronization functionality through Entra Connect.

We have since released a new version (2.5.79.0) of Microsoft Entra Connect that contains this service change. All customers are required to upgrade to the minimum versions by September 30, 2026 to avoid service disruptions.

Expected impacts

If you aren’t upgraded to the minimum required version (2.5.79.0), you might encounter the following impact to the Microsoft Entra Connect Sync service when the service change takes effect:

All synchronization services in Microsoft Entra Connect Sync will fail.

Note

If you’re unable to upgrade by the deadline, you can restore the impacted functionalities by upgrading to the latest version. However, all synchronization services will fail during the period between September 30, 2026, and when you upgrade.

Minimum versions

To avoid any service impact, customers should be on the following version by September 30, 2026:

Version 2.5.79.0 or higher.

The Microsoft Entra Connect Sync .msi installation file for this version is exclusively available on Microsoft Entra Admin Center under Microsoft Entra Connect.

Important

Make sure you familiarize yourself with the minimum requirements for the versions, including but not limited to:

To assist customers with the upgrade process, we occasionally auto upgrade customers where supported. If you would like to be auto upgraded, ensure you have the auto upgrade feature configured. For auto upgrade to work, you should be on version 2.3.20.0 or higher.

Consider moving to Microsoft Entra Cloud Sync

If you're eligible, we recommend migrating from Microsoft Entra Connect Sync to Microsoft Entra Cloud Sync. Microsoft Entra Cloud Sync is the new sync client that works from the cloud and allows customers to set up and manage their sync preferences online. We recommend that you use Cloud Sync because we're introducing new features that improve the sync experiences through Cloud Sync. You can avoid future migrations by choosing Cloud Sync if that's the right option for you. Use the https://aka.ms/EvaluateSyncOptions to see if Cloud Sync is the right sync client for you.

See the following video to understand how Cloud sync provides value to your business.

For more information, see What is cloud sync?

Upgrading Microsoft Entra Connect Sync

If you aren't yet eligible to move to Cloud Sync, use this table for more information on upgrading.

Title Description
Upgrading from a previous version Information on moving from one version of Microsoft Entra Connect to another
Information on deprecation Information on using a deprecated or unsupported version of Microsoft Entra Connect (some information is applicable to versions that are impacted by a service change)

Next steps