Entra Connect Sync – Configure device SCP Connection Missing on Staging Server

Shubham Sharma (OneStepGroup) 30 Reputation points
2025-05-17T13:56:43.9966667+00:00

Hi Community,

We are currently running Entra Connect Sync on a single (active) server and have recently set up a staging server for high availability.

To configure the staging server, I followed the import/export settings process from the active node to the staging node. Everything went smoothly, but I noticed a difference regarding device configuration.

On the active server, the "Configure Devices" option is enabled, and an SCP (Service Connection Point) connection is already established using AD FS authentication.

  • However, on the staging server, the "Configure Devices" with hybrid join devices option does not show any SCP connection.

My Question:

Do I need to manually create the SCP connection with AD FS on the staging server, or will the SCP settings be automatically applied once the staging server is promoted to active?

I’d really appreciate any clarification or best practices from those who’ve handled similar scenarios.

Thanks in advance!

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Accepted answer
  1. Andy David - MVP 157.6K Reputation points MVP Volunteer Moderator
    2025-05-17T15:03:00.68+00:00

    Hi., yea thats expected. A new install doesnt reflect that its enabled even if you import the other servers configuration.

    All you need to do on the staging server is check that Hybrid join option , but no need to let actually configure it or enter the EA creds since it already exists. You can then hit Next and run through the Wizard. (Pretend you are going to download the ConfigureSCP.PS1) :)

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Eric Nguyen 1,025 Reputation points Independent Advisor
    2025-05-19T08:55:06.2366667+00:00

    Manual SCP configuration on the staging server is not required. This is expected behavior, as staging mode servers do not write to Active Directory. Once promoted to active, the server will handle SCP management. It's recommended to run the “Configure Device Options” wizard after promotion to ensure SCP settings are correctly applied for Hybrid Azure AD Join.

    If this resolves your query, please click Accept Answer and select Yes if you found it helpful. Feel free to reach out if you have any additional questions!


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.