Connect Install Roadmap
Updated> [!IMPORTANT]
Daily.Entra.NewsThis was a documentation-heavy day: 16 Microsoft Learn pages were updated and the only Message Center item is a naming change, not a service change. The most consequential guidance states that DirSync and Azure AD Sync are unsupported and no longer work, requiring an upgrade to Microsoft Entra Connect to resume synchronization. Separately, Microsoft Purview DLP is renaming its Enforcement plane from “Entra” to “Application” in new audit logs, with no functional or user impact. No new Entra feature, preview, or general-availability announcement is evidenced.
The updated Microsoft Entra ID guidance states that DirSync and Azure AD Sync are no longer supported and no longer work. Organizations still using either must upgrade to Microsoft Entra Connect to resume synchronization. This is a support-status and migration clarification in documentation, not a newly announced feature or service launch.
Starting in mid-January 2026, Microsoft Purview DLP is renaming the Enforcement plane from “Entra” to “Application.” New audit logs will use “Application,” while existing logs retain “Entra.” The notice explicitly says there is no functional or user impact and instructs administrators to update scripts and documentation.
For applications whose AD FS authorization rules depend on Active Directory groups, the updated guidance says to synchronize those groups with Microsoft Entra Connect before migrating the applications, then verify the groups and their membership. This is access-continuity and migration guidance, not a new capability.
The updated Microsoft Entra Connect Sync guidance describes Express settings as the default option for a single-forest topology using password hash synchronization and as the choice for the commonly deployed scenario. The supplied evidence indicates a documentation clarification; it does not describe a new installer behavior or availability change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
> [!IMPORTANT]
|Topic |Link|
- [Download the Microsoft Entra Connect Health agent for AD FS](https://go.microsoft.com/fwlink/?LinkID=518973).
You can upgrade your Microsoft Entra Connect server from all supported versions with the latest versions:
DirSync and Azure AD Sync aren't supported and no longer work. If you're still using DirSync or Azure AD Sync, you *must* upgrade to Microsoft Entra Connect to resume your sync process.
When you map authorization rules, apps that authenticate with AD FS may use Active Directory groups for permissions. In such a case, use [Microsoft Entra Connect](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/~/GetStarted) to sync these groups with Microsoft Entra ID before migrating the applications. Make sure that you verify those groups and membership before migration so that you can grant access to the same users when the application is migrated.
If you have a single-forest topology and use [password hash sync](how-to-connect-password-hash-synchronization.md) for authentication, express settings are a good option to use when you install Microsoft Entra Connect Sync. Express settings the default option to install Microsoft Entra Connect Sync, and it's used for the most commonly deployed scenario. It's only a few short steps to extend your on-premises directory to the cloud.
> [!WARNING]
This article shows the new and updated documentation for the Microsoft Entra application management.
> [!TIP]
Identity governance helps organizations achieve a balance between *productivity* --- how quickly can a person have access to the resources they need, such as when they join the organization? --- and *security* --- how should their access change over time, such as when that person's employment status changes? Identity lifecycle management is the foundation for identity governance, and effective governance at scale requires modernizing the identity lifecycle management infrastructure for applications.
Use *custom settings* in Microsoft Entra Connect when you want more options for the installation. Use these settings, for example, if you have multiple forests or if you want to configure optional features. Use custom settings in all cases where [express installation](how-to-connect-install-express.md) doesn't satisfy your deployment or topology needs.
- SOAP Discovery: Allows the administrator to enter the WSDL path exposed by the target web service. Discovery produces a tree structure of the application's hosted web services with their inner endpoints or operations along with the operation’s Meta data description. There's no limit to the number of discovery operations that can be done (step by step). The discovered operations are used later to configure the flow of operations that implement the connector’s operations against the data-source (as Import/Export).
| HR | [API-driven connector from any HR source](../identity/app-provisioning/inbound-provisioning-api-concepts.md)<br>[Rippling HCM integration with Microsoft Entra ID/Active Directory](../identity/saas-apps/rippling-hcm-microsoft-entra-id-integration-tutorial.md)<br>[Oracle HCM API-driven connector](../identity/saas-apps/oracle-hcm-provisioning-tutorial.md)<br>[Darwinbox to Microsoft Entra ID](../identity/saas-apps/darwinbox-entra-integration-tutorial.md)<br>[SAP HCM to Microsoft Entra ID](../identity/saas-apps/sap-hcm-microsoft-entra-identity-provisioning.md) |
1. For organizations with a single subscription to Workday or SuccessFactors, and don't use Active Directory
- [Download the Microsoft Entra Connect Health agent for AD FS](https://download.microsoft.com/download/9577dcd4-71d4-4607-8950-3b2b97f499f4/MicrosoftEntraConnectHealthAgentSetup.exe).