Ensure Continuous Identity Synchronization – Action Needed Before April 2027
Upgrading Microsoft Entra Connect Sync
Action required before April 2027
Background
Microsoft has announced that organizations using Microsoft Entra Connect Sync must:
- Upgrade to version 2.6.84.0 or later
- Use application-based authentication
If this isn't done, directory synchronization between on-premises Active Directory and Microsoft Entra ID (Microsoft 365) will stop working once Microsoft begins enforcing these requirements in April 2027.
Timeline
| Date | Event |
|---|---|
| April 7, 2027 | Last day to upgrade |
| April 12, 2027 | Microsoft begins enforcing the requirement |
| April 30, 2027 | Global rollout complete |
What's Affected?
If you use Microsoft Entra Connect Sync to synchronize:
- Users
- Groups
- Passwords (Password Hash Sync)
- Hybrid identities
synchronization can stop working if the server:
- Runs a version older than 2.6.84.0
- Uses legacy authentication
- Has not been migrated to application-based authentication
1Check the Installed Version
There are several ways to check which version is installed.
Option 1 — Control Panel
- Open Control Panel.
- Select Programs and Features.
- Locate Microsoft Entra Connect Sync.
- Note the version number.
Option 2 — Synchronization Service Manager
- Open Synchronization Service Manager.
- Select Help → About.
- Note the version number.
Option 3 — Entra Admin Center
- Sign in to the Microsoft Entra Admin Center.
- Go to:
Entra ID → Entra Connect → Connect Sync → Microsoft Entra connect Health → Sync Services → choose service name → Microsoft Entra Connect Servers → properties - Check the version information for the registered Connect server.
2Back Up the Configuration
Before upgrading, it's recommended to export the current configuration.
- Sign in to the Entra Connect server.
- Start Microsoft Entra Connect.
- Click Configure.
- Select View or export current configuration.
- Click Next.
- Select Export Settings.
- Save the JSON file to a secure location.
Examples: a file server, a network share, a backup server.
3Check Server Requirements
Check .NET Framework
Open PowerShell as administrator and run:
Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full' -Name Release
A Release value of 461808 or higher indicates that
.NET Framework 4.7.2 or later is installed.
Check TLS 1.2
First, check which TLS protocols are available by running:
[Net.ServicePointManager]::SecurityProtocol
TLS 1.2 should be listed in the output.
You can also verify that the server can establish an HTTPS connection using TLS 1.2:
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
Invoke-WebRequest https://login.microsoftonline.com -UseBasicParsing
If the request completes successfully, the server can establish an HTTPS connection using TLS 1.2.
Example: A server returning
Tls, Tls11, Tls12 has TLS 1.2 available. A
Release value such as 533320 indicates a modern
.NET Framework 4.8.1 installation.
4Upgrade Entra Connect
- Download the latest version of Microsoft Entra Connect from Microsoft.
- Run the installer.
- The installer detects the existing installation.
- Click Upgrade.
- Follow the wizard.
- If sign-in is required, use an account with sufficient administrative rights.
- Check: Start the synchronization process when configuration completes
- Click Upgrade.
- Wait for the installation to finish.
- Click Exit.
Recommendation: If you have more than approximately 50,000 AD objects, it's recommended to perform the upgrade outside regular business hours.
5Verify the Authentication Method
Microsoft requires Entra Connect to use application-based authentication. This is just as important as the version upgrade itself.
Check in Microsoft Entra Connect
- Open Microsoft Entra Connect.
- Click Configure.
- Select View current configuration.
- Check which authentication method is in use.
6Verify That Sync Is Working
Open Synchronization Service Manager and confirm:
- ✅ Import succeeds
- ✅ Synchronization succeeds
- ✅ Export succeeds
- ✅ No errors are shown
- ✅ The latest run completed successfully
7Confirm the Installed Version
After upgrading, the version should be verified.
- Open Synchronization Service Manager.
- Select Help → About.
- Confirm the version number is:
Recommendation From IT
Microsoft Entra Connect should be kept up to date on an ongoing basis — not only when support ends.
- ✅ Security updates
- ✅ Bug fixes
- ✅ Improved stability
- ✅ Better performance
- ✅ Support for new features
- ✅ Reduced risk of service disruption
Summary
Before April 7, 2027, you should:
- ✅ Upgrade Microsoft Entra Connect Sync to version 2.6.84.0 or later
- ✅ Confirm the server meets Microsoft's requirements for TLS 1.2 and .NET Framework
- ✅ Back up the configuration
- ✅ Verify that application-based authentication is in use
- ✅ Confirm that synchronization works after the upgrade
If these steps aren't completed, synchronization between on-premises Active Directory and Microsoft Entra ID risks breaking once Microsoft's change takes effect in April 2027.







Kommentarer
Skicka en kommentar