Feature Availability in an Entra-Only Environment
Overview
CerteroX supports three directory configurations: Active Directory only, Microsoft Entra ID only, or both together. This article covers what an Entra-only deployment provides, and which capabilities depend on Active Directory and are therefore not available without it.
It is intended to be read before you decide on a configuration. If you are weighing the options, start with Directory Configuration | Active Directory, Entra ID, or Both.
Why some Capabilities require Active Directory
Microsoft Entra ID is not a cloud-hosted copy of Active Directory. It is a different directory service with a different data model. Several concepts that exist on-premises have no equivalent in Entra, and capabilities built on those concepts cannot be provided from Entra data.
This is an architectural difference rather than a limitation of the platform, and it applies to any product sourcing identity data from Entra.
Capabilities Not Available in an Entra-only Deployment
Capability | Why it requires Active Directory |
|---|
Capability | Why it requires Active Directory |
|---|---|
Passworks self-service password reset. | Requires connectivity to an on-premises Active Directory domain to perform password change operations. Use Microsoft self-service password reset instead. |
Passworks history and blocked user views. | Depend on Passworks. With no password reset activity, there is no history to display. |
Organisational unit structure. | Entra ID has no organisational unit concept. Its organisational hierarchy is flat, expressed through Department and Company attributes. |
Group Policy data. | Group Policy is an on-premises Active Directory feature with no Entra equivalent. |
Active Directory computer accounts. | Entra devices use a different model. On-premises computer account attributes, including the Active Directory computer SID and organisational unit placement, are not available. |
On-premises SID-based operations. | Entra security identifiers differ from on-premises SIDs. Reports or integrations that reference on-premises SIDs will not return the expected results. |
Active Directory group reporting. | Groups are collected into Entra group data rather than Active Directory group data. Reports written against Active Directory group tables return no rows and must be rewritten. |
Custom groups defined on Active Directory attributes. | Definitions referencing organisational unit, domain or on-premises account name have no equivalent field to evaluate and must be re-written against Entra attributes. |
Capabilities that Work Differently
These are available, but the data behind them behaves differently without Active Directory.
Capability | Difference |
|---|
Capability | Difference |
|---|---|
Device inventory | Entra provides basic device data only. Detailed hardware, software and operating system version information requires the Certero client agent. |
Mobile devices | Android and iOS devices are not collected by the Entra ID connector. Certero for Mobile is required. |
Group membership | Direct user members only. Nested groups are not expanded and non-user members are excluded, so counts may be lower than the Entra portal shows. |
User data completeness | Person records are as complete as your Entra tenant. Attributes not maintained in Entra will be empty. |
Last sign-in | Requires the AuditLog.Read.All permission and at least one Entra ID P1 licence. |
Stale device identification | Without Active Directory last-logon data, devices are identified as stale when Entra no longer returns them. A device powered off but still registered in Entra will not be flagged. |
User deletion | With no Active Directory record to act as a safeguard, deleting a user in Entra removes the corresponding person record from CerteroX, together with linked licence assignments and history. See Off-boarding Users | Hybrid Active Directory and Entra ID Environment. |
Fields that Appear but remain Empty
User records include several attributes that describe an account's relationship to Active Directory, synchronization status, last synchronization date, on-premises domain, on-premises account name and immutable identifier.
In an Entra-only deployment these are always empty. They appear in data grids and property sheets because the platform supports both configurations from a single record structure. They are not an indication of missing data.
Deciding whether Entra-only is right for you
Entra-only suits organisations that have no on-premises Active Directory, or that retain one solely to feed identity data into CerteroX and wish to stop doing so.
It is not suitable if you depend on Passworks, Organisational Unit (OU) structure, Group Policy visibility, or reporting built on Active Directory groups or SIDs. Where some of those matter, a hybrid configuration retains them while still bringing Entra data into the platform.
Further Information
See Directory Configuration | Active Directory, Entra ID, or Both for a comparison of all three options.
Getting Started / Support
If you have questions or need help, please contact the Certero Help Desk or your Certero account team.
© 2026 Certero Company Confidential. All rights reserved.