Ensure Continuous Identity Synchronization – Action Needed Before April 2027

Upgrading Microsoft Entra Connect Sync — Required Before April 2027

Upgrading Microsoft Entra Connect Sync

Action required before April 2027

Background

Microsoft has announced that organizations using Microsoft Entra Connect Sync must:

  • Upgrade to version 2.6.84.0 or later
  • Use application-based authentication

If this isn't done, directory synchronization between on-premises Active Directory and Microsoft Entra ID (Microsoft 365) will stop working once Microsoft begins enforcing these requirements in April 2027.

Timeline

DateEvent
April 7, 2027Last day to upgrade
April 12, 2027Microsoft begins enforcing the requirement
April 30, 2027Global rollout complete

What's Affected?

If you use Microsoft Entra Connect Sync to synchronize:

  • Users
  • Groups
  • Passwords (Password Hash Sync)
  • Hybrid identities

synchronization can stop working if the server:

  • Runs a version older than 2.6.84.0
  • Uses legacy authentication
  • Has not been migrated to application-based authentication

1Check the Installed Version

There are several ways to check which version is installed.

Option 1 — Control Panel

  1. Open Control Panel.
  2. Select Programs and Features.
  3. Locate Microsoft Entra Connect Sync.
  4. Note the version number.

Option 2 — Synchronization Service Manager

  1. Open Synchronization Service Manager.
  2. Select Help → About.
  3. Note the version number.

Option 3 — Entra Admin Center

  1. Sign in to the Microsoft Entra Admin Center.
  2. Go to: Entra ID → Entra Connect → Connect Sync → Microsoft Entra connect Health → Sync Services → choose service name → Microsoft Entra Connect Servers → properties
  3. Check the version information for the registered Connect server.
✅ Passing version: 2.6.84.0 or later
❌ Failing version: older than 2.6.84.0

2Back Up the Configuration

Before upgrading, it's recommended to export the current configuration.

  1. Sign in to the Entra Connect server.
  2. Start Microsoft Entra Connect.
  3. Click Configure.
  4. Select View or export current configuration.
  5. Click Next.
  6. Select Export Settings.
  7. Save the JSON file to a secure location.

Examples: a file server, a network share, a backup server.

3Check Server Requirements

Check .NET Framework

Open PowerShell as administrator and run:

Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full' -Name Release

A Release value of 461808 or higher indicates that .NET Framework 4.7.2 or later is installed.

Check TLS 1.2

First, check which TLS protocols are available by running:

[Net.ServicePointManager]::SecurityProtocol

TLS 1.2 should be listed in the output.

✅ TLS 1.2 is available
✅ Modern .NET Framework is installed

You can also verify that the server can establish an HTTPS connection using TLS 1.2:

[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
Invoke-WebRequest https://login.microsoftonline.com -UseBasicParsing

If the request completes successfully, the server can establish an HTTPS connection using TLS 1.2.

Example: A server returning Tls, Tls11, Tls12 has TLS 1.2 available. A Release value such as 533320 indicates a modern .NET Framework 4.8.1 installation.

4Upgrade Entra Connect

  1. Download the latest version of Microsoft Entra Connect from Microsoft.
  2. Run the installer.
  3. The installer detects the existing installation.
  4. Click Upgrade.
  5. Follow the wizard.
  6. If sign-in is required, use an account with sufficient administrative rights.
  7. Check: Start the synchronization process when configuration completes
  8. Click Upgrade.
  9. Wait for the installation to finish.
  10. Click Exit.
Important: The synchronization service is temporarily stopped during the upgrade. A new sync normally starts automatically once the upgrade is complete.

Recommendation: If you have more than approximately 50,000 AD objects, it's recommended to perform the upgrade outside regular business hours.

5Verify the Authentication Method

Microsoft requires Entra Connect to use application-based authentication. This is just as important as the version upgrade itself.

Check in Microsoft Entra Connect

  1. Open Microsoft Entra Connect.
  2. Click Configure.
  3. Select View current configuration.
  4. Check which authentication method is in use.
✅ Application-based Authentication
❌ Legacy Authentication / older sync account
Note: Microsoft typically sends this notice because their telemetry has detected that one or more servers in the environment may be using legacy authentication or running an older version.

6Verify That Sync Is Working

Open Synchronization Service Manager and confirm:

  • ✅ Import succeeds
  • ✅ Synchronization succeeds
  • ✅ Export succeeds
  • ✅ No errors are shown
  • ✅ The latest run completed successfully

7Confirm the Installed Version

After upgrading, the version should be verified.

  1. Open Synchronization Service Manager.
  2. Select Help → About.
  3. Confirm the version number is:
✅ 2.6.84.0 or later

Recommendation From IT

Microsoft Entra Connect should be kept up to date on an ongoing basis — not only when support ends.

  • ✅ Security updates
  • ✅ Bug fixes
  • ✅ Improved stability
  • ✅ Better performance
  • ✅ Support for new features
  • ✅ Reduced risk of service disruption

Summary

Before April 7, 2027, you should:

  • ✅ Upgrade Microsoft Entra Connect Sync to version 2.6.84.0 or later
  • ✅ Confirm the server meets Microsoft's requirements for TLS 1.2 and .NET Framework
  • ✅ Back up the configuration
  • ✅ Verify that application-based authentication is in use
  • ✅ Confirm that synchronization works after the upgrade

If these steps aren't completed, synchronization between on-premises Active Directory and Microsoft Entra ID risks breaking once Microsoft's change takes effect in April 2027.

Kommentarer

Populära inlägg i den här bloggen

🚀 Force Reinstallation of an Intune App

🔵Troubleshooting Intune Device Enrollments: Understanding GUIDs, Registry Paths, and EnterpriseMgmt Tasks

🚀 Windows Autopilot Self-Deploying Mode — Zero-Touch Setup That Feels Like Magic