How many server Microsoft Entra connect can be added in the forest

Ahmed Essam 80 Reputation points
2023-12-05T08:25:22.5933333+00:00

Hello,

We've one root domain with azure ad connect to sync users to MS tenant, and other child domain with no ad sync.

we need to add staging server in the root domain for high availability, and one active server in the root domain, and all three servers will connect using the same global admin account.

does the above scenario will works and supported? or there is another scenario whats the best practice.

Thanks,

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,506 questions
0 comments No comments
{count} votes

Accepted answer
  1. Akshay-MSFT 17,651 Reputation points Microsoft Employee
    2023-12-05T09:43:26.57+00:00

    @Ahmed Essam

    Thank you for posting your query on Microsoft Q&A, from above description I could understand that you are looking for advisory on supported scenario for multiple Entra ID connect in single domain environment.

    Please do correct me if this is not the case by responding in the comments section.

    As per Single forest, multiple sync servers to one Microsoft Entra tenant, having multiple Microsoft Entra Connect Sync servers connected to the same Microsoft Entra tenant is not supported, except for a staging server. It's unsupported even if these servers are configured to synchronize with a mutually exclusive set of objects. You might have considered this topology if you can't reach all domains in the forest from a single server, or if you want to distribute load across several servers. (No errors occur when a new Azure AD Sync Server is configured for a new Microsoft Entra forest and a new verified child domain.)

    User's image

    Microsoft Entra Connect supports installing a second server in staging mode. A server in this mode reads data from all connected directories but does not write anything to connected directories. It uses the normal synchronization cycle and therefore has an updated copy of the identity data.

    In a disaster where the primary server fails, you can fail over to the staging server. You do this in the Microsoft Entra Connect wizard. This second server can be located in a different datacenter because no infrastructure is shared with the primary server. You must manually copy any configuration change made on the primary server to the second server.

    Thanks,

    Akshay Kaushik

    Please "Accept the answer (opting Yes under "Helpful")" and "share your feedback ". This will help us and others in the community as well.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Thameur-BOURBITA 32,626 Reputation points
    2023-12-05T09:42:03.3+00:00

    Hi @Ahmed Essam

    Single forest with multiple active server Entra connect is ot supported:

    Unsupported, filtered topology for a single forest

    You should install one active server and a second staging server to ensure the high availability.

    To get more details supported and recommended design of Entra connect please read the following article:

    Topologies for Microsoft Entra Connect


    Pease don't forget to accept helpful answer

    1 person found this answer helpful.
    0 comments No comments