Technology
Microsoft Sets a September 30, 2026 Cutoff for Entra Connect Sync: Old Versions Stop Syncing Entirely
Microsoft says every Entra Connect Sync server not on version 2.5.79.0 or later by September 30, 2026 will stop synchronizing with Microsoft 365 and Entra ID entirely, not just lose support. Here is who is affected and how to check your version today.
Microsoft has published a mandatory upgrade deadline for any organization running Microsoft Entra Connect Sync, the on-premises tool that keeps a local Active Directory in step with Microsoft 365 and Entra ID. According to Microsoft's own upgrade documentation, "all synchronization services in Microsoft Entra Connect Sync will stop working on September 30, 2026 if you're not on at least version 2.5.79.0." That gives organizations only two weeks from this article's September 16, 2026 publication date, and Microsoft is explicit that this is not a soft support cutoff: "all synchronization services will fail" during the gap between the deadline and whenever the server is actually upgraded, per Microsoft's hardening-update guidance.
What Changed, and Why Microsoft Is Forcing It
Microsoft says it deployed a new first-party application, called the "Microsoft Entra AD Synchronization Service," to handle the connection between an on-premises Active Directory and Entra ID as part of a broader effort to harden that pathway. Version 2.5.79.0, released in May 2025, is the first version built to work with that new service. Anything older was built against the connection method Microsoft is retiring, which is why the cutoff is a hard failure rather than a warning banner. Microsoft's documentation also flags that 2.5.79.0 itself is not a long-term destination: it is only the minimum floor for the September 30 deadline, and organizations upgrading now should confirm they are pulling the current release from the Microsoft Entra admin center rather than stopping at the floor version.
Who This Actually Affects
This applies specifically to Microsoft Entra Connect Sync, sometimes still called by its older name, Azure AD Connect, running on a server an organization manages itself. It is the setup common at businesses that keep a local Windows Server domain and use it as the source of identity for Microsoft 365 mailboxes, Teams, and SharePoint access, rather than managing users only in the cloud. If your organization (or your IT provider) already migrated to Microsoft Entra Cloud Sync, a newer, cloud-managed alternative Microsoft is actively steering customers toward in the same documentation, this deadline does not apply to you.
What to Check Right Now
Open the Synchronization Service Manager on your Entra Connect server, or check Programs and Features, and confirm the installed version number against 2.5.79.0. If you manage this yourself, download the current installer only from the Microsoft Entra admin center, since Microsoft has made the installer exclusively available there rather than through general download pages. Before upgrading, confirm the server meets the minimum requirements Microsoft lists alongside the deadline, including .NET Framework 4.7.2 and TLS 1.2, since a server that has not been patched in a while may be missing one of those. If your organization outsources this to an IT provider or MSP, ask them directly for the installed version number and the planned upgrade date rather than a general assurance that "everything is current."
Why a Missed Deadline Is Worse Than It Sounds
A stalled Entra Connect Sync server does not just delay a cosmetic update. Every account change made in Active Directory, a new hire added, a terminated employee disabled, a password reset, a group membership change, stops reaching Microsoft 365 the moment sync fails. The practical exposure depends on how your tenant authenticates. With Password Hash Synchronization, the most common setup, Microsoft 365 checks a password hash it already has on file, so an employee disabled in Active Directory can keep working cloud access to email, Teams, and SharePoint until someone notices the sync is broken and disables the Microsoft 365 account by hand. With Pass-through Authentication or federation, sign-ins are checked against Active Directory directly, so a fresh sign-in attempt is blocked right away, though any session or token issued before the account was disabled can still remain active until it expires or is explicitly revoked. Either way, for any organization tracking access-control obligations under a cyber insurance policy or a regulatory framework, an identity system that silently stops updating is exactly the kind of gap a risk assessment is supposed to catch before it becomes an audit finding.
Cyber One Solutions can check your Entra Connect Sync version and upgrade path as part of our managed cloud service, which handles Microsoft 365 and Entra ID administration on an ongoing basis, or through a standalone IT assessment if you manage identity in-house and want a second set of eyes before September 30. If you are already reviewing how your Microsoft 365 data is protected, our recent look at why the Recycle Bin is not a backup plan covers a related gap worth closing at the same time.
