Funnel overlay image

Is User Provisioning to Active Directory the missing piece of the Entra identity puzzle?

Tom Urwin Smiling

Tom Urwin

Senior Architect

Published: 10 August 2026

For organisations modernising identity while Active Directory remains part of the estate, Entra’s developing support for user provisioning to AD provides a path to cloud-led identity. Here’s what’s changing, how it fits the roadmap, and what identity teams should review before shifting authority into Entra.

In hybrid identity estates, cloud-led identity management often has to coexist with on-premises Active Directory. Line-of-business applications, access models and operational processes can still depend on AD. Even where Entra ID handles authentication, Conditional Access and governance, the source of authority for users can remain on-premises.

The missing piece has been user provisioning into Active Directory. Group provisioning allowed cloud-managed groups to be projected into AD for legacy access, but user objects remained harder to handle. Without a reliable way to provision users, organisations had to keep older identity management patterns in place, even when their strategic direction was cloud-first.

User provisioning from Entra ID to Active Directory gives organisations a more credible route to make Entra the place where user lifecycle decisions are made, while still supporting on-premises resources that cannot be retired overnight.

What user provisioning to AD enables

Direct provisioning of user objects from Entra ID to Active Directory using Microsoft Entra Cloud Sync.

Support for selective provisioning through scoping rules, so organisations can control which users are written back.

Organisational unit targeting, allowing provisioned users to be placed where they belong in AD rather than pushed into a generic location.

Password writeback support, so cloud-managed credentials can continue to work for on-premises authentication scenarios.

Provisioning and audit logs that give identity teams evidence of what happened, when it happened and why.

Where user provisioning changes the roadmap

User provisioning to Active Directory changes where identity ownership can sit. Instead of keeping user lifecycle decisions anchored to legacy directories, organisations can start moving more of that authority into Entra while still supporting AD-backed applications that remain in use.

That’s a more realistic path for most modernisation programmes.

AD rarely disappears in one move. Organisations need to reduce dependency in stages, avoid disrupting critical services and govern any change to identity authority properly. In that model, Entra becomes the place where lifecycle, access and assurance decisions are made, while AD remains available for the systems that still need it.

It also changes how organisations can manage legacy access. Instead of treating on-premises accounts as permanent, unmanaged exceptions, identity teams can govern them through the same lifecycle thinking used for cloud access.

The result is hybrid identity that’s easier to govern. Meaning we can establish:

  • Where authority sits
  • How access is issued
  • How changes are evidenced
  • How exceptions are contained

Decisions to make before shifting authority

Before changing how users are provisioned, identity teams need a clear view of the systems, processes and dependencies already shaping the estate.

Ebony and green circled eye icon on transparent background

Check which identity engine owns each user population today, including Entra provisioning, Microsoft Identity Manager (MIM), Entra Connect Sync and Cloud Sync.

Green and ebony thumbs up icon on transparent background

Decide where source of authority should move first, rather than trying to convert every user population at once.

Ebony and green shield tick and motion arrows icon on transparent background

Use scoping filters carefully so provisioning does not conflict with existing automation processes

Map attributes and organisational unit placement deliberately, especially where legacy applications depend on specific AD structures.

Ebony and green ticklist icon on transparent background

Test with controlled user groups before expanding to broader populations.

Ebony and green 'OK,' hand gesture icon on transparent background

Review password writeback (ensuring it’s only implemented where needed), authentication and recovery flows so cloud-led management does not introduce operational gaps.

Modernise hybrid identity without losing control

User provisioning to Active Directory gives organisations a stronger route out of legacy identity patterns. With the right AD model, application dependencies and transition design in place, identity teams can shift authority into Entra without forcing a hard break with systems that continue to depend on AD.

For organisations still running hybrid identity, this is the point to reassess the roadmap.

  • Which users still need AD?
  • Which applications still rely on it?
  • Which lifecycle processes are being held back by older provisioning models?
  • Where should Entra become the authority, with AD retained only where it still serves a clear purpose?

The organisations that get most value from this will treat it as part of a wider identity modernisation plan.

It gives identity teams a chance to reset where authority belongs. To determine who creates users, where lifecycle decisions are made, how access is governed, and where AD still has a defined role.

The aim is to keep hybrid identity transitional, with modernisation choices led by business need, risk and long-term identity strategy rather than by legacy constraints.

If you want to keep pace with every Entra update to help you navigate your identity road map, you can download our expert guide below, bookmark our always updating Identity Hub, or get in touch with us to talk about your specific plans.

tag icon

latest edition

Everything you need to know about Microsoft Entra

A clear, practical view of how Microsoft Entra works as a unified platform.

Expert guidance on modern identity design, security, governance, and Entra licensing.

Discover how you can:

  • Run Entra as one coherent identity platform
  • Apply end-to-end security and governance
  • Modernise IAM safely, from MIM to AI-driven identity
Butterfly overlay image
Tom Urwin Smiling

Author

Tom Urwin

Senior Architect

Tom is a dynamic and enthusiastic Senior Architect, focusing on Microsoft’s identity and security stack, along with governance and compliance. He uses his experience and vision to turn client problems and ideas into long-term success.

Butterfly overlay image

Got a question? Need more information?

Our expert team is here to help.