Navigated to page Certero - AI Docs

Feature Availability in an Entra-Only Environment

CerteroX_Logo_Black.png


Overview

CerteroX supports three directory configurations: Active Directory only, Microsoft Entra ID only, or both together. This article covers what an Entra-only deployment provides, and which capabilities depend on Active Directory and are therefore not available without it.

It is intended to be read before you decide on a configuration. If you are weighing the options, start with Directory Configuration | Active Directory, Entra ID, or Both.


Why some Capabilities require Active Directory

Microsoft Entra ID is not a cloud-hosted copy of Active Directory. It is a different directory service with a different data model. Several concepts that exist on-premises have no equivalent in Entra, and capabilities built on those concepts cannot be provided from Entra data.

This is an architectural difference rather than a limitation of the platform, and it applies to any product sourcing identity data from Entra.


Capabilities Not Available in an Entra-only Deployment

Capability

Why it requires Active Directory

Passworks self-service password reset.

Requires connectivity to an on-premises Active Directory domain to perform password change operations. Use Microsoft self-service password reset instead.

Passworks history and blocked user views.

Depend on Passworks. With no password reset activity, there is no history to display.

Organisational unit structure.

Entra ID has no organisational unit concept. Its organisational hierarchy is flat, expressed through Department and Company attributes.

Group Policy data.

Group Policy is an on-premises Active Directory feature with no Entra equivalent.

Active Directory computer accounts.

Entra devices use a different model. On-premises computer account attributes, including the Active Directory computer SID and organisational unit placement, are not available.

On-premises SID-based operations.

Entra security identifiers differ from on-premises SIDs. Reports or integrations that reference on-premises SIDs will not return the expected results.

Active Directory group reporting.

Groups are collected into Entra group data rather than Active Directory group data. Reports written against Active Directory group tables return no rows and must be rewritten.

Custom groups defined on Active Directory attributes.

Definitions referencing organisational unit, domain or on-premises account name have no equivalent field to evaluate and must be re-written against Entra attributes.


Capabilities that Work Differently

These are available, but the data behind them behaves differently without Active Directory.

Capability

Difference

Device inventory

Entra provides basic device data only. Detailed hardware, software and operating system version information requires the Certero client agent.

Mobile devices

Android and iOS devices are not collected by the Entra ID connector. Certero for Mobile is required.

Group membership

Direct user members only. Nested groups are not expanded and non-user members are excluded, so counts may be lower than the Entra portal shows.

User data completeness

Person records are as complete as your Entra tenant. Attributes not maintained in Entra will be empty.

Last sign-in

Requires the AuditLog.Read.All permission and at least one Entra ID P1 licence.

Stale device identification

Without Active Directory last-logon data, devices are identified as stale when Entra no longer returns them. A device powered off but still registered in Entra will not be flagged.

User deletion

With no Active Directory record to act as a safeguard, deleting a user in Entra removes the corresponding person record from CerteroX, together with linked licence assignments and history. See Off-boarding Users | Hybrid Active Directory and Entra ID Environment.


Fields that Appear but remain Empty

User records include several attributes that describe an account's relationship to Active Directory, synchronization status, last synchronization date, on-premises domain, on-premises account name and immutable identifier.

In an Entra-only deployment these are always empty. They appear in data grids and property sheets because the platform supports both configurations from a single record structure. They are not an indication of missing data.


Deciding whether Entra-only is right for you

Entra-only suits organisations that have no on-premises Active Directory, or that retain one solely to feed identity data into CerteroX and wish to stop doing so.

It is not suitable if you depend on Passworks, Organisational Unit (OU) structure, Group Policy visibility, or reporting built on Active Directory groups or SIDs. Where some of those matter, a hybrid configuration retains them while still bringing Entra data into the platform.


Further Information

See Directory Configuration | Active Directory, Entra ID, or Both for a comparison of all three options.


Getting Started / Support

If you have questions or need help, please contact the Certero Help Desk or your Certero account team.


© 2026 Certero Company Confidential. All rights reserved.