Provisioning to Active Directory with Microsoft Entra Cloud Sync FAQ

Read about frequently asked questions for provisioning to Active Directory with Microsoft Entra Cloud Sync.

Does Group Provision to AD in Microsoft Entra Cloud Sync work side-by-side with other Microsoft Entra Connect Sync capabilities?

Yes, you can use Microsoft Entra Cloud Sync just for Security Group Provision to AD while using Connect Sync for AD to Microsoft Entra ID sync.

I have Microsoft 365 groups that I provision to AD using Group Writeback feature in Microsoft Entra Connect Sync. Will that continue to work?

Yes, when you uninstall or disable Group Writeback V2 from your Connect Sync configuration, it defaults to Group Writeback V1. This default supports the ability to write back all Microsoft 365 groups in Microsoft Entra ID.

What if I want to disable Group Writeback V1 as well?

When you disable Group Writeback V1, the next full sync deletes all the cloud groups that are written by Microsoft Entra Connect Sync to AD. Cloud Security Groups provisioned using Microsoft Entra Cloud Sync won’t be impacted by this operation.

Can I continue to use the "Group writeback" field through MS Graph and Microsoft Entra admin center for setting groups in scope for provisioning to AD using Microsoft Entra Cloud Sync?

No, this field isn't currently used for determining the scope of groups being provisioned to AD using Cloud Sync. You have to use the Microsoft Entra Cloud Sync configuration experience in the portal to set scope.