| MC1262584 | Upcoming change – Microsoft Entra Connect security update to block hard match for users with Microsoft Entra roles |
|---|
| Classification | planForChange |
|---|---|
| Last Updated | 03/26/2026 23:43:18 |
| Start Time | 03/26/2026 23:39:47 |
| End Time | 08/02/2026 07:00:00 |
| Action Required By Date | 2026-05-31T07:00:00Z |
| Message Content |
[Introduction] We’re introducing a security update to Microsoft Entra Connect and Cloud Sync to better protect privileged cloud‑managed accounts. Today, when Entra Connect or Cloud Sync adds new objects from Active Directory, the service attempts a “hard match” by comparing the object’s sourceAnchor to the onPremisesImmutableId of existing cloud accounts. If there’s a match, the service takes over the source of authority (SoA) and updates the cloud object using the attributes from Active Directory. Beginning in early June 2026, Microsoft Entra ID will block hard‑match attempts that target cloud‑managed users who hold Microsoft Entra roles. This change helps prevent attackers from taking over privileged accounts by manipulating on‑premises attributes. [When this will happen] General Availability (Worldwide, DoD, GCC, and GCCH): We will begin rolling out in early June 2026 and expect to complete by early July 2026. [How this affects your organization] Who is affected
What will happen
[What you can do to prepare] If your environment relies on hard‑matching accounts that hold Microsoft Entra roles, you may encounter an InvalidHardMatch error after this change takes effect. Recommended actions:
Learn more:
[Compliance considerations] No compliance considerations identified. Review as appropriate for your organization. |