| MC1263280 | Microsoft Entra: Security hardening to prevent user account takeover in Microsoft Entra Connect Sync |
|---|
| Classification | planForChange |
|---|---|
| Last Updated | 03/27/2026 19:44:53 |
| Start Time | 03/27/2026 19:42:11 |
| End Time | 11/01/2026 07:00:00 |
| Action Required By Date | 2026-06-30T07:00:00Z |
| Message Content |
[Introduction] Microsoft is strengthening security in Microsoft Entra Connect Sync to prevent user account takeover through hard match abuse. These updates improve the integrity of identity mapping between on-premises Active Directory and Microsoft Entra ID and expand audit visibility for administrators. [When this will happen]
[How this affects your organization] Who is affected Organizations that use Microsoft Entra Connect Sync to synchronize user identities from on-premises Active Directory to Microsoft Entra ID What will happen How hard match works: When Microsoft Entra Connect adds new objects from Active Directory, it compares the object’s sourceAnchor value with the OnPremisesImmutableId of an existing cloud-managed user. If these values match, a hard match occurs and the cloud object is taken over by Microsoft Entra Connect Sync. Security hardening changes:
“Hard match operation blocked due to security hardening. Review OnPremisesObjectIdentifier mapping.”
[What you can do to prepare]
Learn more:
[Compliance considerations] No compliance considerations identified. Review as appropriate for your organization. |