Migrate Group Writeback
Updatedmanager: mwongerapk
Daily.Entra.News30 September was a documentation-only Entra ID day: all 14 supplied changes were Microsoft Learn updates, with no new or removed items and no Message Center changes. The meaningful edits clarify hybrid identity prerequisites—supported Connect hosts, TLS 1.2, PTA agent host limits, and gMSA schema level—rather than announce a new capability or change tenant behavior.
The updated prerequisites state that Microsoft Entra Connect must run on a domain-joined Windows Server 2022, 2019, or 2016 server, with Windows Server 2022 recommended. Windows Server 2016 is in extended support and may require a paid support program for supported configurations; unsupported server versions may cause failures or unexpected behavior. This is deployment guidance, not evidence of a new product capability or retirement.
The updated quick start directs administrators to enable TLS 1.2 when it is not already enabled, use a server in the same Active Directory forest as the users whose passwords need validation, and notes that installing the Pass-through Authentication agent on Windows Server Core is unsupported. The evidence documents deployment prerequisites; it does not show a change to PTA runtime behavior.
A prerequisites update states that the Active Directory schema in the gMSA domain’s forest needs to be updated to Windows Server 2012 or later. Administrators using the affected gMSA-based setup should verify the schema level before deployment; the supplied change is a documentation clarification rather than a feature announcement.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
manager: mwongerapk
- The Active Directory schema in the gMSA domain's forest needs to be updated to Windows Server 2012 or later.
|Requirement|Description and more requirements|
To complete the tutorial, you need these items:
manager: mwongerapk
author: omondiatieno
The following are prerequisites required for completing this tutorial
manager: mwongerapk
1. Identify a server that runs Windows Server 2022, Windows Server 2019, or Windows Server 2016 to run Microsoft Entra Connect. If not enabled already, [enable TLS 1.2 on the server](./how-to-connect-install-prerequisites.md#enable-tls-12-for-azure-ad-connect). Add the server to the same Active Directory forest as the users whose passwords you need to validate. It should be noted that installation of Pass-Through Authentication agent on Windows Server Core versions isn't supported.
manager: mwongerapk
- Azure CLI
manager: mwongerapk
- Microsoft Entra Connect must be installed on a domain-joined server that runs Windows Server 2022, Windows Server 2019, or Windows Server 2016. We recommend Windows Server 2022. You can deploy Microsoft Entra Connect on Windows Server 2016. However, since Windows Server 2016 is in extended support, you might need [a paid support program](/lifecycle/policies/fixed#extended-support) if you require support for this configuration. Installing on unsupported versions of Windows Server may cause service failures or unexpected behavior.
| AADSTS50117 | Failed to deserialize policy specified in the request's claim parameter. |