# Check directory synchronization before relying on a Cloud Apps user suspension

> Can on-premises directory synchronization reverse a Cloud Apps suspension applied through Microsoft Entra ID?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-461-check-directory-synchronization-before-relying-on-a-cloud-apps-user-suspension/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:15+00:00
- Modified: 2026-09-10T02:08:04+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Can on-premises directory synchronization reverse a Cloud Apps suspension applied through Microsoft Entra ID?

## Potentially affected

Connected-app governance actions involving users automatically synchronized from on-premises Active Directory to Microsoft Entra ID.

## DSE recommendation

Include the authoritative directory owner in the containment decision and verify that the intended restriction survives synchronization.

## Article

## Source facts

Defender for Cloud Apps offers a Suspend user governance action for connected applications. Microsoft warns that when Microsoft Entra ID automatically synchronizes users from on-premises Active Directory, the on-premises settings override Entra settings and the suspension action is reverted. The Governance log records manual and automatic task status, including action success or failure. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-cloud-apps/governance-actions).

## Applicability

Use this boundary for a synchronized identity involved in a connected-app response. Establish where the account state is authoritative before interpreting a successful cloud-side action as continuing containment. This brief concerns user activity governance, not the retiring file-policy workflow.

## DSE recommendation

Include the authoritative directory owner in the containment decision and verify that the intended restriction survives synchronization. Record the chosen response across the relevant identity systems, who may approve it and how the account can safely return to service. Do not repeatedly reapply a reverted cloud action without resolving the authority conflict. Preserve the action history for the incident investigator.

## Verification

With an approved test identity, record the initial account state, governance action result and subsequent synchronized state. Check the resulting access behavior through the intended application rather than relying only on the action’s success entry. Compare the outcome with the containment plan and keep a reversion open as a failed persistence requirement. Restore the test identity through the agreed owner-controlled process, documenting the final state in both systems.

## Official references

[Microsoft Learn: Governance actions for connected apps](https://learn.microsoft.com/en-us/defender-cloud-apps/governance-actions). Source reviewed September 9, 2026.

## Primary reference

- Name: Governing connected apps - Microsoft Defender for Cloud Apps | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-cloud-apps/governance-actions
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check directory synchronization before relying on a Cloud Apps user suspension,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-461-check-directory-synchronization-before-relying-on-a-cloud-apps-user-suspension/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
