--- title: "Directory Configuration | Active Directory, Entra ID, or Both" canonical: "https://ai-docs.certero.com/space/CUP/326238277/Directory%20Configuration%20%7C%20Active%20Directory%2C%20Entra%20ID%2C%20or%20Both" format: markdown --- --- ## Overview CerteroX can source identity and device data from Microsoft Active Directory, from Microsoft Entra ID, or from both. This article compares the three options and sets out what each requires. --- ## The Three Configurations | | <span style="color: #ffffff">**Active Directory only**</span> | <span style="color: #ffffff">**Hybrid — both**</span> | <span style="color: #ffffff">**Entra ID only**</span> | | --- | --- | --- | --- | | **Identity Source** | Active Directory | Both, managed by a preferred source. | Entra ID | | **On-premises infrastructure** | Required | Required | Not required | | **Cloud-only users visible** | No | Yes | Yes | | **Passworks self-service password reset** | Available | Available | Not available | | **Organisational unit structure** | Available | Available | Not available | | **Group Policy data** | Available | Available | Not available | | **Active Directory group reporting** | Available | Available | Not available | | **Configuration complexity** | Lowest | Highest | Low | --- ## Active Directory Only The established configuration. Suitable where Active Directory remains your system of record and you have no cloud-only users to account for. Nothing changes for existing customers. Adopting Entra ID is optional. --- ## Hybrid - Both Directories Suitable where you maintain both directories and want complete coverage. Active Directory users, cloud-only users, and the capabilities that depend on on-premises data. It provides the fullest picture, and it is the most involved to configure. Three decisions are required: 1. **Set your Preferred Directory Source before the Entra ID connector first runs.** It defaults to Active Directory, and the setting is applied at the point data is written — so a first run before the choice is made will already have applied the default. See *[Setting your Preferred Directory Source](https://docs.certero.com/space/CUP/326336556/Setting+your+Preferred+Directory+Source)*. 2. **Schedule the two connectors so they do not overlap.** See [Scheduling the Entra ID Connector in a Hybrid Environment](https://docs.certero.com/space/CUP/326238257/Scheduling+the+Entra+ID+Connector+in+a+Hybrid+Environment). 3. **Agree an offboarding process covering both directories.** Actioning a leaver in only one produces an inconsistent result. See [Off-boarding Users | Hybrid Active Directory and Entra ID Environment](https://helpdesk.certero.com/space/KCS/326172753/Off-boarding+Users+%7C+Hybrid+Active+Directory+and+Entra+ID+Environment). --- ## Entra ID Only Suitable where you have no on-premises Active Directory, or retain one solely to feed CerteroX and want to stop. Before choosing this configuration, read *[Feature availability in an Entra-only deployment](https://docs.certero.com/space/CUP/326172793/Feature+Availability+in+an+Entra-Only+Environment)*. Several capabilities depend on Active Directory and are not available without it, most notably Passworks self-service password reset, organisational unit structure, Group Policy data, and reporting built on Active Directory groups or on-premises SIDs. --- ## Before you enable the Entra ID connector Two checks are worth completing first. Both are far easier before the first collection than after. ### 1. Review consumers of the `ActiveDirectoryGuid` field > 📝 **This applies to hybrid deployments and is important.** In a hybrid deployment, where a device exists in both directories and is matched by hostname, the `ActiveDirectoryGuid` field is updated to hold the Entra device identifier in place of the Active Directory one. No error is raised, and the change is not visible in the interface. Anything reading that field directly will begin returning a different value. Before enabling the connector, search your custom reports, scheduled queries, SCCM integration and API scripts for `ActiveDirectoryGuid` and confirm what depends on it. See *[ActiveDirectoryGuid field | Entra and Hybrid deployments](https://helpdesk.certero.com/space/KCS/326041626/ActiveDirectoryGuid+Field+%7C+Entra+and+Hybrid+Deployments)**.* ### 2. Confirm your synchronisation scope Users synchronised from Active Directory to Entra by Microsoft Entra Connect are matched to their existing person record. Users outside that scope are treated as new people. Knowing in advance which is which lets you distinguish an expected increase in user count from a matching problem. See *[How are users matched between Active Directory and Entra ID](https://docs.certero.com/space/CUP/326336576/How+Are+Users+Matched+Between+Active+Directory+and+Entra+ID)**.* --- ## Can I change Configuration Later? Yes. You can add the Entra ID connector to an existing Active Directory deployment, and you can change your Preferred Directory Source at any time. Changing the preferred source affects **subsequent** connector runs. It does not retrospectively re-arbitrate records already written. --- ## Further Information Please contact Certero Support, or speak to your Certero account team, if you would like to discuss which configuration best fits your environment. --- ## Getting Started / Support If you have questions or need help, please contact the **Certero Help Desk** or your Certero account team. --- © 2026 Certero Company Confidential. All rights reserved.