Navigated to page Certero - AI Docs

Reporting on Entra ID Users and Groups

CerteroX_Logo_Black.png


Overview

This article covers reporting on identity data once the Entra ID Connector is in use, including what changes for existing reports in a hybrid deployment.


Active Directory and Entra ID groups are held Separately

The most important point for report authors: groups from the two directories are stored separately and are not merged.

  • Active Directory groups populate the Active Directory group data

  • Entra ID groups populate the Entra group data

  • A group synchronised from Active Directory to Entra appears in both, as two independent records

There is no automatic linking between the two. The platform does not attempt to identify that an Active Directory group and an Entra group are the same group, because the two directories provide no reliable basis for doing so.


What this means for your Reports

Deployment

Effect

Active Directory only

No change. Existing reports continue to work exactly as before.

Hybrid

Reports against Active Directory groups continue to work, but cover only Active Directory groups. To report on your full estate, you also need to include Entra group data.

Entra ID only

Reports written against Active Directory groups return no rows, because no Active Directory data is collected. They must be rewritten against Entra group data.

A report returning no rows in an Entra-only deployment is not a fault. It is querying a data source that is not populated in that configuration.


Building Reports on Entra data

Entra users and groups are available as report sources in the same way as their Active Directory equivalents, and can be used in criteria, filters and dynamic groups.

When building a report in a hybrid deployment, decide first whether you want:

  • Users from one directory: report on Active Directory users or Entra users specifically

  • All people regardless of source: report on the person record, which is populated from whichever directory is preferred for each user

The second is usually what is wanted for headcount, licensing and compliance reporting. The first is useful for directory-specific administration, such as identifying users present in one directory but not the other.


Group Membership Counts

Entra group membership figures may be lower than the equivalent figure in the Entra portal, for two reasons:

  • Only direct members are collected. Nested groups are not expanded, so members who belong via a nested group are not counted.

  • Only user members are collected. Service principals, contacts and nested groups are excluded.

Where an accurate effective membership is needed, flatten the group in Entra or report from Entra directly.


Reviewing existing Reports before Enabling the Connector

In a hybrid deployment, it is worth listing which of your reports query Active Directory group data before enabling the Entra ID connector. Those reports will continue to work and to return Active Directory groups only, the question is whether that remains the coverage you want once Entra groups are also present.

The same review should cover custom groups and dynamic filters defined on Active Directory attributes such as organisational unit, domain or on-premises account name.


Further Information

See How to create a Report | v8.1+ for the general report building process, and Entra ID Connector | Supported Data and Collection Limitations for what is collected.


Getting Started / Support

If you are unsure whether your environment is affected, please contact the Certero Help Desk or your Certero account team.


© 2026 Certero Company Confidential. All rights reserved.