Cloud Sync: Entra ID to AD; Groups sync'ing but no members of the groups: Error: NotEffectivelyEntitled

Tom Robinson 0 Reputation points
2025-10-09T23:57:30.9566667+00:00

Entra ID to AD Sync not working for All Users members.

I have set up Cloud Sync to sync Entra ID to AD on premises. The groups are syncing but the members of the groups are skipped with NotEffectivelyEntitled.

What am I doing wrong? How can I get the members fo the groups to synchronise to the on premises AD?

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. Anonymous
    2025-10-15T06:15:07.5766667+00:00

    Hello Tom Robinson,
    Thank you for your response and the workarounds. You have correctly zeroed in on the fundamental design constraint of Microsoft's hybrid identity features.

    Your question was: Could you please clarify if there's a documented way to make API-driven provisioning work with cloud-only users, or should we proceed with the PowerShell migration approach?
    To answer that, unfortunately There is no documented, supported way from Microsoft to use API-driven provisioning to directly create cloud-only Entra ID users in on-premises Active Directory. API-driven provisioning is designed for integrating external sources like HR systems (Workday, SAP, etc.), not for migrating or exporting existing cloud-only users from Entra ID to AD. The definitive solution is that the PowerShell migration approach is the required and officially supported method for your scenario.

    You should absolutely proceed with your PowerShell script, as it is the only viable path to convert your users to the hybrid status required for all subsequent Entra ID > AD provisioning features.
    Thanks for your patience during this issue!
    Regards,

    Monalisha

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.