Skip to content
Pro IT NW

Blog · 10 min read ·

Share

Entra Connect Sync deadline: April 7, 2027, not Sept 30

Microsoft Entra Connect Sync must be on version 2.6.84.0 or later, with application-based authentication configured, by April 7, 2027 — after that, Microsoft says synchronization services stop working. Separately, version 2.5.79.0 reaches end of support on October 23, 2026.

Correction — October 5, 2026: This post was built around a September 30, 2026 cutoff that Microsoft no longer publishes. On September 29, 2026, Microsoft replaced the notice on its installation prerequisites and version history pages. The September 30 / 2.5.79.0 wording is gone. The notice now reads: "Upgrade Microsoft Entra Connect Sync to version 2.6.84.0 or later and configure application-based authentication by April 7, 2027. Legacy authentication is being retired, and synchronization services will stop working after this date if these requirements aren't met." We have rewritten the deadline, the FAQ, and the checklist below to match. We have not seen a Microsoft statement about what, if anything, changed on September 30 itself.

If you run hybrid identity — Active Directory on-premises, accounts synchronized into the cloud — there is a hard date on your calendar whether you put it there or not. By April 7, 2027, every Microsoft Entra Connect Sync server needs to be on version 2.6.84.0 or later and configured for application-based authentication. Miss either half and, in Microsoft's words, "synchronization services will stop working." Not "loses support." Stops.

Microsoft's installation prerequisites page carries the notice under the heading "Mandatory upgrade required", and the same text sits at the top of the version history. It is explicit about recovery, too: "If synchronization stops, upgrade to the latest version and configure application-based authentication to restore service."

Two things changed at once on September 29, and the second is the bigger job. The minimum version rose from 2.5.79.0 to 2.6.84.0 — an upgrade. And the notice now requires application-based authentication, which Microsoft describes as replacing the Microsoft Entra Connector account's username and password with "an application identity that uses Oauth 2.0 client credential flow with certificate credentials." That is a change to how your most privileged sync server proves who it is, not a version bump.

The one-sentence version: the date moved out to April 7, 2027 but the requirement got bigger — and 2.5.79.0, the old minimum, still reaches end of support on October 23, 2026, so anyone who upgraded to the old floor has a nearer date than the new deadline.

Earlier updates to this post

The callouts below were written while the September 30 notice was still live. The version and end-of-support facts in them still hold; read any mention of September 30 as historical.

Update — September 7, 2026 (superseded — see September 18 below): Name the target build: it is 2.6.84.0, the current release, which Microsoft recommends installing "as soon as possible" because it carries security fixes. If a server took 2.6.79.0, stop — Microsoft recalled that build after an issue surfaced post-release, and says to uninstall it and install 2.6.84.0. Separately, the miiserver.exe.config known issue — synchronization failing after upgrade with System.IO.FileLoadException: Could not load file or assembly 'System.Diagnostics.DiagnosticSource, Version=6.0.0.1' or one of its dependencies. The located assembly's manifest definition does not match the assembly reference. — is documented against 2.5.190.0 and 2.6.1.0, both mid-ladder versions, which is one more reason not to park there. The page does not say whether 2.6.84.0 is affected. And 2.5.76.0's own end of support, September 1, 2026, has now passed. Check the full ladder before you commit to a target.
Update — September 18, 2026 (superseded — see September 26 below): The target build has moved again. Microsoft released 2.6.91.0 on September 16, 2026, for download via the Microsoft Entra admin center, and its release notes are explicit: "This release includes security fixes. We recommend upgrading to this version as soon as possible." That also closes the gap the September 7 callout above flagged — 2.6.84.0 now has a published end-of-support date, September 16, 2027 (twelve months after 2.6.91.0's release), so it is no longer an open-ended build. 2.6.91.0 itself carries no end-of-support date yet, under the same release-plus-twelve-months policy. The new release also makes phishing-resistant authentication in the setup wizard generally available and on by default.
Update — September 26, 2026: There is a newer build again. Microsoft released 2.6.92.0 on September 23, 2026, and its own release notes say plainly, "This is a hotfix release," fixing "an issue in version 2.6.91.0 where enabling Pass-through Authentication through the Microsoft Entra Connect wizard could fail while registering the locally installed Microsoft Entra Connect Authentication Agent." The "This release includes security fixes. We recommend upgrading to this version as soon as possible" notice now sits against 2.6.92.0, not 2.6.91.0. That release also gives 2.6.91.0 a published end-of-support date for the first time — September 23, 2027 (twelve months after 2.6.92.0's release) — so it is no longer an open-ended build either. Practical takeaway: target 2.6.92.0 — it is the newest build and the one Microsoft's upgrade-as-soon-as-possible notice now sits against. If you run Pass-through Authentication and use the Microsoft Entra Connect wizard, it also fixes the 2.6.91.0 agent-registration failure.

One more thing in 2.6.91.0 worth knowing: it adds a guided migration workflow from Microsoft Entra Connect Sync to Microsoft Entra Cloud Sync — configuration assessment, provisioning agent setup, staged activation, and validation, built into the release. It is available only in the Azure public cloud. That is a bigger decision than a version bump — worth evaluating on its own timeline, and now worth evaluating alongside the April 7, 2027 authentication change, since both touch the same server.

The version trap

Microsoft's Entra Connect Sync version history — last updated September 29, 2026 — publishes a retirement table. Read it next to the new 2.6.84.0 minimum and the trap is obvious:

VersionEnd of support
2.5.3.0July 31, 2026 (already passed)
2.5.76.0September 1, 2026 (already passed)
2.5.79.0October 23, 2026
2.5.190.0February 2, 2027
2.6.1.0March 10, 2027
2.6.3.0July 7, 2027
2.6.84.0September 16, 2027
2.6.91.0September 23, 2027
2.6.92.0no date printed

Until September 29, the warning named 2.5.79.0 as the minimum. An admin who did the sensible thing — upgraded to the version named in the warning and closed the ticket — is now on a build that is below the new 2.6.84.0 minimum and whose published end of support is October 23, 2026. The change window they fought for bought a few weeks, and the next conversation is already due.

The same logic applies to the new floor. 2.6.84.0 meets the April 7, 2027 requirement on version, and its published end of support is September 16, 2027 — runway, but not much past the deadline. The newest build, 2.6.92.0, has no end-of-support date printed yet and carries Microsoft's "upgrading to this version as soon as possible" notice.

Neither fact is hidden. They simply live in different places: the deadline is a banner, and the per-version retirement dates are a table further down the version history. Planning this upgrade properly means reading both — that is the difference between booking one change window and booking two.

Why the table keeps moving: Microsoft's stated policy is that "versions of Microsoft Entra Connect Sync 2.x retire 12 months from the date that a newer version is released. This policy went into effect on 15 March 2023." The twelve months run from the next build's release, not from your install. Your supported window is therefore set by Microsoft's release cadence, and a version can be retired out from under a server that has not changed at all.

What stops if a server misses the requirement

"Synchronization stops" sounds abstract until you decompose it into the things your organization notices.

  • Password hash synchronization stops. A user changes their password on-premises and the cloud never hears about it. Help desk volume follows within hours.
  • New-hire provisioning stops. Accounts created in Active Directory do not appear in the cloud directory. Every onboarding stalls at the same step, and the workaround people reach for is manual cloud accounts that then have to be reconciled later.
  • Deprovisioning stops. This is the one that should get security's attention. Disabling a departing employee's Active Directory account no longer removes their cloud access. Your offboarding runbook still says "disable in AD," the technician still does it, the checkbox still gets ticked — and the access is still live.

The failure mode is quiet. Directory synchronization does not surface an error to end users; it simply stops reflecting reality, and the gap between what Active Directory says and what the cloud believes widens every day until someone reconciles it by hand.

Check Your Entra Connect Sync Version (New April 2027 Deadline)Watch on YouTube (opens in a new tab)

Why this is a Tier-0 change, not a lunchtime patch

The Entra Connect Sync server is not an application server that happens to run a Microsoft agent. It holds credentials that can write to your directory. Compromise it and you have compromised the identity plane — which is the working definition of a Tier-0 asset.

That classification changes the shape of the work. A Tier-0 change means a scheduled window, a documented rollback position, administration from an appropriately trusted workstation, and verification afterwards that synchronization actually resumed rather than merely that the installer exited cleanly. None of that is difficult. All of it takes calendar time — and the teams that miss April 7 will mostly miss it on approvals, not on engineering.

The authentication change raises the stakes on that discipline. Moving the connector from a password to a certificate-backed application identity means deciding who manages the certificate — Microsoft Entra Connect by default, or your own certificate or application — and where its private key lives. Microsoft's guidance recommends a TPM-backed key. Those are decisions to make deliberately, not in the last fortnight before a hard cutoff.

What to do before April 7, 2027

Short, ordered, and none of it requires a project:

  1. Find every Entra Connect Sync server and record its exact version. Including the staging server if you have one — a staging server that falls behind is a rollback position that does not exist. Write the versions down; "we think it is current" is not an inventory.
  2. Compare each version against the retirement table above. Below 2.6.84.0 means you do not meet the April 7, 2027 requirement. On 2.5.79.0 means an October 23, 2026 end-of-support date as well. Below 2.5.79.0 means you are already out of support — confirm synchronization is actually running today.
  3. Pick a target build with runway, not the floor. The whole point of the trap is that the minimum is not a destination. Choose from the version history table with the end-of-support column visible, so the next upgrade is a year out rather than a month out.
  4. Plan the authentication change, not just the upgrade. Pick the certificate-management option (managed by Microsoft Entra Connect, Bring Your Own Certificate, or Bring Your Own Application), check whether the server has a TPM, and read Microsoft's application identity guide before the window, not during it.
  5. Book the change window well before April 7, 2027. Treat it as a Tier-0 change: approval, window, rollback position, named owner. A server on 2.5.79.0 should go first — its October 23, 2026 end of support comes long before the new deadline.
  6. Verify synchronization after the change, not just the installer's exit. Confirm a test password change flows through, a test account provisions, and a test disable propagates. Those are the three things that break, so those are the three things to prove.
  7. Put the next end-of-support date on the calendar before you close the ticket. Under a twelve-month retirement policy driven by Microsoft's release cadence, this is a recurring maintenance item, not a one-off.

Common mistakes we expect to see

Upgrading to the version named in the warning

Covered above, and worth repeating because it is the default behavior of a competent admin working from one page. The minimum is the pass mark, not the answer — and the minimum already moved once, from 2.5.79.0 to 2.6.84.0. Read the version history page before choosing a target build.

Assuming a deadline this hard comes with a grace period

Most Microsoft lifecycle dates end support: you stop receiving updates and keep running. This one is a back-end service change, and the documented outcome is that "synchronization services will stop working after this date if these requirements aren't met." There is nothing to buy. The date has already been rewritten once; do not plan on it happening again.

Treating an unchanged server as a current server

Because the twelve-month clock starts when the next version ships, a server nobody has touched can move from supported to retired without a single change on your side. "We have not changed anything" is a reason to check the version, not a reason to assume it is fine.

Related reading

Sources and further reading

Where to start

Get the version numbers now. Everything else in this post is a decision you cannot make until you know what you are running, and the inventory is a ten-minute job that most teams have been deferring since the notice went up. If every server is on 2.6.84.0 or later and already using application-based authentication, you are done until the next build retires. If not, book the change window well before April 7, 2027: a planned Tier-0 change is materially cheaper than an emergency one after sync stops.

If you would rather have a senior engineer confirm the version position, plan the upgrade as a Tier-0 change, and verify that password sync, provisioning, and deprovisioning all resumed afterwards, the project intake form takes about three minutes. We'll come back with scope and a fixed-fee range.


Pro IT NW does senior-led Microsoft project work. Vendor-neutral. Labor-only. Based in Seattle, delivered USA-wide. We don't take resale margins on licensing, and we don't sell you a managed service to fix a version number.

Questions we get asked

When does Microsoft Entra Connect Sync stop working?
April 7, 2027, for any server that is not on version 2.6.84.0 or later with application-based authentication configured. Microsoft's installation prerequisites and version history pages both carry the same notice: 'Upgrade Microsoft Entra Connect Sync to version 2.6.84.0 or later and configure application-based authentication by April 7, 2027. Legacy authentication is being retired, and synchronization services will stop working after this date if these requirements aren't met.' That notice replaced, on September 29, 2026, an earlier one that named September 30, 2026 and version 2.5.79.0.
Did Entra Connect Sync stop working on September 30, 2026?
Microsoft's pages no longer describe a September 30, 2026 cutoff. On September 29, 2026, Microsoft replaced the notice that said synchronization would stop on September 30 for servers below 2.5.79.0 with the April 7, 2027 requirement. We have not seen a Microsoft statement about what, if anything, changed on September 30 itself, so if a server below 2.5.79.0 is still in service, check that synchronization is actually running rather than assuming either way.
What is application-based authentication for Entra Connect Sync?
It replaces the username-and-password Microsoft Entra Connector account with an application identity. Microsoft's documentation describes it as 'an application identity that uses Oauth 2.0 client credential flow with certificate credentials,' with three ways to manage it: managed by Microsoft Entra Connect (the default), Bring Your Own Certificate, or Bring Your Own Application. The April 7, 2027 notice requires both the version upgrade and this authentication change — upgrading alone does not satisfy it.
What is the minimum Entra Connect Sync version now?
Version 2.6.84.0. Microsoft raised the minimum named in its notice from 2.5.79.0 to 2.6.84.0 on September 29, 2026. Microsoft's version history lists 2.6.84.0's own end of support as September 16, 2027, and the newest build, 2.6.92.0, released September 23, 2026, carries the 'This release includes security fixes. We recommend upgrading to this version as soon as possible' notice.
Is 2.5.79.0 still a safe place to stop?
No. Version 2.5.79.0 is below the new 2.6.84.0 minimum, and Microsoft's published version history still lists its end of support as October 23, 2026. A server on 2.5.79.0 is weeks from running an out-of-support build and does not meet the April 7, 2027 requirement. Plan the upgrade to a current build, not to a floor.
How long is a version of Microsoft Entra Connect Sync supported?
Twelve months. Microsoft's published policy is that versions of Microsoft Entra Connect Sync 2.x retire 12 months from the date that a newer version is released, a policy that went into effect on 15 March 2023. Because the clock starts when the next build ships rather than when you install yours, the supported window on any given version is set by Microsoft's release cadence, not by your deployment date.
What actually breaks when Entra Connect Sync stops synchronizing?
Hybrid identity synchronization stops entirely. Password hash synchronization stops, so on-premises password changes no longer reach the cloud. New-hire provisioning stops, so accounts created in Active Directory never appear in the cloud directory. Deprovisioning stops too, which is the one that matters for security: disabling a departing employee's Active Directory account no longer removes their cloud access. The directory does not throw an error a user would notice — it silently stops telling the truth.
Is upgrading Entra Connect Sync a routine patch?
No. The Entra Connect Sync server is a Tier-0 asset — it holds credentials that can write to your directory, and compromising it is equivalent to compromising the identity plane. Moving it to application-based authentication changes how that server proves its identity, which makes this a change-controlled job with a scheduled window, a rollback position, and post-change verification. The work itself is not long; the approvals and the verification are what need lead time.
Which Entra Connect Sync versions have published retirement dates?
Microsoft's version history page, last updated September 29, 2026, publishes a retirement table: 2.5.3.0 reached end of support on July 31, 2026; 2.5.76.0 on September 1, 2026; 2.5.79.0 on October 23, 2026; 2.5.190.0 on February 2, 2027; 2.6.1.0 on March 10, 2027; 2.6.3.0 on July 7, 2027; 2.6.84.0 on September 16, 2027; and 2.6.91.0 on September 23, 2027. The newest build listed, 2.6.92.0, released September 23, 2026, has no end-of-support date printed against it yet. Check the table itself before planning around any of these dates.

Written by the team at · Senior-led Microsoft project consultancy · Seattle and the Pacific Northwest, delivered USA-wide.

Need Entra Connect upgraded before September 30?

Senior Microsoft engineers based in the Pacific Northwest — onsite around Puget Sound, remote anywhere in the US. Tell us the environment and the deadline, and we'll scope it as a fixed-fee project.