Cloud Sync vs Connect Sync vs PTA vs PHS vs AD FS
Verdict: Cloud Sync natively bridges disconnected forests and is evaluated first. Pass-through auth validates against on-prem AD with no cloud-stored password. AD FS is federated sign-in only, not synchronisation.
| Criterion | Cloud Sync | Connect Sync | Pass-through auth | Password hash sync | AD FS |
|---|---|---|---|---|---|
| Role | Cloud-orchestrated provisioning | Server-based directory sync | Cloud validates against on-prem AD | Hash stored in cloud | Federated sign-in |
| Disconnected multi-forest | Native | Needs trust or consolidation | n/a | n/a | n/a |
| Password stored in cloud | n/a | n/a | No | Yes | No |
| Choose when | M&A and cloud-first | Features Cloud Sync lacks | Credential data residency | Simplest resilient auth | Legacy federation only |
Rules
- Cloud Sync natively synchronises multiple disconnected AD forests to one tenant; Connect Sync needs a trust or consolidation.
- Pass-through authentication validates credentials against on-prem AD and stores no password in the cloud.
- Microsoft directs organisations to evaluate Cloud Sync before installing Connect V2.0.
- Cloud Sync provides Source of Authority management for cloud-first strategies, with cloud-to-AD provisioning for legacy needs.
- Connect Health requires an Entra ID P1 licence even though the sync tooling itself is free.
Traps
- Connect Health only monitors identity infrastructure; it performs no object synchronisation.
- AD FS provides federated sign-in, not directory synchronisation, and cannot merge disconnected forests.
- The sync method chosen does not change Connect Health's P1 licensing requirement.