Directory Configuration | Active Directory, Entra ID, or Both
Overview
CerteroX can source identity and device data from Microsoft Active Directory, from Microsoft Entra ID, or from both. This article compares the three options and sets out what each requires.
The Three Configurations
| Active Directory only | Hybrid — both | Entra ID only |
|---|
| Active Directory only | Hybrid — both | Entra ID only |
|---|---|---|---|
Identity Source | Active Directory | Both, managed by a preferred source. | Entra ID |
On-premises infrastructure | Required | Required | Not required |
Cloud-only users visible | No | Yes | Yes |
Passworks self-service password reset | Available | Available | Not available |
Organisational unit structure | Available | Available | Not available |
Group Policy data | Available | Available | Not available |
Active Directory group reporting | Available | Available | Not available |
Configuration complexity | Lowest | Highest | Low |
Active Directory Only
The established configuration. Suitable where Active Directory remains your system of record and you have no cloud-only users to account for.
Nothing changes for existing customers. Adopting Entra ID is optional.
Hybrid - Both Directories
Suitable where you maintain both directories and want complete coverage. Active Directory users, cloud-only users, and the capabilities that depend on on-premises data.
It provides the fullest picture, and it is the most involved to configure. Three decisions are required:
Set your Preferred Directory Source before the Entra ID connector first runs. It defaults to Active Directory, and the setting is applied at the point data is written — so a first run before the choice is made will already have applied the default. See Setting your Preferred Directory Source.
Schedule the two connectors so they do not overlap. See Scheduling the Entra ID Connector in a Hybrid Environment.
Agree an offboarding process covering both directories. Actioning a leaver in only one produces an inconsistent result. See Off-boarding Users | Hybrid Active Directory and Entra ID Environment.
Entra ID Only
Suitable where you have no on-premises Active Directory, or retain one solely to feed CerteroX and want to stop.
Before choosing this configuration, read Feature availability in an Entra-only deployment. Several capabilities depend on Active Directory and are not available without it, most notably Passworks self-service password reset, organisational unit structure, Group Policy data, and reporting built on Active Directory groups or on-premises SIDs.
Before you enable the Entra ID connector
Two checks are worth completing first. Both are far easier before the first collection than after.
1. Review consumers of the ActiveDirectoryGuid field
This applies to hybrid deployments and is important.
In a hybrid deployment, where a device exists in both directories and is matched by hostname, the ActiveDirectoryGuid field is updated to hold the Entra device identifier in place of the Active Directory one. No error is raised, and the change is not visible in the interface.
Anything reading that field directly will begin returning a different value. Before enabling the connector, search your custom reports, scheduled queries, SCCM integration and API scripts for ActiveDirectoryGuid and confirm what depends on it.
See ActiveDirectoryGuid field | Entra and Hybrid deployments.
2. Confirm your synchronisation scope
Users synchronised from Active Directory to Entra by Microsoft Entra Connect are matched to their existing person record. Users outside that scope are treated as new people. Knowing in advance which is which lets you distinguish an expected increase in user count from a matching problem.
See How are users matched between Active Directory and Entra ID.
Can I change Configuration Later?
Yes. You can add the Entra ID connector to an existing Active Directory deployment, and you can change your Preferred Directory Source at any time.
Changing the preferred source affects subsequent connector runs. It does not retrospectively re-arbitrate records already written.
Further Information
Please contact Certero Support, or speak to your Certero account team, if you would like to discuss which configuration best fits your environment.
Getting Started / Support
If you have questions or need help, please contact the Certero Help Desk or your Certero account team.
© 2026 Certero Company Confidential. All rights reserved.