Simplify hybrid complexity and strengthen your security posture by managing users and groups natively in the cloud.
Updated Nov 03, 2025
Version 1.0No. Converting a user’s Source of Authority from Active Directory to Entra does not require disabling the user object in either system. The object remains active in both directories.
For the second question, after conversion, the user object becomes cloud-managed, meaning changes in Entra do not sync back to AD. Optional writeback features (like password writeback) can still be enabled for compatibility, but attribute updates in Entra stay in the cloud.
Isn’t this essentially just breaking the sync?
For the disable part, I meant in a leaver situation. Life cycle of users will get more complex when doing this.
Would have been great if we could change SOA without breaking the sync.