Organizations still using Microsoft Entra Connect Sync should verify their environment before September 30, 2026.
Microsoft has confirmed that all synchronization services in Entra Connect Sync will stop working on that date if the environment is running a version earlier than 2.5.79.0. The requirement is tied to a backend service change Microsoft introduced to harden its services.
Microsoft guidance:
https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/security-updates-pks
For organizations that rely on hybrid identity, this should be treated as both a security-hardening and service-continuity issue, not simply another routine software update.
Your Environment May Already Be Ready
Not every organization needs to perform a manual upgrade.
Microsoft has been automatically upgrading eligible Entra Connect Sync and Entra Connect Health environments as part of this security-related change. Customers that were successfully auto-upgraded should not be affected by the September 30 deadline.
The environments requiring the most attention are those where:
- Auto-upgrade is disabled
- Auto-upgrade is suspended or failed
- Entra Connect Sync remains below version 2.5.79.0
Administrators can review the auto-upgrade state with:
Get-ADSyncAutoUpgrade -Detail
The key point is simple:
Do not assume if synchronization is working today means the environment is ready for September 30. Verify the installed version and auto-upgrade status.
What Should Organizations Do Now?
Before the deadline:
- Verify the installed Microsoft Entra Connect Sync version.
- Confirm that auto-upgrade is enabled and functioning.
- Review Microsoft Entra Connect Health status and agent versions.
- Upgrade the environment if necessary.
- Validate synchronization health after the upgrade.
Microsoft identifies 2.5.79.0 as the minimum required version, but organizations performing an upgrade should move to the latest supported release rather than stopping at the minimum.
This is particularly important because version 2.5.79.0 itself reaches the end of its support lifecycle shortly after the September deadline.
What About Microsoft Entra Cloud Sync?
Microsoft recommends that eligible organizations consider Microsoft Entra Cloud Sync and continues to introduce new synchronization capabilities through that platform.
That does not mean every Entra Connect Sync environment should migrate today.
Organizations should first validate whether their current Active Directory topology, synchronization requirements, device requirements, and other dependencies are supported.
For now, the priority is straightforward:
Make sure Entra Connect Sync will continue operating after September 30.
Cloud Sync can be evaluated separately as part of the organization's longer-term hybrid identity strategy.
Need Help Validating Your Environment?
If you are unsure whether your Microsoft Entra Connect Sync environment is ready for the September 30 deadline, Helient can help review your current version, auto-upgrade status, synchronization health, prerequisites, and upgrade path.
We can also help evaluate whether Microsoft Entra Cloud Sync makes sense for your longer-term hybrid identity strategy.
Work with Helient's Microsoft identity experts to validate your environment and plan the right next step. For assistance, contact service@helient.com.