πŸ“‹ Microsoft Entra Documentation Changes

Daily summary for changes since January 15th 2026, 7:37 PM PST

Report generated on January 16th 2026, 7:37 PM PST

πŸ“Š Summary

20
Total Commits
0
New Files
16
Modified Files
0
Deleted Files
6
Contributors

πŸ“ Modified Documentation Files

Modified by omondiatieno on Jan 16, 2026 10:21 AM
πŸ“– View on learn.microsoft.com
+7 / -11 lines changed
Commit: January whatsnew updates
Changes:
Before
After
---
title: What's new in Microsoft Entra application management
description: This article shows the new and updated documentation for the Microsoft Entra application management.
ms.date: 12/02/2025
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: whats-new
 
Welcome to what's new in Microsoft Entra application management documentation. This article lists new docs and those articles that had significant updates in the last three months. To learn what's new with the application management service, see [What's new in Microsoft Entra ID](~/fundamentals/whats-new.md).
 
## November 2025
 
### New articles
### Updated articles
 
- [Integrating Microsoft Entra ID with applications getting started guide](plan-an-application-integration.md) - Revised for technical accuracy
 
## September 2025
 
### New articles
---
title: What's new in Microsoft Entra application management
description: This article shows the new and updated documentation for the Microsoft Entra application management.
ms.date: 01/16/2026
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: whats-new
 
Welcome to what's new in Microsoft Entra application management documentation. This article lists new docs and those articles that had significant updates in the last three months. To learn what's new with the application management service, see [What's new in Microsoft Entra ID](~/fundamentals/whats-new.md).
 
## December 2025
 
### New articles
 
- [Deactivate an enterprise application](deactivate-application-portal.md)
 
## November 2025
 
### New articles
### Updated articles
+8 / -8 lines changed
Commit: acrolinx
Changes:
Before
After
 
- SOAP Discovery: Allows the administrator to enter the WSDL path exposed by the target web service. Discovery produces a tree structure of the application's hosted web services with their inner endpoints or operations along with the operation’s Meta data description. There's no limit to the number of discovery operations that can be done (step by step). The discovered operations are used later to configure the flow of operations that implement the connector’s operations against the data-source (as Import/Export).
 
- REST Discovery: Allows the administrator to enter REST service details, including Service Endpoint, Resource Path, Method and Parameter details. The REST services information is stored in the ```discovery.xml``` file of the ```wsconfig``` project. They'll be used later by the administrator to configure the Rest Web Service activity in the workflow.
 
- Schema configuration: Allows the administrator to configure the schema. The schema configuration includes a listing of Object Types and attributes for a specific application. The administrator may choose the attributes are to be part of the schema.
 
 
The computer that runs the provisioning agent should have:
 
- Connectivity to application's REST or SOAP endpoints, as well as with outbound connectivity to login.microsoftonline.com, [other Microsoft Online Services](/microsoft-365/enterprise/urls-and-ip-address-ranges) and [Azure](/azure/azure-portal/azure-portal-safelist-urls) domains. An example is a Windows Server 2016 virtual machine hosted in Azure IaaS or behind a proxy.
- At least 3 GB of RAM, to host a provisioning agent.
- .NET Framework 4.7.2
- A Windows Server 2016 or a later version.
 
Before configuring provisioning, ensure that you:
- Expose the necessary SOAP or REST APIs in your application to create, update and delete users.
 
 
### Cloud requirements
 
- SOAP Discovery: Allows the administrator to enter the WSDL path exposed by the target web service. Discovery produces a tree structure of the application's hosted web services with their inner endpoints or operations along with the operation’s Meta data description. There's no limit to the number of discovery operations that can be done (step by step). The discovered operations are used later to configure the flow of operations that implement the connector’s operations against the data-source (as Import/Export).
 
- REST Discovery: Allows the administrator to enter REST service details, including Service Endpoint, Resource Path, Method, and Parameter details. The REST services information is stored in the ```discovery.xml``` file of the ```wsconfig``` project. They'll be used later by the administrator to configure the Rest Web Service activity in the workflow.
 
- Schema configuration: Allows the administrator to configure the schema. The schema configuration includes a listing of Object Types and attributes for a specific application. The administrator may choose the attributes are to be part of the schema.
 
 
The computer that runs the provisioning agent should have:
 
- Connectivity to application's REST or SOAP endpoints, as well as with outbound connectivity to login.microsoftonline.com, [other Microsoft Online Services](/microsoft-365/enterprise/urls-and-ip-address-ranges), and [Azure](/azure/azure-portal/azure-portal-safelist-urls) domains. An example is a Windows Server 2016 virtual machine hosted in Azure IaaS or behind a proxy.
- At least 3 GB of RAM, to host a provisioning agent.
- .NET Framework 4.7.2
- A Windows Server 2016 or a later version.
 
Before configuring provisioning, ensure that you:
- Expose the necessary SOAP or REST APIs in your application to create, update, and delete users.
 
 
### Cloud requirements
Modified by Mark Wahl on Jan 16, 2026 7:11 PM
πŸ“– View on learn.microsoft.com
+7 / -5 lines changed
Commit: add apps.md
Changes:
Before
After
| HR | [API-driven connector from any HR source](../identity/app-provisioning/inbound-provisioning-api-concepts.md)<br>[Rippling HCM integration with Microsoft Entra ID/Active Directory](../identity/saas-apps/rippling-hcm-microsoft-entra-id-integration-tutorial.md)<br>[Oracle HCM API-driven connector](../identity/saas-apps/oracle-hcm-provisioning-tutorial.md)<br>[Darwinbox to Microsoft Entra ID](../identity/saas-apps/darwinbox-entra-integration-tutorial.md)<br>[SAP HCM to Microsoft Entra ID](../identity/saas-apps/sap-hcm-microsoft-entra-identity-provisioning.md) |
| HR | Student information systems via [School Data Sync](/schooldatasync/school-data-sync-overview) |
|[LDAP directory](../identity/app-provisioning/on-premises-ldap-connector-configure.md)| OpenLDAP<br>Microsoft Active Directory Lightweight Directory Services<br>389 Directory Server<br>Apache Directory Server<br>IBM Tivoli DS<br>Isode Directory<br>NetIQ eDirectory<br>Novell eDirectory<br>Open DJ<br>Open DS<br>Oracle (previously Sun ONE) Directory Server Enterprise Edition<br>RadiantOne Virtual Directory Server (VDS) |
| [SQL database](../identity/app-provisioning/tutorial-ecma-sql-connector.md)| Microsoft SQL Server and Azure SQL<br>IBM DB2 10.x<br>IBM DB2 9.x<br>Oracle 10g and 11g<br>Oracle 12c and 18c<br>MySQL 5.x|
| Cloud platform| [AWS IAM Identity Center](../identity/saas-apps/aws-single-sign-on-provisioning-tutorial.md) |
| Cloud platform| [Google Cloud Platform - User Provisioning](../identity/saas-apps/g-suite-provisioning-tutorial.md) |
| Business applications| Multiple. With Microsoft Entra integrations to [Pathlock](https://pathlock.com/applications/microsoft-entra-id-governance/) and to other partner products, customers can take advantage of additional risk and fine-grained separation-of-duties checks enforced in those products, with access packages in Microsoft Entra ID Governance. |
| [MIC SAAS Portal](../identity/saas-apps/mic-saas-portal-tutorial.md) | | ● |
| [MicroFocus Novell eDirectory (LDAP connector)](../identity/app-provisioning/on-premises-ldap-connector-configure.md) | ● | |
| [Microsoft 365](../fundamentals/concept-group-based-licensing.md) | ● | ● |
| [Microsoft Azure SQL (SQL connector)](../identity/app-provisioning/tutorial-ecma-sql-connector.md) | ● | |
| [Microsoft Azure](/azure/role-based-access-control/role-assignments-portal) | ● | ● |
| [Microsoft Defender for Cloud Apps](/defender-cloud-apps/manage-admins)| ● | ● |
| [Microsoft Dynamics 365 finance and operations](/dynamics365/guidance/implementation-guide/security-strategy-product-oa)| | ● |
| [Microsoft Entra Domain Services](../identity/domain-services/synchronization.md) | ● | ● |
| [Microsoft Intune](/intune/intune-service/fundamentals/role-based-access-control#microsoft-entra-roles-with-intune-access) | ● | ● |
| [Microsoft Lightweight Directory Server (ADAM) (LDAP connector)](../identity/app-provisioning/on-premises-ldap-connector-configure.md) | ● | |
| [Microsoft SharePoint Server on-premises](../identity/saas-apps/sharepoint-on-premises-tutorial.md) | | ● |
| [Microsoft SQL Server (SQL connector)](../identity/app-provisioning/tutorial-ecma-sql-connector.md) | ● | |
| [Microsoft Viva Engage](/viva/engage/manage-viva-engage-groups/create-a-dynamic-group) | ● | ● |
| HR | [API-driven connector from any HR source](../identity/app-provisioning/inbound-provisioning-api-concepts.md)<br>[Rippling HCM integration with Microsoft Entra ID/Active Directory](../identity/saas-apps/rippling-hcm-microsoft-entra-id-integration-tutorial.md)<br>[Oracle HCM API-driven connector](../identity/saas-apps/oracle-hcm-provisioning-tutorial.md)<br>[Darwinbox to Microsoft Entra ID](../identity/saas-apps/darwinbox-entra-integration-tutorial.md)<br>[SAP HCM to Microsoft Entra ID](../identity/saas-apps/sap-hcm-microsoft-entra-identity-provisioning.md) |
| HR | Student information systems via [School Data Sync](/schooldatasync/school-data-sync-overview) |
|[LDAP directory](../identity/app-provisioning/on-premises-ldap-connector-configure.md)| OpenLDAP<br>Microsoft Active Directory Lightweight Directory Services<br>389 Directory Server<br>Apache Directory Server<br>IBM Tivoli DS<br>Isode Directory<br>NetIQ eDirectory<br>Novell eDirectory<br>Open DJ<br>Open DS<br>Oracle (previously Sun ONE) Directory Server Enterprise Edition<br>RadiantOne Virtual Directory Server (VDS) |
| [SQL database](../identity/app-provisioning/tutorial-ecma-sql-connector.md)| Microsoft SQL Server and Azure SQL<br>IBM DB2 10.x<br>IBM DB2 9.x<br>Oracle 10g and 11g<br>Oracle 12c and 18c<br>MySQL 5.x|<br>MySQL 8.x<br>Postgres
| Cloud platform| [AWS IAM Identity Center](../identity/saas-apps/aws-single-sign-on-provisioning-tutorial.md) |
| Cloud platform| [Google Cloud Platform - User Provisioning](../identity/saas-apps/g-suite-provisioning-tutorial.md) |
| Business applications| Multiple. With Microsoft Entra integrations to [Pathlock](https://pathlock.com/applications/microsoft-entra-id-governance/) and to other partner products, customers can take advantage of additional risk and fine-grained separation-of-duties checks enforced in those products, with access packages in Microsoft Entra ID Governance. |
| [MIC SAAS Portal](../identity/saas-apps/mic-saas-portal-tutorial.md) | | ● |
| [MicroFocus Novell eDirectory (LDAP connector)](../identity/app-provisioning/on-premises-ldap-connector-configure.md) | ● | |
| [Microsoft 365](../fundamentals/concept-group-based-licensing.md) | ● | ● |
| [Microsoft Active Directory Lightweight Directory Server (ADAM) (LDAP connector)](../identity/app-provisioning/on-premises-ldap-connector-configure.md) | ● | |
| [Microsoft Azure SQL (SQL connector)](../identity/app-provisioning/tutorial-ecma-sql-connector.md) | ● | |
| [Microsoft Azure](/azure/role-based-access-control/role-assignments-portal) | ● | ● |
| [Microsoft Defender for Cloud Apps](/defender-cloud-apps/manage-admins)| ● | ● |
| [Microsoft Dynamics 365 finance and operations](/dynamics365/guidance/implementation-guide/security-strategy-product-oa)| | ● |
| [Microsoft Entra Domain Services](../identity/domain-services/synchronization.md) | ● | ● |
| [Microsoft Intune](/intune/intune-service/fundamentals/role-based-access-control#microsoft-entra-roles-with-intune-access) | ● | ● |
| [Microsoft SharePoint Server on-premises](../identity/saas-apps/sharepoint-on-premises-tutorial.md) | | ● |
| [Microsoft SQL Server (SQL connector)](../identity/app-provisioning/tutorial-ecma-sql-connector.md) | ● | |
| [Microsoft Viva Engage](/viva/engage/manage-viva-engage-groups/create-a-dynamic-group) | ● | ● |
+3 / -3 lines changed
Commit: Remove references to download center
Changes:
Before
After
> [!IMPORTANT]
> Microsoft doesn't support modifying or operating Microsoft Entra Connect Sync outside of the actions that are formally documented. Any of these actions might result in an inconsistent or unsupported state of Microsoft Entra Connect Sync. As a result, Microsoft can't provide technical support for such deployments.
 
You can find the download for Microsoft Entra Connect on [Microsoft Download Center](https://go.microsoft.com/fwlink/?LinkId=615771).
 
| Solution | Scenario |
| --- | --- |
### Next steps to Install Microsoft Entra Connect
|Topic |Link|
| --- | --- |
|Download Microsoft Entra Connect | [Download Microsoft Entra Connect](https://go.microsoft.com/fwlink/?LinkId=615771)|
|Install using Express settings | [Express installation of Microsoft Entra Connect](./how-to-connect-install-express.md)|
|Install using Customized settings | [Custom installation of Microsoft Entra Connect](./how-to-connect-install-custom.md)|
|Upgrade from DirSync | [Upgrade from Azure AD Sync tool (DirSync)](./how-to-dirsync-upgrade-get-started.md)|
* [Download Microsoft Entra Connect Health Agent for AD FS.](https://go.microsoft.com/fwlink/?LinkID=518973)
* [See the installation instructions](how-to-connect-health-agent-install.md#install-the-agent-for-ad-fs).
* Get started using Microsoft Entra Connect Health for sync
* [Download and install the latest version of Microsoft Entra Connect](https://go.microsoft.com/fwlink/?linkid=615771). The Health Agent for sync is installed as part of the Microsoft Entra Connect installation (version 1.0.9125.0 or higher).
* Get started using Microsoft Entra Connect Health for AD DS
* [Download Microsoft Entra Connect Health Agent for AD DS](https://go.microsoft.com/fwlink/?LinkID=820540).
> [!IMPORTANT]
> Microsoft doesn't support modifying or operating Microsoft Entra Connect Sync outside of the actions that are formally documented. Any of these actions might result in an inconsistent or unsupported state of Microsoft Entra Connect Sync. As a result, Microsoft can't provide technical support for such deployments.
 
You can find the download for Microsoft Entra Connect on [Microsoft Download Center](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/~/GetStarted).
 
| Solution | Scenario |
| --- | --- |
### Next steps to Install Microsoft Entra Connect
|Topic |Link|
| --- | --- |
|Download Microsoft Entra Connect | [Download Microsoft Entra Connect](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/~/GetStarted)|
|Install using Express settings | [Express installation of Microsoft Entra Connect](./how-to-connect-install-express.md)|
|Install using Customized settings | [Custom installation of Microsoft Entra Connect](./how-to-connect-install-custom.md)|
|Upgrade from DirSync | [Upgrade from Azure AD Sync tool (DirSync)](./how-to-dirsync-upgrade-get-started.md)|
* [Download Microsoft Entra Connect Health Agent for AD FS.](https://go.microsoft.com/fwlink/?LinkID=518973)
* [See the installation instructions](how-to-connect-health-agent-install.md#install-the-agent-for-ad-fs).
* Get started using Microsoft Entra Connect Health for sync
* [Download and install the latest version of Microsoft Entra Connect](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/~/GetStarted). The Health Agent for sync is installed as part of the Microsoft Entra Connect installation (version 1.0.9125.0 or higher).
* Get started using Microsoft Entra Connect Health for AD DS
* [Download Microsoft Entra Connect Health Agent for AD DS](https://go.microsoft.com/fwlink/?LinkID=820540).
+1 / -3 lines changed
Commit: update HR source and Oracle EBS
Changes:
Before
After
 
Identity governance helps organizations achieve a balance between *productivity* --- how quickly can a person have access to the resources they need, such as when they join the organization? --- and *security* --- how should their access change over time, such as when that person's employment status changes? Identity lifecycle management is the foundation for identity governance, and effective governance at scale requires modernizing the identity lifecycle management infrastructure for applications.
 
For many organizations, identity lifecycle for employees is tied to the representation of that user in a human capital management (HCM) system. For organizations using Workday as their HCM system, Microsoft Entra ID can ensure user accounts in AD are [automatically provisioned and deprovisioned for workers in Workday](~/identity/saas-apps/workday-inbound-tutorial.md). Doing so leads to improved user productivity through automation of birthright accounts and manages risk by ensuring application access is automatically updated when a user changes roles or leaves the organization. The Workday-driven user provisioning [deployment plan](https://aka.ms/WorkdayDeploymentPlan) is a step-by-step guide that walks organizations through the best practices implementation of Workday to Active Directory User Provisioning solution in a five-step process.
 
Microsoft Entra ID P1 or P2 also includes Microsoft Identity Manager, which can import records from other on-premises HCM systems, including SAP, Oracle eBusiness, and Oracle PeopleSoft.
 
Business-to-business collaboration increasingly requires granting access to people outside your organization. [Microsoft Entra B2B](~/external-id/index.yml) collaboration enables organizations to securely share their applications and services with guest users and external partners while maintaining control over their own corporate data.
 
 
Identity governance helps organizations achieve a balance between *productivity* --- how quickly can a person have access to the resources they need, such as when they join the organization? --- and *security* --- how should their access change over time, such as when that person's employment status changes? Identity lifecycle management is the foundation for identity governance, and effective governance at scale requires modernizing the identity lifecycle management infrastructure for applications.
 
For many organizations, identity lifecycle for employees is tied to the representation of that user in a human capital management (HCM) system. For organizations using Workday as their HCM system, Microsoft Entra ID can ensure user accounts in AD are [automatically provisioned and deprovisioned for workers in Workday](~/identity/saas-apps/workday-inbound-tutorial.md). Doing so leads to improved user productivity through automation of birthright accounts and manages risk by ensuring application access is automatically updated when a user changes roles or leaves the organization. The Workday-driven user provisioning [deployment plan](https://aka.ms/WorkdayDeploymentPlan) is a step-by-step guide that walks organizations through the best practices implementation of Workday to Active Directory User Provisioning solution in a five-step process. Organizations can also use [SuccessFactors](~/identity/saas-apps/sap-successfactors-inbound-provisioning-tutorial.md), [SAP HCM](~/identity/saas-apps/sap-hcm-microsoft-entra-identity-provisioning.md) , [Oracle HCM](~/saas-apps/oracle-hcm-provisioning-tutorial.md), [Rippling HCM](~/identity/saas-apps/rippling-hcm-microsoft-entra-id-integration-tutorial.md), [Darwinbox](~/identity/saas-apps/darwinbox-entra-integration-tutorial.md), or [other HCM systems](~/identity/app-provisioning/inbound-provisioning-api-concepts.md).
 
Business-to-business collaboration increasingly requires granting access to people outside your organization. [Microsoft Entra B2B](~/external-id/index.yml) collaboration enables organizations to securely share their applications and services with guest users and external partners while maintaining control over their own corporate data.
 
 
 
+1 / -2 lines changed
Commit: Remove references to download center
Changes:
Before
After
- [Download the Microsoft Entra Connect Health agent for AD FS](https://go.microsoft.com/fwlink/?LinkID=518973).
- See the [installation instructions](#install-the-agent-for-ad-fs).
- Get started using Microsoft Entra Connect Health for sync:
- [Download and install the latest version of Microsoft Entra Connect](https://go.microsoft.com/fwlink/?linkid=615771). The health agent for sync is installed as part of the Microsoft Entra Connect installation (version 1.0.9125.0 or later).
- Get started using Microsoft Entra Connect Health for AD Domain Services:
- [Download the Microsoft Entra Connect Health agent for AD Domain Services](https://go.microsoft.com/fwlink/?LinkID=820540).
 
## Install the agent for AD FS
 
- [Download the Microsoft Entra Connect Health agent for AD FS](https://go.microsoft.com/fwlink/?LinkID=518973).
- See the [installation instructions](#install-the-agent-for-ad-fs).
- Get started using Microsoft Entra Connect Health for sync:
- [Download and install the latest version of Microsoft Entra Connect](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/~/GetStarted). The health agent for sync is installed as part of the Microsoft Entra Connect installation (version 1.0.9125.0 or later).
- Get started using Microsoft Entra Connect Health for AD Domain Services:
- [Download the Microsoft Entra Connect Health agent for AD Domain Services](https://go.microsoft.com/fwlink/?LinkID=820540).
 
## Install the agent for AD FS
 
 
Modified by Mark Wahl on Jan 16, 2026 7:10 PM
πŸ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: clarify which SAP and Oracle
Changes:
Before
After
 
1. For organizations with a single subscription to Workday or SuccessFactors, and don't use Active Directory
1. For organizations with a single subscription to Workday or SuccessFactors, and have both Active Directory and Microsoft Entra ID
1. For organizations with multiple HR systems, or an on-premises HR system such as SAP, Oracle eBusiness or PeopleSoft
 
For more information, see [What is HR driven provisioning?](~/identity/app-provisioning/what-is-hr-driven-provisioning.md)
 
 
1. For organizations with a single subscription to Workday or SuccessFactors, and don't use Active Directory
1. For organizations with a single subscription to Workday or SuccessFactors, and have both Active Directory and Microsoft Entra ID
1. For organizations with multiple HR systems, or an on-premises HR system such as SAP HCM, Oracle E-Business Suite or PeopleSoft
 
For more information, see [What is HR driven provisioning?](~/identity/app-provisioning/what-is-hr-driven-provisioning.md)
 
Modified by omondiatieno on Jan 16, 2026 11:12 AM
πŸ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: Remove references to download center
Changes:
Before
After
> [!TIP]
> If you plan to federate on-premises Windows Server Active Directory with Microsoft Entra ID, then you need to select **I plan to configure this domain for single sign-on with my local Active Directory** when you run the Microsoft Entra Connect tool to synchronize your directories.
>
> You also need to register the same domain name you select for federating with your on-premises directory in the **Microsoft Entra Domain** step in the wizard. To see what that setup looks like, see [Verify the domain selected for federation](~/identity/hybrid/connect/how-to-connect-install-custom.md#verify-the-azure-ad-domain-selected-for-federation). If you don't have the Microsoft Entra Connect tool, you can [download it here](https://go.microsoft.com/fwlink/?LinkId=615771).
 
## Add your custom domain name
 
> [!TIP]
> If you plan to federate on-premises Windows Server Active Directory with Microsoft Entra ID, then you need to select **I plan to configure this domain for single sign-on with my local Active Directory** when you run the Microsoft Entra Connect tool to synchronize your directories.
>
> You also need to register the same domain name you select for federating with your on-premises directory in the **Microsoft Entra Domain** step in the wizard. To see what that setup looks like, see [Verify the domain selected for federation](~/identity/hybrid/connect/how-to-connect-install-custom.md#verify-the-azure-ad-domain-selected-for-federation). If you don't have the Microsoft Entra Connect tool, you can download the latest version from the [Microsoft Entra Admin Center](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/~/GetStarted) under the **Manage** tab of the **Microsoft Entra Connect | Get started** page.
 
## Add your custom domain name
 
+1 / -1 lines changed
Commit: Remove references to download center
Changes:
Before
After
> [!WARNING]
> If you customized the out-of-the-box sync rules, *back them up before you proceed with the upgrade, then manually redeploy them after you're finished.*
 
1. Download the latest version of Microsoft Entra Connect from the [Microsoft Download Center](https://go.microsoft.com/fwlink/?LinkId=615771).
1. As you already installed Microsoft Entra Connect, perform an in-place upgrade to update your Microsoft Entra Connect installation to the latest version.
 
Run the downloaded package and follow the on-screen instructions to update Microsoft Entra Connect.
> [!WARNING]
> If you customized the out-of-the-box sync rules, *back them up before you proceed with the upgrade, then manually redeploy them after you're finished.*
 
1. Download the latest version from the [Microsoft Entra Admin Center](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/~/GetStarted) under the **Manage** tab of the **Microsoft Entra Connect | Get started** page.
1. As you already installed Microsoft Entra Connect, perform an in-place upgrade to update your Microsoft Entra Connect installation to the latest version.
 
Run the downloaded package and follow the on-screen instructions to update Microsoft Entra Connect.
+1 / -1 lines changed
Commit: Remove references to download center
Changes:
Before
After
 
### Sync AD FS groups in Microsoft Entra ID
 
When you map authorization rules, apps that authenticate with AD FS may use Active Directory groups for permissions. In such a case, use [Microsoft Entra Connect](https://go.microsoft.com/fwlink/?LinkId=615771) to sync these groups with Microsoft Entra ID before migrating the applications. Make sure that you verify those groups and membership before migration so that you can grant access to the same users when the application is migrated.
 
For more information, see [Prerequisites for using Group attributes synchronized from Active Directory](~/identity/hybrid/connect/how-to-connect-fed-group-claims.md).
 
 
### Sync AD FS groups in Microsoft Entra ID
 
When you map authorization rules, apps that authenticate with AD FS may use Active Directory groups for permissions. In such a case, use [Microsoft Entra Connect](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/~/GetStarted) to sync these groups with Microsoft Entra ID before migrating the applications. Make sure that you verify those groups and membership before migration so that you can grant access to the same users when the application is migrated.
 
For more information, see [Prerequisites for using Group attributes synchronized from Active Directory](~/identity/hybrid/connect/how-to-connect-fed-group-claims.md).
 
+1 / -1 lines changed
Commit: Remove references to download center
Changes:
Before
After
- [Download the Microsoft Entra Connect Health agent for AD FS](https://download.microsoft.com/download/9577dcd4-71d4-4607-8950-3b2b97f499f4/MicrosoftEntraConnectHealthAgentSetup.exe).
- See the [installation instructions](#install-the-agent-for-ad-fs).
- Get started using Microsoft Entra Connect Health for sync:
- [Download and install the latest version of Microsoft Entra Connect](https://go.microsoft.com/fwlink/?linkid=615771). The health agent for sync is installed as part of the Microsoft Entra Connect installation (version 1.0.9125.0 or later).
- Get started using Microsoft Entra Connect Health for AD Domain Services:
- [Download the Microsoft Entra Connect Health agent for AD Domain Services](https://download.microsoft.com/download/9577dcd4-71d4-4607-8950-3b2b97f499f4/MicrosoftEntraConnectHealthAgentSetup.exe).
- See the [installation instructions](#install-the-agent-for-azure-ad-ds).
- [Download the Microsoft Entra Connect Health agent for AD FS](https://download.microsoft.com/download/9577dcd4-71d4-4607-8950-3b2b97f499f4/MicrosoftEntraConnectHealthAgentSetup.exe).
- See the [installation instructions](#install-the-agent-for-ad-fs).
- Get started using Microsoft Entra Connect Health for sync:
- [Download and install the latest version of Microsoft Entra Connect](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/~/GetStarted). The health agent for sync is installed as part of the Microsoft Entra Connect installation (version 1.0.9125.0 or later).
- Get started using Microsoft Entra Connect Health for AD Domain Services:
- [Download the Microsoft Entra Connect Health agent for AD Domain Services](https://download.microsoft.com/download/9577dcd4-71d4-4607-8950-3b2b97f499f4/MicrosoftEntraConnectHealthAgentSetup.exe).
- See the [installation instructions](#install-the-agent-for-azure-ad-ds).
+1 / -1 lines changed
Commit: Remove references to download center
Changes:
Before
After
Use *custom settings* in Microsoft Entra Connect when you want more options for the installation. Use these settings, for example, if you have multiple forests or if you want to configure optional features. Use custom settings in all cases where [express installation](how-to-connect-install-express.md) doesn't satisfy your deployment or topology needs.
 
Prerequisites:
- [Download Microsoft Entra Connect](https://go.microsoft.com/fwlink/?LinkId=615771).
- Complete the prerequisite steps in [Microsoft Entra Connect: Hardware and prerequisites](how-to-connect-install-prerequisites.md).
- Make sure you have the accounts described in [Microsoft Entra Connect accounts and permissions](reference-connect-accounts-permissions.md).
 
Use *custom settings* in Microsoft Entra Connect when you want more options for the installation. Use these settings, for example, if you have multiple forests or if you want to configure optional features. Use custom settings in all cases where [express installation](how-to-connect-install-express.md) doesn't satisfy your deployment or topology needs.
 
Prerequisites:
- [Download Microsoft Entra Connect](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/~/GetStarted).
- Complete the prerequisite steps in [Microsoft Entra Connect: Hardware and prerequisites](how-to-connect-install-prerequisites.md).
- Make sure you have the accounts described in [Microsoft Entra Connect accounts and permissions](reference-connect-accounts-permissions.md).
 
+1 / -1 lines changed
Commit: Remove references to download center
Changes:
Before
After
 
If you have a single-forest topology and use [password hash sync](how-to-connect-password-hash-synchronization.md) for authentication, express settings are a good option to use when you install Microsoft Entra Connect Sync. Express settings the default option to install Microsoft Entra Connect Sync, and it's used for the most commonly deployed scenario. It's only a few short steps to extend your on-premises directory to the cloud.
 
Before you start installing Microsoft Entra Connect Sync, [download Microsoft Entra Connect Sync](https://go.microsoft.com/fwlink/?LinkId=615771), and be sure to complete the prerequisite steps in [Microsoft Entra Connect: Hardware and prerequisites](how-to-connect-install-prerequisites.md).
 
If the express settings installation doesn't match your topology, see [Related articles](#related-articles) for information about other scenarios.
 
 
If you have a single-forest topology and use [password hash sync](how-to-connect-password-hash-synchronization.md) for authentication, express settings are a good option to use when you install Microsoft Entra Connect Sync. Express settings the default option to install Microsoft Entra Connect Sync, and it's used for the most commonly deployed scenario. It's only a few short steps to extend your on-premises directory to the cloud.
 
Before you start installing Microsoft Entra Connect Sync, [download Microsoft Entra Connect Sync](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/~/GetStarted), and be sure to complete the prerequisite steps in [Microsoft Entra Connect: Hardware and prerequisites](how-to-connect-install-prerequisites.md).
 
If the express settings installation doesn't match your topology, see [Related articles](#related-articles) for information about other scenarios.
 
+1 / -1 lines changed
Commit: Remove references to download center
Changes:
Before
After
 
DirSync and Azure AD Sync aren't supported and no longer work. If you're still using DirSync or Azure AD Sync, you *must* upgrade to Microsoft Entra Connect to resume your sync process.
 
Before you start installing Microsoft Entra Connect, make sure you [download Microsoft Entra Connect](https://go.microsoft.com/fwlink/?LinkId=615771) and complete the prerequisite steps described in [Microsoft Entra Connect: Hardware and prerequisites](how-to-connect-install-prerequisites.md). Pay special attention to the following requirements for Microsoft Entra Connect because they're different from DirSync:
 
- **Required versions of .NET and PowerShell**: Newer versions that what are required for DirSync must be on the server for Microsoft Entra Connect.
- **Proxy server configuration**: If you use a proxy server to reach the internet, this setting must be configured before you upgrade. DirSync always used the proxy server that was configured for the user who installed it, but Microsoft Entra Connect uses machine settings instead.
 
DirSync and Azure AD Sync aren't supported and no longer work. If you're still using DirSync or Azure AD Sync, you *must* upgrade to Microsoft Entra Connect to resume your sync process.
 
Before you start installing Microsoft Entra Connect, make sure you [download Microsoft Entra Connect](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/~/GetStarted) and complete the prerequisite steps described in [Microsoft Entra Connect: Hardware and prerequisites](how-to-connect-install-prerequisites.md). Pay special attention to the following requirements for Microsoft Entra Connect because they're different from DirSync:
 
- **Required versions of .NET and PowerShell**: Newer versions that what are required for DirSync must be on the server for Microsoft Entra Connect.
- **Proxy server configuration**: If you use a proxy server to reach the internet, this setting must be configured before you upgrade. DirSync always used the proxy server that was configured for the user who installed it, but Microsoft Entra Connect uses machine settings instead.
+1 / -1 lines changed
Commit: Remove references to download center
Changes:
Before
After
 
|Topic |Link|
| --- | --- |
|Download Microsoft Entra Connect | [Download Microsoft Entra Connect](https://go.microsoft.com/fwlink/?LinkId=615771)|
|Install by using express settings | [Express installation of Microsoft Entra Connect](how-to-connect-install-express.md)|
|Install by using customized settings | [Custom installation of Microsoft Entra Connect](./how-to-connect-install-custom.md)|
|Upgrade from DirSync | [Upgrade from Azure AD Sync tool (DirSync)](how-to-dirsync-upgrade-get-started.md)|
 
|Topic |Link|
| --- | --- |
|Download Microsoft Entra Connect | [Download Microsoft Entra Connect](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/~/GetStarted)|
|Install by using express settings | [Express installation of Microsoft Entra Connect](how-to-connect-install-express.md)|
|Install by using customized settings | [Custom installation of Microsoft Entra Connect](./how-to-connect-install-custom.md)|
|Upgrade from DirSync | [Upgrade from Azure AD Sync tool (DirSync)](how-to-dirsync-upgrade-get-started.md)|