# Make Microsoft Entra Connect replaceable before synchronization stops

> Microsoft Entra Connect is replaceable only when its configuration, advanced exceptions, credentials, failover order, and validation evidence are ready. Staging mode lowers recovery time, but it is active-passive—not active-active.

- Canonical URL: https://update.dsesecurity.com/updates/make-microsoft-entra-connect-replaceable-before-synchronization-stops/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-08-04T22:53:02+00:00
- Modified: 2026-08-04T22:53:02+00:00
- Last reviewed by DSE: 2026-08-04
- Resource type: Playbook
- DSE priority: Important
- Topics: Business Continuity, IT, Microsoft 365 & Identity
- Reading time: 4 minutes

## What you need to know

Microsoft Entra Connect is replaceable only when its configuration, advanced exceptions, credentials, failover order, and validation evidence are ready. Staging mode lowers recovery time, but it is active-passive—not active-active.

## Potentially affected

Organizations using Microsoft Entra Connect Sync for hybrid identity, especially those relying on password hash synchronization, password writeback, Exchange hybrid writeback, custom filtering, or custom synchronization rules.

## DSE recommendation

Choose a documented rebuild or staging-server strategy, export current configuration to protected storage, record settings the export omits, and rehearse a single-active-server failover with pending-export and password-sync validation.

## Article

## Source fact: staging mode is active-passive protection

Microsoft’s current [staging-server and disaster-recovery guidance](https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-sync-staging-server) supports fault tolerance, testing configuration changes, and replacing an old server. A staging server imports and synchronizes data but does not export to Microsoft Entra ID or on-premises Active Directory. Password hash synchronization and password writeback also do not run while that server remains in staging mode. Microsoft is explicit: Entra Connect Sync supports active-passive high availability, not active-active, and only one server may actively export changes.

A staging server still receives directory changes and maintains its own database. Microsoft recommends keeping its scheduler enabled and its synchronization recent. Before a role switch, run an initial cycle when rules or scope changed, confirm accidental-delete protection, and inspect pending exports. If the former active server is unreachable, it must be shut down or isolated so it cannot unexpectedly resume exporting.

## Source fact: password services require separate failover attention

Disabling staging mode starts exports, password synchronization, and password writeback. Microsoft warns that password hash sync resumes from the staging server’s last recorded watermark. A server left staged for an extended period can have a large backlog; new password changes might not work in Microsoft Entra ID until catch-up completes. Microsoft advises monitoring the application event log during catch-up and not restarting synchronization services, because a restart can make processing resume from an earlier watermark. Password writeback can also be disrupted if two servers are active.

## Source fact: rebuild is supported, but configuration must survive

Microsoft describes rebuild-on-demand as a viable disaster-recovery model. The sync engine can rebuild its object state from Active Directory and Microsoft Entra ID, using the sourceAnchor to join existing on-premises and cloud objects. What must be preserved is the applied configuration, including filters and synchronization rules. The companion [configuration import and export guidance](https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-import-export-config) says wizard changes create time-stamped JSON files under the Entra Connect program-data location; changes made with PowerShell, Synchronization Service Manager, or Synchronization Rules Editor require an on-demand export.

The exported JSON must not be hand-edited. Import deliberately starts the new server in staging mode, but it is not a complete machine clone. Microsoft lists settings that may require manual reapplication, including device writeback, selected object types or attributes, custom run profiles, provisioning hierarchy, and parts of federated sign-in configuration. Post-installation comparison of the imported settings with a new export is an essential verification step.

## DSE recommendation: choose the recovery model from business tolerance

DSE recommends an explicit decision between rebuild-on-demand and a warm staging server. Base it on tolerated delay in directory changes, password synchronization, and real-time writeback—not simply server uptime. A straightforward environment with a tested configuration package may accept rebuild time. Complex filters, rules, multiple forests, writeback, or a short recovery objective favor a maintained staging server.

In either model, treat the Windows host as replaceable and the configuration plus procedure as the durable asset. Keep a protected copy of the latest supported export away from the sync server. Maintain a separate register of Entra Connect version, sourceAnchor choice, forests and connectors, sign-in method, OU and attribute scope, custom rules and precedence, writeback features, scheduler state, service and connector account requirements, network dependencies, and every setting the export does not restore.

## DSE recommendation: rehearse this controlled handoff

- Prepare. Patch the candidate server to a supported build, update configuration and advanced settings, enable its scheduler, and confirm a recent successful import and synchronization.
- Inspect. Run the required full or initial cycle after scope or rule changes. Review pending adds, updates, and deletes; stop if volume or direction is unexplained.
- Quiesce. Put the reachable primary into staging mode. If it failed, positively isolate it from outbound access and record how reactivation is prevented.
- Promote. Disable staging mode only on the approved replacement. Verify exports, password hash sync progress, writeback where used, Entra Connect Health, and representative identity changes.
- Stabilize. Keep the old server isolated or staged, document the new role assignment, export the resulting configuration, and investigate every difference from the intended build.

This DSE playbook is an operational interpretation of Microsoft’s supported models. It does not replace environment-specific change approval. Its purpose is to prove that Entra Connect can be replaced without creating two writers or exporting an unreviewed directory change.

## Official sources

- [Microsoft: Entra Connect staging server and disaster recovery](https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-sync-staging-server)
- [Microsoft: Import and export Entra Connect configuration settings](https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-import-export-config)
- [Microsoft: Customize an Entra Connect installation](https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-install-custom)

## Primary reference

- Name: Microsoft Entra Connect: Staging server and disaster recovery
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-sync-staging-server
- Source publication date: 2026-04-02

## Citation and use

Preferred citation: “Make Microsoft Entra Connect replaceable before synchronization stops,” DSE Security, https://update.dsesecurity.com/updates/make-microsoft-entra-connect-replaceable-before-synchronization-stops/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
