Microsoft Entra Connect Sync: the September 2026 upgrade deadline
What identity teams should verify before the mandatory Entra Connect Sync upgrade deadline, and how to reduce cutover risk.
Executive summary
Microsoft states that organisations running Microsoft Entra Connect Sync must be on version 2.5.79.0 or later by 30 September 2026. Below that minimum, all Connect Sync synchronisation services can fail when the associated service change takes effect. Microsoft recommends moving to the latest supported release rather than treating the minimum version as the target.
This is an identity-service continuity issue, not a routine desktop update. The useful question is not only “what version is installed?” It is also whether the server, custom rules, database, network path, monitoring and recovery process are ready for a controlled upgrade.
Why it matters
Connect Sync sits between an authoritative on-premises directory and Microsoft Entra ID. If synchronisation stops, existing cloud sign-ins do not automatically stop, but identity changes can cease to flow. Joiners, leavers, password changes and group or attribute updates may be delayed, depending on the organisation’s configuration.
That delay can become a security and operations problem. Teams need a clear owner, an understood impact window and evidence that synchronisation resumed correctly.
What to establish now
Confirm the deployed design
Record the Connect version, Windows Server version, database arrangement, staging server status and synchronisation topology. Check whether automatic upgrade is enabled and whether it has actually kept the server current. An enabled setting is not evidence of a completed upgrade.
Inventory custom synchronisation rules and connectors. Export configuration through the organisation’s approved process and store it as sensitive identity infrastructure data.
Review prerequisites
Microsoft calls out current platform requirements including .NET Framework and TLS 1.2. Review the prerequisites for the exact release selected, including proxy, service account, SQL and operating-system dependencies. Obtain the installer through the Microsoft Entra admin centre as documented by Microsoft.
Build a controlled change plan
Define the pre-change health evidence, maintenance window, rollback conditions and named decision maker. If a staging server exists, confirm that its configuration and version are suitable before relying on it as the recovery path.
Document the normal scheduler state and recent import, synchronisation and export results. Resolve unexplained errors before the upgrade; otherwise the team may incorrectly attribute an existing problem to the new version.
Validation after the upgrade
Validate the installed version and service state, then observe a complete synchronisation cycle. Confirm successful imports and exports for every in-scope connector and review Microsoft Entra Connect Health where it is deployed.
Use approved test identities to verify representative changes rather than making an unplanned production change. Include create, update and disable scenarios where policy permits. Check that monitoring detects a stopped scheduler or failed export and reaches the correct support team.
Keep the change open until the identity owner accepts the evidence. A green Windows service alone does not prove end-to-end synchronisation.
Strategic decision: Connect Sync or Cloud Sync
The deadline should trigger a design review, but it should not force a rushed platform migration. Microsoft recommends considering Cloud Sync where it meets requirements. Compare supported topology, attributes, writeback needs, operational model and recovery approach before choosing.
If Connect Sync remains the right platform, upgrade it properly. If Cloud Sync is the future state, treat that as a separate project with coexistence, pilot and exit criteria.
Risks and limitations
This article does not provide a tenant-specific upgrade runbook or claim that version 2.5.79.0 is the latest available release. Release status can change. Verify the current version history and prerequisites immediately before implementation.
Tested versions
No commands or installation procedure are presented. This operational advisory was checked against Microsoft documentation current on 19 September 2026.
Community discussion
Questions and comments
Share a question, correction or implementation experience. Comments are public and require a GitHub account. Please do not include tenant names, credentials, logs or other confidential information.