Connect to single on-premises AD forest | ● | ● |
Connect to multiple on-premises AD forests | ● | ● |
Connect to multiple disconnected on-premises AD forests | | ● |
Lightweight agent installation model | | ● |
Multiple active agents for high availability | | ● |
Support for user objects | ● | ● |
Support for group objects | ● | ● |
Support for contact objects | ● | ● |
Support for device objects | ● | |
Allow basic customization for attribute flows | ● | ● |
Synchronize Exchange online attributes | ● | ● |
Synchronize extension attributes 1-15 | ● | ● |
Synchronize customer defined AD attributes (directory extensions) | ● | ● |
Support for Password Hash Sync | ● | ● |
Support for Pass-Through Authentication | ● | |
Support for federation | ● | ● |
Seamless Single Sign-on | ● | ● |
Supports installation on a Domain Controller | ● | ● |
Support for Windows Server 2016 | ● | ● |
Filter on Domains/OUs/groups | ● | ● |
Filter on objects’ attribute values | ● | |
Allow minimal set of attributes to be synchronized (MinSync) | ● | ● |
Allow removing attributes from flowing from AD to Microsoft Entra ID | ● | ● |
Allow advanced customization for attribute flows | ● | |
Support for password writeback | ● | ● |
Support for device writeback | ● | Customers should use Cloud Kerberos trust for this moving forward |
Support for group writeback | | ● |
Support for merging user attributes from multiple domains | ● | |
Microsoft Entra Domain Services support | ● | |
Exchange hybrid writeback | ● | ● |
Unlimited number of objects per AD domain | ● | |
Support for up to 150,000 objects per AD domain | ● | ● |
Groups with up to 50,000 members | ● | ● |
Large groups with up to 250,000 members | ● | |
Cross domain references | ● | ● |
Cross forest references | ● | |
On-demand provisioning | | ● |
Support for US Government | ● | ● |