The Marketing OU users exist in fabrikam.com, a completely separate on-premises AD DS forest belonging to a different company than A. Datum, whose own Microsoft Entra tenant only syncs the adatum.com forest today. To give those Fabrikam users access to storage1 in A. Datum ' s tenant, their identities must also be represented in that tenant. Microsoft Entra Connect cloud sync uses lightweight, cloud-managed provisioning agents that are specifically designed to support complex or multi-forest topologies, including syncing from a partner organization ' s forest, with a much smaller on-premises footprint and configuration burden than the full Microsoft Entra Connect Sync engine, and without requiring a trust relationship between the two companies ' forests. The traditional Microsoft Entra Connect Sync engine (whether in active or staging mode) is built around a single organization ' s identity infrastructure and is a heavier deployment to extend safely across an independent partner company ' s forest; staging mode specifically only prepares a secondary sync server to take over, and does not by itself address the cross-company sync problem. AD FS provides federation and SSO but does not create Microsoft Entra ID objects for Fabrikam ' s users. Microsoft Entra Connect cloud sync is therefore the correct, purpose-built option.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit