IT Glossary

Directory Synchronization

Directory synchronization keeps identity data consistent between directories. Learn how it works and why it is not the same thing as provisioning.

August 7, 2026

What is directory synchronization?

Directory synchronization is the automated process that keeps identity data consistent between two or more directories, for example between an on-premises Active Directory and a cloud directory such as Microsoft Entra ID or Google Workspace. It copies users, groups, and attributes on a schedule, so a single change never has to be made twice.

How directory synchronization works

  • A sync agent reads objects from the source directory at a fixed interval, commonly every 30 minutes.
  • Rules decide which objects and attributes are in scope, and which are filtered out.
  • A matching key, usually an immutable identifier rather than an email address, links the same person across both directories.
  • Changes flow in one direction by default, with write-back enabled selectively for passwords or specific attributes.
  • Conflicts and duplicates are reported rather than silently merged.

Synchronization is not provisioning

The two are routinely confused. Directory synchronization copies identity data between directories, so the same person exists in both. Provisioning creates and removes accounts inside applications. Syncing Active Directory to Entra ID gives nobody a Slack account, and disabling a synced user does not close their Notion seat. Directories talk to directories, while applications need their own connection.

Examples and use cases

A company runs Entra Connect between its on-premises AD and its Microsoft 365 tenant. Identity data stays consistent and the Microsoft applications behave correctly. Everything else in the stack, roughly 90 tools, sits outside that flow entirely, each with its own user list. The team assumes a synced directory means governed access, and the first access review is where that assumption breaks. Corma connects to those applications directly, so the account picture matches the directory instead of diverging from it.

Related concepts

FAQ

What is the difference between directory synchronization and SCIM?

Synchronization keeps two directories aligned. SCIM is a standard protocol for creating and removing user accounts inside an application. One is directory to directory, the other directory to application.

How often does directory synchronization run?

Typically every 30 minutes for standard attributes, with password hash sync running more frequently. Real-time propagation is the exception rather than the rule.

What happens when directory synchronization fails?

Changes stop propagating silently. New joiners do not appear in the cloud directory and departures stay active, which is why sync health belongs on the monitoring dashboard.

Do you still need directory synchronization in a cloud-only company?

No. A cloud-only organization has a single directory. Synchronization exists to bridge an on-premises directory that has not yet been retired.

Request a demo