Hybrid identity

Connect Active Directory and Entra
without losing source authority.

MAITS designs and modernises hybrid identity across Active Directory, Microsoft Entra Connect, Cloud Sync, authentication, directory attributes and operational ownership.

Synchronisation is an identity control

A topology decides which source is authoritative, how objects are matched, which attributes can flow, what can write back and how failure is detected.

Hybrid architecture

One identity estate. Deliberate flow in both directions.

Active Directory, cloud identity and relying services must share an explicit model for authority, matching, lifecycle and supported writeback.

Hybrid identity architectureActive Directory connects to Microsoft Entra through Entra Connect or Cloud Sync, then to cloud applications, Microsoft 365, Azure and external identities. Supported writeback is a separate, scoped decision.ON-PREMISESActive DirectoryForests · domains · trustsUsers · groups · attributesExchange dependenciesService identitiesSYNC OPTIONEntra ConnectServer-managedCustom rules · stagingSYNC OPTIONCloud SyncCloud-managed agentsCLOUD IDENTITYMicrosoft EntraAuthenticationConditional AccessGovernance · PIMWorkload identityRELYING SYSTEMSCloud & partnersApplicationsMicrosoft 365Azure resourcesExternal identitiesAPIsWRITEBACK — ONLY WHERE CURRENTLY SUPPORTED AND REQUIRED
The right synchronisation topology depends on source authority, forests, attribute flows, authentication, writeback needs, scale and operating model.

Directory foundation

Modern cloud identity still depends on sound directory engineering.

ACTIVE DIRECTORY

Forests, domains and trust

Assess domain and forest topology, trust relationships, UPN design, group strategy, attributes, stale identities and privileged groups.

SOURCE AUTHORITY

Ownership and matching

Define which system owns each identity and attribute, how existing cloud objects are matched, and which immutable identity assumptions must survive migration.

AUTHENTICATION

Hybrid sign-in strategy

Evaluate password hash synchronisation, pass-through authentication or remaining federation dependencies against resilience, risk and operating effort.

OPERATIONS

Health and recoverability

Design agent placement, staging or redundancy, monitoring, change control and recovery so synchronisation failure is visible and supportable.

Entra Connect or Cloud Sync

Choose the topology from requirements, not fashion.

Microsoft Entra Connect Sync runs provisioning on an on-premises synchronisation server. Microsoft Entra Cloud Sync stores configuration and runs the provisioning service in Microsoft’s cloud, using lightweight on-premises agents.

Cloud Sync can support multiple disconnected Active Directory forests and scoped synchronisation. Entra Connect remains relevant where its established topology, advanced synchronisation rules or particular hybrid dependencies are required.

MAITS assesses coexistence, migration, agent placement, scoping, attribute mapping, source anchors, authentication and operational constraints before recommending a path.

Microsoft Cloud Sync overview

Synchronisation engineering

Make the data path understandable and testable.

TOPOLOGY

Tenant and forest relationships

Map single or multiple forests, domains, network boundaries, target tenants and coexistence constraints.

FLOW

Scope and attributes

Define organisational-unit or group scope, filtering, transformations, extension attributes and authoritative ownership.

MATCH

Join and source anchor

Control identity matching, duplicate handling and immutable identity decisions before enabling production flow.

CHANGE

Staging and migration

Rehearse transitions between sync technologies with rollback criteria, reconciliation and cutover evidence.

Writeback & Exchange identity

Treat reverse flow as a separately governed capability.

Writeback support varies by technology and scenario. MAITS validates the current Microsoft support boundary before including it in a design.

PASSWORD

Password writeback

Where licensed and supported, connect cloud password reset or change to the on-premises directory with appropriate policy and monitoring.

GROUPS

Group provisioning to AD

Use current Cloud Sync group provisioning where it meets requirements; treat legacy Entra Connect group writeback modes and migration constraints precisely.

DEVICES

Device writeback

Retain only for supported hybrid scenarios that genuinely depend on on-premises device objects, rather than as a default modern design.

EXCHANGE

Recipient identity dependencies

Account for mail-related attributes, recipients, contacts, groups, Exchange Online and remaining on-premises directory management dependencies.

Microsoft’s supported writeback capabilities and prerequisites change over time. The implementation design is validated against current documentation and the organisation’s exact Entra, Active Directory and Exchange topology.

Modernisation path

Move deliberately from inherited estate to intentional architecture.

01 / DISCOVER

Map

Inventory directories, connectors, rules, attributes, sign-in dependencies, writeback and operational ownership.

02 / DESIGN

Decide

Set source authority, target topology, authentication, scope, flows, monitoring and supported reverse paths.

03 / COEXIST

Prove

Stage representative identities, reconcile results and test failure, recovery and Exchange consequences.

04 / CUT OVER

Modernise

Transition using explicit decision points, rollback criteria, validation and controlled retirement.

Legacy identity migration

Replace capability, not just a product name.

Older estates may include Microsoft Identity Manager, Forefront Identity Manager, custom management agents, federation platforms or bespoke provisioning engines. Their connectors and metaverse logic can carry business rules that are not visible elsewhere.

Microsoft Entra does not replace every MIM or legacy IGA use case one-for-one. MAITS maps the authoritative sources, transformations, joins, workflows and target-system constraints first, then sequences coexistence, migration, validation and retirement around the capability that must remain.

DiscoverMapCoexistMigrateValidateCut overRetire

Start a conversation

Make hybrid identity a designed system, not inherited plumbing.

Bring your forests, current sync topology and cloud target. MAITS can establish a practical modernisation path.