← Back to blog
Cloud & Infrastructure

Device sync in Entra Cloud Sync: the missing piece for hybrid environments

By Zarioh Digital Solutions5 min read
Share
Device sync in Entra Cloud Sync: the missing piece for hybrid environments

Entra Cloud Sync could not synchronise computer objects from Active Directory for a long time — which kept Hybrid Azure AD Join out of reach. That blocked Conditional Access, Windows Hello for Business, and Intune co-management. In August 2026 that obstacle disappears: device sync is now available in preview in Cloud Sync.

Microsoft Entra Cloud Sync was launched as the cloud-native successor to the older Microsoft Entra Connect Sync. Lighter, simpler to maintain, and without a local SQL database. For new deployments the choice was quickly made. But for organisations that had been running Connect Sync for years, one obstacle remained insurmountable: Cloud Sync could not synchronise computer objects from Active Directory to Entra ID. That blocked Hybrid Azure AD Join — and with it, a significant part of the Windows management infrastructure relied on by many IT teams.

In August 2026, Microsoft has removed that obstacle. Device sync is now available as a preview in Microsoft Entra Cloud Sync. For organisations that were waiting on this capability to complete their transition from Connect Sync, this is the starting signal to build a serious migration plan.

Why was device sync such a bottleneck?

Hybrid Azure AD Join means a device is simultaneously a member of the on-premises Active Directory domain and registered in Microsoft Entra ID. That dual identity is the foundation for a range of capabilities that IT teams rely on daily: Conditional Access policies that require device compliance, Windows Hello for Business via cloud trust, single sign-on to Microsoft 365 services without additional login prompts, and Intune co-management alongside an existing SCCM infrastructure.

As long as Cloud Sync could not synchronise devices, Hybrid Azure AD Join was simply unavailable for organisations that wanted to move to Cloud Sync. They had to keep Connect Sync running — with all the accompanying server infrastructure, SQL instance, and management overhead — solely to synchronise computer objects. For IT teams looking to simplify, that was a frustrating roadblock.

How does device sync in Cloud Sync work?

The new capability uses a separate synchronisation job within Cloud Sync, the AD2AADDeviceSync job. This job synchronises computer objects from on-premises Active Directory to Microsoft Entra ID. After synchronisation, devices become Hybrid Azure AD Joined: they have an Entra identity while technically remaining part of the local domain.

Configuration is done through the Microsoft Entra portal, under the Cloud Sync settings. Administrators define which organisational units (OUs) are synchronised, in the same way that user and group sync is already configured. The provisioning agent — running on an on-premises server — handles the communication. No separate SQL database is needed and no additional server is required if the agent is already installed for user sync.

Device attributes that are synchronised include the computer object GUID, operating system, version, and domain membership details. The result in Entra ID is a hybrid device object that can be used in Conditional Access policies, device compliance evaluations, and Intune management.

What else changes in Cloud Sync?

Device sync is the most prominent addition, but not the only improvement Microsoft is bringing to Cloud Sync in August 2026. Three other enhancements are worth noting.

Source of Authority conversion: organisations that want to transition users from 'synchronised via Connect Sync' to 'managed via Cloud Sync' now have a structured migration path. The Source of Authority determines which system is authoritative for a specific user's identity, and a controlled conversion prevents two systems from simultaneously trying to manage the same object.

Group writeback to Active Directory: Cloud Sync can now write Microsoft 365 groups back to on-premises Active Directory. This is valuable for organisations that also want to use Entra groups for on-premises access control, for example as a membership criterion for local file servers or applications.

Improved Exchange Hybrid support: Exchange Hybrid environments require synchronisation of specific mail-related attributes between on-premises Exchange and Exchange Online. Cloud Sync now supports these scenarios more comprehensively, making migration from Connect Sync for Exchange environments more achievable than before.

Running both tools simultaneously: the rule you cannot skip

A critical warning applies to any organisation considering running Cloud Sync and Connect Sync simultaneously: the two tools must never manage the same object. One engine per object is the hard rule. If both tools are active in the environment, scoping must be watertight — defined per OU or per group, so that each object is exclusively assigned to one tool.

For the device sync component, this is especially relevant. If Connect Sync is already synchronising devices and you want to switch to Cloud Sync device sync, remove the device sync scope in Connect Sync first before enabling it in Cloud Sync. Microsoft recommends testing this in a pilot environment with a scoped OU before rolling it out to the full device population.

When is the right time to make the switch?

If your organisation has been waiting for device sync in Cloud Sync to complete the migration from Connect Sync, the moment has arrived to build a project plan. Three factors determine the pace of that migration.

First, the Connect Sync version. Organisations still running Connect Sync are being urged by Microsoft to upgrade to version 2.5.79.0 or later, with a deadline in September 2026. This is a good moment to evaluate whether a full switch to Cloud Sync makes more sense than an incremental upgrade.

Second, the complexity of the environment. Simple environments with a single AD forest, no Exchange Hybrid, and a limited number of OUs can migrate relatively quickly. More complex environments — multiple forests, Exchange Hybrid, custom attributes, or connected HR systems — require a more detailed migration plan, including a test phase and a rollback scenario.

Third, feature parity. With the additions of August 2026, the functional gap between Cloud Sync and Connect Sync has narrowed considerably. For most hybrid environments, Cloud Sync now offers a capable alternative. Check the Microsoft documentation to verify that the specific capabilities your environment requires are supported before starting a migration project.

Device sync in Entra Cloud Sync is a long-awaited step that clears the path for IT teams who wanted to make the switch but were held back by this technical gap. The feature is currently in preview, with general availability expected in the coming months. Would you like to know whether your hybrid environment is ready for a migration to Cloud Sync, or do you need support planning the transition? Contact Zarioh for a technical conversation.

Z

Zarioh Digital Solutions

IT specialists from Utrecht, the Netherlands. We help businesses with Microsoft 365, AI agents, hosting and telephony — and share what we learn in practice. Follow us on LinkedIn

Related articles

← Back to all articles
Share