How do I configure Entra Cloud Sync to add another domain?

System Administrator 20 Reputation points
2025-03-14T20:24:41.4033333+00:00

I have Entra Cloud Sync provisioning setup of an on-premise AD domain on 2 servers. I want to add a different domain from our 2 AWS AD servers. I have the provisioning agent installed on the AWS AD servers but I can't get it configured to synchronize them for that domain.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,208 questions
{count} votes

Accepted answer
  1. Raja Pothuraju 20,800 Reputation points Microsoft External Staff
    2025-03-24T23:48:43.0766667+00:00

    Hello @System Administrator,

    Thank you for connecting over the team's call.

    As discussed, we observed that whenever you attempt to sync a cloud-only user back to Active Directory (AD) via a cloud security group using Provision Microsoft Entra ID to Active Directory - Configuration, you encounter the following provisioning error: "The User '3c202fee-2d62-40e6-8d35-de6269d8086d' will be skipped due to the following reasons: 1) This object is not assigned to the application. If you did not expect the object to be skipped, assign the object to the application or change your scoping filter to allow all users and groups to be in scope for provisioning. 2) This object does not have required entitlement for provisioning. If you did not expect the object to be skipped, update provisioning scope to 'Sync all users and groups' or assign the object to the application with entitlement of provisioning category 3) This object did not pass a scoping filter. If you did not expect the object to be skipped, please review your scoping filters and ensure that the object passes your specified scoping criteria. The scope evaluation result is: {"On-prem Owned Users.dirSyncEnabled IS TRUE":false}".

    User's image Cause: The provisioning is being skipped because the targeted user is a cloud-only user (created in Microsoft Entra ID).

    Due to a design limitation, cloud-only users cannot be synced back to AD—only cloud-only security groups can be synced.

    For more details, you can refer to the following document, which specifies that only on-prem synced users are supported for security group provisioning: Provision Microsoft Entra ID to Active Directory - Prerequisites

    User's image I hope this information is helpful. Please feel free to reach out if you have any further questions.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".


2 additional answers

Sort by: Most helpful
  1. Marcin Policht 44,245 Reputation points MVP
    2025-03-14T22:10:55.1666667+00:00

    Follow https://learn.microsoft.com/en-us/entra/identity/hybrid/cloud-sync/how-to-troubleshoot


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin


  2. Thameur-BOURBITA 36,241 Reputation points
    2025-03-16T12:56:21.0666667+00:00

    Hi @System Administrator

    Please try follow this article: Provision Active Directory to Microsoft Entra ID - Configuration


    Please don't forget to accept helpful answer


    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.